Cyber
Small and medium-sized businesses (SMBs) and enterprise-sized businesses have overlapping needs as well as individual needs. From the hacker perspective, data is data, no matter where they get it so SMBs are just as likely to be targeted as enterprise organizations. However, SMBs typically have smaller budgets and less personnel, making them an easier target. Because of these limitations, SMB security needs to be approached more strategically thank with Enterprise security. One item that needs to be approached differently for SMBs than enterprises is how the company approaches security in the event of an attack. While enterprise organizations
have the budget and resources to have a reactionary approach to attacks, SMBs donʼt have the luxury of employing a security operations center (SOC) to react to attacks. Instead, SMBs should focus on a proactive approach to attacks, “one that uses a layered security strategy, detecting suspicious activity at each step of the breach ‘process ,̓ and putting a stop to a potential breach as early in that process as is possible” (Amigorena, 2018). Some examples of how to implement this approach are to ensure all software and operating systems remain updated to protect against vulnerabilities, installing anti-virus and anti- malware protection,
monitor logins and network activity, and conduct regular audits of data use. SMBs should also approach their security staff differently from enterprise organizations. Enterprises have dedicated IT teams with multiple people who are able to handle security responsibilities as well as standard IT needs. SMBs typically donʼt have the staff to approach security in this manner. According to Brooks of Netwrix, SMB IT teams “have to ensure continuous operation, patch the system, support users, repair hardware, develop security policies and make sure everyone is following them, educate other employees, deal with compliance auditors, perform backup regularly, fight against ransomware
and viruses, and much more” (Brooks, 2017). With an IT staff of two to three people, it is likely that their consistent daily routine of handling every IT matter will result in mistakes or potential threats being missed. Because of this recommends, hiring at least one employee whoʼs sole focus is security will ensure that there is always someone focusing on the SMBs security with few distractions. Alternatively, hiring a managed security service provider (MSSP) to handle security is another option for SMBs. By hiring an MSSP, SMBs can get corporate-level security from a team of experts that they otherwise wouldnʼt be able to get in-house due to budget limitations. Amigorena, F. (2018). Cybersecurity advice for
small and medium business. CPO Magazine. Retrieved from https:// www.cpomagazine.com/ cyber-security/ cybersecurity-advice-for- small-and-medium- business/ Brooks, R. (2017). Cybersecurity risks in large enterprises and SMBs. Netwrix. Retrieved from https://blog.netwrix.com/ 2017/06/28/ cybersecurity-risks-in- large-enterprises-and- smbs/