Skip to main content

Create a Culture of Cybersecurity at Your Small Business

With Cyber Security Month in full swing, it may be a good time to help your employees understand the role they can play in your business's cyber security.

October is National Cyber Security Awareness Month, which can mean paying extra attention to keeping intruders from breaching your company’s data. While tools such as firewalls and virus protection software can be critical ingredients of a secure system, employees may often be overlooked as a key to your system’s safety.

“Cybersecurity is not just about IT. The best detection tools only do part of the job,” says James Pooley, an IP and legal security consultant and author of Secrets: Managing Information Assets in the Age of Cyberespionage. “Hacks come from the outside, but they usually succeed only with help from the inside,” he says. “It’s usually accidental, like what happened with the Sony hack. Someone saw an email that looked legitimate and clicked on an attachment that opened a door, letting malicious software enter the system. It sat there like a sleeper cell, gathering data and waiting for the perfect time to strike.”
promo image
Big opportunities can make or break a business.
See how these small-business owners got the job done.
While external hacks make headlines, the most common data breaches stem from employee negligence, agrees Michael Bruemmer, vice president of consumer protection at Experian. “Cyber-attacks exploiting human mistakes are extremely common. It only takes an employee surfing the Web and accidentally allowing viruses on his or her computer or receiving an email from an unknown source and clicking on a phishing scam link to put the company at risk.”
Cybersecurity starts with employee awareness, so the more you teach them about the threats, such as phishing scams, adware, malware and viruses, the better.

Social Media a Culprit

Many people reveal a great deal about themselves on social media, believes Pooley, and that can allow hackers to “scrape” those sites for information and use it to craft messages that look like they're coming from friends or coworkers. “The message might have an attachment or a link to a fake website that hosts the invasive software. Everyone in a company has the potential to become an unwitting accomplice for hackers,” he says.
“Some of the biggest hacks are what we call social hacks,” agrees Erik Knight, CEO ofSimpleWan. “Most of the time the computer systems are not what fail. It's the people problem. The quickest way to gain access to a system is to talk your way into it.”

Action Necessary

Cyber-breaches will likely continue to get worse, so it can be critical for small-business owners to get a handle on the situation, Knight believes. “As Fortune 500 companies toughen up their security, hackers are going to start targeting smaller organizations, because they lack the procedures and technology to protect themselves. Technology is important, but the people factor can circumvent almost any of those technologies if not properly addressed early on,” he says.
“For every high-profile retail breach you’ve heard about, you can bet there were at least a dozen cyber-attacks on small and medium-sized businesses,” Bruemmer adds. “Small businesses are often preyed upon by cyber-criminals, who view the category as having fewer resources to manage cyber-security.”
Whether hackers succeed may depend on how careful you and your employees are. To help develop a culture of cybersecurity for your company, keep the following tips in mind.

Train Employees

“The single most important and cost-effective action any company can do to raise its game on information security is training, but it can’t be a one-time orientation video for new hires,” Pooley says. “To be really effective, training has to be continuous; varied, so it’s interesting; world class, which means hiring experts, and inclusive, [which means] executives have to join in.”
According to Pooley, the best training should include real-world examples that enable employees to see how cybersecurity leads to job security. “When an employee does detect something and report it, publicly thank the staff member—people notice that,” he says.
“Frequently remind employees about security procedures and conduct trainings every year,” Bruemmer says. “There are many other best practices to follow, including requiring mobile devices to be tested for security prior to connecting to networks or enterprise systems, improving access and authentication practices to make sure that only the appropriate employees and contractors have access to its information systems, and encrypting sensitive or confidential personal and business information stored on computers.”

Teach Red Flags

“Cybersecurity starts with employee awareness, so the more you teach them about the threats, such as phishing scams, adware, malware and viruses, the better,” says Kevin Layton, CEO of Data-Dynamix, which specializes in demographic data and marketing strategies. “Giving guidance about what to look for in emails and computer performance is very important to minimize the threat. Strong and changing passwords are also key, as well as policies that discourage sharing them.”
For the best protection, staff should be kept up-to-date on the latest cyber threats, believes John Canfield, vice president of risk management at WePay, where the company regularly does training to update employees. “For example, spear phishing is an email that comes from a cyber-thief but appears to be from someone within your operations or from another company you do business with in an attempt to obtain data. Staff aware of such threats can then double check to make sure the request is coming from a legitimate source rather than unknowingly releasing sensitive information.”

Have a Plan

Once cyber-threats are detected, employees should know what to do with the information, which is why having an incident response plan can be crucial. “A plan can help your company act quickly if a data breach occurs and acting quickly can help to prevent further data loss, significant fines and costly customer backlash,” Bruemmer says.

Julie Bawden Davis
Writer/Author/Publisher/Speaker, Garden Guides Press

Comments

Readers Choice

Lead Your Team Into a Post-Pandemic World

During the Covid-19 crisis, I’ve spoken with many CEOs who have shared that a key priority for them, naturally, has been the safety and well-being of their employees. And there are many examples of inspiring actions taken by CEOs and companies in support of their employees. But as we’ve come to recognize that this crisis will last more than a few short weeks, companies are now defining their approach for the long haul. I’ve seen two crucial ideas take hold with corporate leaders. One: Given the magnitude of the shock and the challenges that this crisis represents, companies must consider the full breadth of their employees’ needs as people. Safety is essential, of course, but it’s also important to address higher-level needs such as the want for truth, stability, authentic connections, self-esteem, growth, and meaning in the context of the crisis. Two: Many CEOs have begun thinking about this crisis in three phases. They may assign different names or specific lengths to t

4 Ways Google Search Can Help You Achieve Your Marketing Goals

Google Ads Google Ad extensions are a great way to add key descriptive text without taking up space in your actual ad and improve your quality score for even better results. It’s a win-win right? Google Maps Is your business discoverable on Google Maps? For small businesses, adding detailed information and the use of strategic keywords can be helpful for a better location optimization. Google Ranks SEO is vital for moving up in Google rankings. To climb up the ladder, incorporate top keywords in page titles, meta tags and focus on consistently delivering relevant content. Backlinking If SEO is the the only strategy you have, it is the right time to change that. Start adding backlinks to your content. Quality backlinks can further increase your brand authority. 

Twenty Smart Business Buzzwords

Some words may grate on your nerves, but business leaders are still using "disrupt," "synergy" and "ideate." You should too. Spend any amount of time in a corporate environment and you'll likely notice there are some words that seem to come up on a daily basis. Certain verbiage becomes part of the  corporate culture  and soon, you may feel as if you need to use it to fit in. While they can change from one day to the next, most corporate buzzwords have a positive meaning. They're used to boost morale and motivate everyone involved in the conversation. Here are 20 of the top business buzzwords that you should make an effort to work into your vocabulary. 1. Impact Impact is a powerful word that has become a favorite of business professionals.  Grammarians argue  that the word is being used improperly, urging you to use "affect" instead, but businesses love it. 2. Corporate Synergy Half of the people who use this term likely