why don't small-scale and startup businesses prioritize cybersecurity relative to larger or more established organizations.
Literature Review 1
Small to medium-sized enterprises (SMEs) makeup between 95%-99% of private businesses worldwide, employ 60%-70% of the workforce in most countries and generate 33% of the GDP. SMEs account for a high percentage of the world's pollution because of the significant numbers of SMEs, and their accumulative impact (Theyel & Hofmann, 2012). The objective of this paper is to analyze why don't small-scale and startup businesses prioritize cybersecurity relative to larger or more established organizations. The issue of cyber security is not new but rather has developed more than a half-century. The arrest of an East German spy in IBM’s German by West Germany’s police in 1968 was acknowledged as the first case of cyber espionage (Warner, 2012, p. 784). In 1983, high school student that was inspired by WarGames movie and called their selves as 414s successfully got inside the unclassified military networks. Ten years ago, “the first real war in cyberspace” attacked Estonia and put the country into “a national security situation” (Hansen and Niessenbaum, 2010, p. 1168). Nowadays, cyber security has been a daily issue that can be found anywhere, from the news that reports spam, scams, frauds, and identity theft, to academic articles that discuss cyber warfare, cyber espionage, and cyber defense (Dunn-Cavelty, 2010). These significantly bring the issue of cyber security to become more important and relevant in recent years. After going through the whole research process we came to know that SMEs companies are less careful about the security and underestimate their risk level.
Introduction
Virtually any element of cyberspace can be at risk, and the degree of interconnection of those elements can make it difficult to determine the extent of the security measures needed. (ITU, 2005). (Sonnenreich, W. et al, 2006) posit that “it’s very difficult to obtain data about the true cost of a security incident (single loss expectancy (SLE)).” Typically, companies don’t track security incidents; they focus on fixing the problem rather than assessing the incident cost. Effects of botnets are anticipated to grow as networks become more powerful and high-speed interconnectivity becomes inevitable. Though, newer technologies with new powerful defenses may be introduced, (Hammock, 2010) posits that cyber-security researchers assume that the current situation is, primarily, due to adverse effects of interconnectivity.
Whereas the interconnectivity promotes opportunities for end-users to have socio-economic benefits, they also pose potential threats. Threats undermine the user’s confidence, while security and privacy breaches threaten the user’s trust. Stakeholder’s awareness and understanding of the relevance of secure Internet infrastructure are paramount. They involve a holistic approach, which encompasses legislative, regulatory, law enforcement and technological aspects. (Multi-Stakeholder Policy Dialogue)
(Farahmand, F. et al, 2008) integrated perceptions of risk, benefit, and incentives and developed a framework that aligned stakeholder perceptions of cyber-security risks.
(McFadzean, E. et al, 2007) found that the “decision-makers” perception of both internal and external risks has a major impact on cyber-security. These attitudes, opinions, and values have an effect on the perceivers’ actions and decision-making processes (Barnett & Vaicys, 2000) (Brewer, 2002) (Frey, 2000). (McFadzean, E. et al, 2007) inferred that, “decision-makers’ perception of risk” is co-related with their roles and actions, and influences their cyber-security strategy”. Some research works indicate that perceived risk is quantifiable and predictable (Slovic, 1987) (Johnson & Tversky, 1984).
Many entrepreneurs don't realize that small businesses are just as at risk for cyber-attacks as larger companies, but they are. According to a report "2018 Data Breach Investigations Report" by Verizon, 61 percent of data breach victims were small businesses. Regardless of the size of your business, cybercriminals who want to access your network will take advantage of any vulnerable attack surface. A single unprotected or improperly secured edge device can be all they need to access an entire system. It would be absolutely impossible to eliminate the risk of breaches entirely, however by proper investment and understanding the impact of cybersecurity in small businesses this potential security risk can be reduced.
Literature Review
The news often reports on incidents involving large corporations facing massive data breaches where the personal information of millions of consumers was potentially leaked. However, we don't often hear reports about the hacking of small businesses, mainly because these types of attacks aren't public knowledge.
“Organizations may recognize information security as an issue but it is often found that they do not have a full understanding of what they should be doing or how to go about it. Small organizations face the same security challenges as larger companies but there is a significant difference that exists depending upon the size of the organization involved” (Gupta & Hammond, 2005).
You’ve heard about the large-scale data breaches at Target, Home Depot, Sony, and other mega-companies. You would think that these big companies would do more to protect the security of their data and their customers’ data. After all, they have the resources to do it, and good security is just good business or is it?
