The Major Security Risks Small Businesses Face and How to Defend Against ThemJust because you are flying under the radar, doesn't mean cyber attackers won't target you. Hear from experts on how to keep your business safe.

ByAndrea Huspeni

Opinions expressed by Entrepreneur contributors are their own.

Shutterstock

No business is completely safe from security vulnerabilities. Just look at Target, Home Depot and TJ Maxx. While these well-known companies may seem like a more attractive target for hackers, the businesses flying under the radar face the same, if not more, threats from cyber attackers looking to cause mayhem in a company.

To help small- and midsize-businesses stay protected, we asked tech experts what the biggest security risk these companies face and how they can defend against them.

Here is what they had to say:

Cyber attackers don't discriminate.

Small and midsize businesses often make a philosophical mistake right off the bat: They assume they are too small to be relevant to hackers. I can promise you that cyber attackers believe in equal opportunity for targets.

Related:Here's How to Build a Strong Security Team to Keep Your Company Safe and Sound

So while larger companies often opt for corporate-owned devices, there are many products available on a per-seat basis that will work to secure proprietary data even when accessed by personally-owned devices. This is where SMBs need to focus: on the protection of their data. Even if your strategy is not as comprehensive (or expensive) as those in place at a federal agency or a massive corporation, building roadblocks on the way to exposed plaintext information is a necessary tactic to discourage hackers. Otherwise you're an easy mark.

-- Ray Potter, CEO ofSafeLogic, a company providing security, encryption and FIPS validation products to applications

Security flaws are everywhere.

Right now a lot of the challenges arise from how networked and interconnected the modern marketplace is. Social media is a great example of a technology and business advancement that has brought businesses closer to customers and clients while also increasing business risk.

As employees engage in sales and networking across social networks, new pathways into the business open up and cyber criminals know how to exploit them. One of the most effective actions businesses can take to reduce the risks that come from our interconnected marketplace is to provide knowledge. Many users do not understand how cyber criminals leverage social tools and technologies to gain access to businesses and their data. A simple weekly update from IT on threats and how to avoid them is an important way to ensure your user base is well informed and avoiding risky online activity. It empowers your employees to be accountable for security, and incorporates them into your security solution.

-- Anna Frazzetto,Chief Digital Technology Officer and SVP atHarvey Nash, an IT recruiting firm

It comes back to the data.

Protecting sensitive data from hackers should be the top priority for businesses of all sizes. These threats can come in the form of phishing and malware that seek to infiltrate the corporate network, endpoints and the cloud applications employees use. To mitigate against these threats:

  • Update patches as they become available
  • Use security products that protect the entire IT stack – the device, operating system, application, network, cloud and data layers
  • Train employees to have security awareness

-- Pravin Kothari, founder and CEO ofCipherCloud, an enterprise cloud security company

Related:7 Cybersecurity Layers Every Entrepreneur Needs to Understand

People are a liability.

People remain the biggest security risk to any sized organization, including SMBs. As threats become more sophisticated, even careful employees may find themselves victims of phishing or accidentally opening attachments with viruses. The best defense is ensuring that staff get consistent education to keep security at the top of mind. Security training for all employees really should start on day one.

The other large issue I see is organizations maintaining a legacy security posture, or original security plan. It's not enough to configure the firewall and walk away. Every organization should consider bringing in a third party to get a vulnerability assessment. Even if you have a dedicated security team, a second set of eyeballs will help identify risks and start working towards remediation.

科特妮·汤普森,首席技术官Green House Data,an environmentally conscious data center service

Imbalance in security.

The fastest growing threat are sophisticated phishing attacks, which, when not identified and stopped promptly, can lead to a loss of business.

Business needs to be smart about balancing in-house security resources and building a strong team, while also leveraging third-party security services. There are a number of third-party security services, many of them are SaaS based, that don't require investments in hardware and are generally easier to deploy.

Related:Why Small-Business Entrepreneurs Should Care About Cybersecurity

Perhaps the most important thing is to treat security threats seriously and to proactively assess your security measures. Many companies don't take security seriously enough until something bad happens. It is generally a lot more expensive to clean up after a security breach, than addressing it proactively.

-- Arne Josefsberg, Chief Information Officer ofGoDaddy, an Internet domain registrar and web hosting company

Wavy Line
Andrea Huspeni

Founder of This Dog's Life

Andrea Huspeni is the former special projects director at Entrepreneur.com and the founder ofThis Dog's Life.

Editor's Pick

Related Topics

Business Culture

The Newest Workplace Trend Has HR Sounding The Alarm

HR departments are still figuring out how to handle "quiet quitting," but a new trend is taking over.

Business News

An 81-Year-Old Florida CEO Just Indicted for a $250 Million Ponzi Scheme Ran a Sprawling Senior Citizen Crime Ring

Carl Ruderman is the fifth senior citizen in the Miami-Fort-Lauderdale-Palm Beach metropolitan area to face charges in connection with the scam.

Money & Finance

Want to Become a Millionaire? Follow Warren Buffett's 4 Rules.

企业家是不能过度指狗万官方望太多a company exit for their eventual 'win.' Do this instead.

Business News

Taco Bell Slammed With Lawsuit Over 'Especially Concerning' Advertisements, Allegedly Deceiving Customers

The class action lawsuit claims the chain is advertising more than they deliver.

Business News

Body of Missing 27-Year-Old Goldman Sachs Banker Found in Nearby Body of Water

John Castic, a 27-year-old Goldman Sachs employee, went missing around 2:30 a.m. on Saturday after attending a concert at the Brooklyn Mirage in East Williamsburg.

Marketing

'I Cannot Wait to Host You': Gwyneth Paltrow Just Listed Her Guesthouse On Airbnb.

The goop founder says she hopes 'we'll find connections and commonalities over a delicious meal.'