Got Effective Cybersecurity Practices? Be Aware: The FTC Is Watching You.Data breaches can happen to any business -- not just those with big names. Claiming "I didn't know" won't suffice when this happens to you.

ByAdam Levy

Opinions expressed by Entrepreneur contributors are their own.

Shutterstock

Following a July ruling against medical testing laboratory LabMD (which is now out of business), the Federal Trade Commission has emerged as a central regulator of cybersecurity practices for U.S. businesses. The FTC's mandate to act on "unfair or deceptive" business practices that could harm consumers is being interpreted in a way that means any business that handles (and might potentially mishandle) consumer data is liable to fall under the organization's scrutiny.

That's almost every business today.

Related:5 Cybersecurity Tools Your Company Should Have

Some background: The Commission reversed an administrative law judge's ruling and found that LabMD, a clinical laboratory for physicians, failed to protect the sensitive personal and medical information of consumers. From 2001 to 2014, LabMD collected this information for over 750,000 patients.

Based on theLabMD ruling, which cited a lack of "even basic precautions to protect the sensitive consumer information maintained on its computer system," it appears that actual harm from a data breach doesn't necessarily need to be proven if the potential for harm exists.

The ruling sends a clear and sobering signal to business owners:You must make significant, demonstrable efforts to protect yourself from data breaches or face the consequences.

Related:Court Rules FTC Can Come After Your Company After a Cyber Attack

A glimpse of what's to come

"LabMD's security practices were unreasonable, lacking even basic precautions to protect the sensitive consumer information maintained on its computer system," the FTC ruled. "Among other things, it failed to use an intrusion detection system or file integrity monitoring; neglected to monitor traffic coming across its firewalls; provided essentially no data security training to its employees; and never deleted any of the consumer data it had collected."

For small business owners who have a seemingly endless list of concerns to address, making time to focus on data security best practices is sometimes difficult to justify. But it has to be done: The FTC and other government entities are only going to sharpen their focus on data security and consumer privacy in the coming years. Data integrity must become a core aspect of doing business (rather than a minor detail that can be overlooked).

With this in mind, small business owners should be aware of a few common misconceptions surrounding data security, as well as the best practices they should rely on to address them:

Misconception No. 1: Data security is a "big business' problem.

A surprising number of small business owners look at data security as something they don't need to worry about. You'll hear owners say, "Nobody is interested in the data we have. We're not Sony or a government agency."

但事实是,网络罪犯最certainly interested in your data, and according to Fox Business,43 percent of worldwide attacksin 2015 were against small businesses with fewer than 250 employees.

最重要的是,普遍的ransomware attacks means that it no longer matters if your data is important to other people. If it's important to you -- the owner -- hackers can take it and force you to pay large sums of money to get it back.

As a small business owner, you must consider it critical to have a managed-data backup system in place. This won'tpreventattacks, but it can significantly mitigate harm to your business if one does occur, especially in the case of a ransomware attack.

Misconception No. 2: One solution for all threats

Small business owners are especially susceptible to believing that a single solution will defend against all possible threats. Security is better viewed as a managed process.

Related:10 Data-Security Measures You Can't Do Without

Simply having some legacy IT solutions in place shouldn't let you develop a false sense of security and avoid asking important questions, including:Are we addressing vulnerabilities through security patching? Are we getting regular reports of that activity so that, in the event of a breach, it's documented and we canrespond effectivelyto an audit? Is our firewall being actively managed?

You need to have a managed security system in place, one that includes regular reports on security measures, potential threats and updates. If you need more information, conduct some research on third-partymanaged security service providers, which can offer on-premise and remote solutions depending on your needs.

Misconception No. 3: Cybersecurity training is for the IT guys.

Data security isn't just IT's responsibility -- it needs to be a priority for all employees. Your entire network can be compromised if, for instance, just one employeefalls victim to a phishing email.

The threat landscape is constantly changing. Implementing an employee-training program and being able to demonstrate that security should be a priority for all employees and is becoming increasingly important. Invest inregular training sessionsand implement policies to reinforce the information shared.

Misconception No. 4: The price isn't right.

Small business owners often look at security solutions and say, "That sounds expensive." In reality, the cost of these services is far from prohibitive, and the services can scale as businesses and their needs grow.

What's more, forgoing security solutions means you risk the much higher price tag that accompanies a breach.Reports from Kaspersky Lab indicatethat small businesses spend an average $38,000 recovering from just one data breach.

Before making an investment, then, conduct a thorough assessment of your current security measures. A security audit will give you a good idea of where you stand and make you aware of any serious vulnerability.

Related:4 Strategies Small Businesses Can Use To Avoid a Data Breach

Like any unfortunate event, data breaches can happen to any business -- not just those with big names. The FTC ruling in LabMD demonstrates how the government is placing more and more liability responsibility on business owners to protect their client data.

If yours is a small business, just claiming "I didn't know" will no longer suffice when a data breach does occur. No matter what the size or industry of your business, make data security a top priority.

Wavy Line
Adam Levy

CEO, Magnet Solutions Group

Adam Levyis the founder ofMagnet Solutions Group,an IT and web development company, andLoTops, a CRM and management application for small businesses in any industry. He tweets regularly on business technology at@Adam__Levy.

Editor's Pick

Related Topics

Money & Finance

Want to Become a Millionaire? Follow Warren Buffett's 4 Rules.

企业家是不能过度指狗万官方望太多a company exit for their eventual 'win.' Do this instead.

Business Solutions

Learn to Program an AI Chatbot for Your Business in This $30 Course

Get back-to-school savings on this AI coding course.

Business Ideas

55 Small Business Ideas to Start in 2023

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2023.

Data & Recovery

Get 1TB of Cloud Storage for Life for $119.97 With This Back-to-School Sale

This 1TB Cloud Storage Solution Is Only $119.97 for Back to School

Business News

Netflix is Hiring an AI-Focused Role—and the Starting Salary is up to $900,000

The streaming giant is looking for a leader in its machine learning department.

Leadership

This Common Leadership Habit Will Harm Your Credibility. Are You Guilty of It?

As leaders, we're always looking for ways to build credibility among peers and employees. But this easy-to-make mistake can ruin it in an instant.