According to a recent post from Dean (2015), a fellow for Internet Governance and Cyber-security at the School of International and Public Affairs at Columbia University, those major data breaches did not result in significant costs for the affected companies
For example, according to Dean (2015), the now infamous Sony Hack (widely attributed to North Korea’s attempt to block the release of the film The Interview) ended up costing the company about $35 million, less than 2% of the company’s projected annual revenue for 2014. The Interview is estimated to have grossed approximately $46.7 million, a good part of it likely as a result of the publicity related to the breach.
Many entrepreneurs don't realize that small businesses are just as at risk for cyber-attacks as larger companies, but they are. According to a report "2018 Data Breach Investigations Report" by Verizon, 61 percent of data breach victims were small businesses. Regardless of the size of your business, cybercriminals who want to access your network will take advantage of any vulnerable attack surface. A single unprotected or improperly secured edge device can be all they need to access an entire system.
The larger Target breach, which occurred in late 2013 and exposed over 40 million credit and debit card account numbers as well as 70 million other PII (Personally Identifiable Information) records, ended up costing the company about $105 million, after subtracting insurance reimbursement and tax deductions for breach-related expenses. That is less than 0.1% of the company’s 2014 sales.
The Home Depot breach was barely a pin-prick to the company. The breach resulted in 56 million stolen credit and debit card numbers, yet cost the company just $43 million, $15 million of which was covered by insurance, leaving a $28 million cost less than 0.01% of 2014 sales.
According to the post "Internet privacy in the digital age", based on 2012 small business security research, 60% of small businesses fail within 6 months of suffering a cyber-attack. That number is even more concerning because studies show that 31% of all cyber-attacks in 2012 targeted businesses with fewer than 250 employees. Additionally, 55% of small businesses with less than $10 million in annual revenue reported experiencing at least one data breach in the previous year, and more than 50% reported experiencing more than one.
Why do hackers target small businesses?
Breaches at big corporations, such as Target and Home Depot, make the headlines, small businesses are still very much targets for hackers. Stephen Cobb, a senior security researcher at antivirus software company ESET, said that small businesses fall into hackers' cybersecurity sweet spot: They have more digital assets to target than an individual consumer has but less security than a larger enterprise.
Gaining access to a multinational organization can be difficult. Larger organizations have the budget and the obvious need to protect their networks. When you collect personal data from around the globe or generate billions in revenue, you dedicate time and resources to protecting yourself. SMBs, on the other hand, don’t always focus on cybersecurity the way they should. And this is what cybercriminals are counting on.
Small business is easy to attack due to this complacent attitude and a lack of investment into cybersecurity measures. Since security breaches can be devastating to a small business, many SMB owners are more likely to pay a ransom to get their data back. And finally, small businesses are often the key for attackers to gain access to larger businesses that the SMBs work with.
The other reason small businesses are appealing targets is that hackers know these companies are less careful about security. According to Towergate Insurance, small businesses often underestimate their risk level, with 82 percent of small business owners saying they're not targets for attacks because they don't have anything worth stealing. However, there are several reasons why small businesses are a prime target for cyber attackers.
Impact of a Data Breach on SMBs
When a multinational or global company is attacked, the cost can be astronomical whereas, according to the Ponemon Institute, the average cost for small businesses to clean up after being hacked is about $690,000 and, for middle market companies, it is over $1 million.
To an outsider, this may seem less significant in comparison with the high-profile cases that make it to the top of the news cycle, but these costs represent a huge financial burden for an SMB. In fact, according to the article in Denver Post by Gary Miller (2016), 60% of small companies are unable to sustain their business more than six months following a cyber-attack. They frequently just don’t have the resources.
And, in addition to clean-up and containment costs, SMBs who collect personally identifiable information (PII) in Europe is now also going to have to deal with potential fines that arise from the European Union’s General Data Protection Regulation (GDPR). The regulation includes mandatory breach reporting rules that stipulate an organization must report a breach within 72 hours of detection.
The penalties for non-compliance are steep with fines of up to 20 million Euros or 4% of global annual turnover, whichever is higher. When you think of a small business not being able to survive a breach that costs under a million dollars to clean up, you can imagine what the outcome of such a heavy fine would be
“The 2006 Computer Crime and Security Survey, conducted by the Computer Security Institute in conjunction with the U.S. Federal Bureau of Investigation's International Computer Crime Squad
[CSI/FBI 2006], showed an alarmingly high number of businesses reporting difficulties with computer and Internet fraud. Losses due to computer security breaches totaled over US$ 52 million in 2006, a figure that is down 30% from the over US$ 141 million reported in 2004. It must be noted, however, that these figures relate just to the 313 respondents that advised the CSI / FBI survey of their results, and not all companies in the US. It was distributed to 5,000 companies in January 2006 for the response, showing a return rate of 6%” (Das & Nayak, 2013).
