Many people believe that cyberattacks are a problem faced by large businesses. However, recent analysis indicates the 40 percent of cyberattacks launched against corporations target companies with 500 or less employees. Small and medium size businesses (SMB) are the backbone of the United States and in many countries around the world. In the U.S. SMBs are the primary source of jobs and the largest group of exporters.
A recent study found that the vast majority of SMBs depend on the Internet in their day-to-day operations. Given the importance of this segment to the U.S. economy and its reliance on the Internet, it is important for these companies to be protected against ever growing risk of cyberattacks.
A search for metrics on this segment of U.S. business found some extremely troubling figures. For example, a recent survey conducted by the Endurance International Group found that 81 percent of SMBs are currently concerned about cybersecurity and 91 percent think about it often.
There is good reason for SMBs to be this concerned. Symantec published a report that stated 60 percent of targeted attacks in 2014 were aimed at SMBs. Add to that a study by PCWorld, of small businesses who suffered a breach, which found that roughly 60 percent go out of business within six months after an attack.
There seems to be a common belief among companies that if they outsource their IT/systems or go with a cloud vendor they are not responsible if a breach occurs. A lawyer once told me “that is not true – everyone will get invited to the lawsuit.”
The risks do not stop there. Think about all the SMBs that sell to the military and all levels of government. Many of them often connect directly to their customers systems. All organizations must get smarter when it comes to connecting to vendor systems. Ongoing cybersecurity assessments and active monitoring of the connections are the basics. Perhaps it is time to take the next step. Is that regulation, establishing a minimum level of cybersecurity for all vendors? I would bet it is a combination of the two.
RELATED: Learn more about securing defense and federal networks at C4ISR & Networks and Federal Times’ CyberCon 2015, held Nov. 18 at the Ritz Carlton-Pentagon City in Arlington, Virginia.