Benefits of Investing in Cybersecurity Protection
There are many business advantages to investing in cybersecurity defenses
1. Increase client and Consumer trust and it, in turn, increase the reputation of the company
2. Protection of most valuable Business assets
3. Reduce internal and external security threats
4. Many regulatory compliances, which in turn increase the business
5. Have peace of mind
Conclusion
The information is an asset that must be protected and cared for by the rules and procedures defined as security policies, in the same way, that we protect our financial and patrimonial resources. Small businesses are just as at risk for cyber-attacks as larger companies. Small business is easy to attack due to this complacent attitude and a lack of investment into cybersecurity measures. Small businesses are appealing targets is that hackers know these companies are less careful about security. Small businesses are appealing targets is that hackers know these companies are less careful about the security and small businesses underestimate their risk level as compared to the larger organization. Due to such underestimation, many small scale industry can’t sustain post cyber-attack. So I would recommend small and medium scale industries should also give cyber-security as same importance as larger companies.
References
2018 Data Breach Investigations Report. (n.d.). Retrieved from https://enterprise.verizon.com/resources/reports/DBIR_2018_Report_execsummary.pdf
Barnett & Vaicys. (2000). The moderating effect of individual's perceptions of ethical work climate on ethical judgments & behavoral intentions. 27 (4), 317-362.
Brewer, B. (2002). Perception & Reason. Oxford University Press.
Das, S., & Nayak, T. (2013). Impact of cybercrime: Issues and challenges. International Journal of Engineering Sciences & Emerging Technologies, 6(2), 142-153. Retrieved from http://www.ijeset.com/media/0002/2N12-IJESET0602134A-v6-iss2-142-153.pdf
Dean, B. (2015, March 4). Why companies have little incentive to invest in cybersecurity. Retrieved from https://theconversation.com/why-companies-have-little-incentive-to -invest-in-cybersecurity-37570
Dunn-Cavelty, M. 2010. ‘Cyber Security’ in A. Collins, Contemporary Security Studies. Oxford: OUP
Farahmand, F. et al. (2008). Incentives & Perceptions of Information Security Risks. Twenty Ninth International Conference on Information systems. Paris.
Frey, B. (2000). The Impact of Moral Intensity on Decision Making in a business context. 26 (3), 181-195
GDPR. (n.d.). Retrieved from https://gdpr-info.eu/art-5-gdpr/
Hammock, M. (2010, June). A Review of the Economics of Information Security Literature. Social Sciences Research Network (SSRN) .
Hansen, L. and Niessanbaum, H. (2009). Digital Disaster, Cyber Security, and the Copenhagen School. International Studies Quarterly, 53, pp. 1155-1175
Internet privacy in the digital age. (n.d.). Retrieved from http://mastersinlaw.champlain.edu/internet-privacy-in-the-digital-age/
ITU. (2005). A Comparative Analysis of Cyber-security Initiatives Worldwide. International Telecommunications Union (ITU).
Johnson & Tversky. (1984). Representations of Perceptions of Risk. Experimental Psychology, 55-70.
McFadzean, E. et al. (2007). Perception of Risk & the Strategic Impact of existing IT on Information Security Strategy at the Board level. 31 (5), 622-660.
Miller, G. (2016, October 23). 60% of small companies that suffer a cyber-attack are out of business within six months. Retrieved April 30, 2019, from https://www.denverpost.com/2016/10/23/small-companies-cyber-attack-out-of-business/
Multi-Stakeholder Policy Dialogue. (n.d.). Retrieved 2010, from www.intgovforum.org
Ponemon Institue. (2019, April). The 2019 Study on cyber resilient organization. Retrieved from https://www.ibm.com/downloads/cas/GAVGOVNV
Slovic, P. (1987). Perceptions of Risk. Science , 236, 280-285.
Sonnenreich, W. et al. (2006, February). Return on Security Investment (ROSI) - A Practical Quantitative Model. 38 (1).
Theyel, G., & Hofmann, K. (2012). Stakeholder relations and sustainability practices of US small and medium-sized manufacturers. Management Research Review, 35, 1110-1133. http://dx.doi.org/10.1108/01409171211281255
Warner, M. (2012). Cybersecurity: A Pre-history. Intelligence and National Security, 27 (5), pp. 781-799
Gupta, A., & Hammond, R. (2005). Information systems security issues and decisions for small businesses: An empirical examination. Information Management & Computer Security, 13(4), 297-310. doi:10.1108/09685220510614425