Malware, Mobile Lead SMB Security ThreatsOnline marketing and blogs are another key attack vector that small and midsize businesses need to guard, says Blue Coat Security researcher.
(click image for larger view)
Slideshow: Top 10 Security Stories Of 2010
The fact that attacks on SMB systems don't often generate headlines -- as with recent government or larger enterprise hacks -- might actually make them more vulnerable. Awareness is key, especially in organizations where IT resources are spread thin, as when all tech things fall on the shoulders of one manager or employee.
"For the SMBs who don't have the level of budget and security people that a larger organization might have, the problem's magnified," Larsen said.
He encourages systems administrators and other IT pros at SMBs to think about what kinds of attacks their company might attract and what the attacker might be after -- financial and customer information are two common targets -- and then adds some unsettling advice: "You have to start from the premise that whatever defenses you have put in place won't work."
That's not intended to cause hopelessness, but rather to keep SMBs alert and better able to identify unusual activity on their networks. That remains true, Larsen said, even when a smaller firm has enlisted the help of a vendor like Blue Coat.
Staying current with patches -- and not necessarily just waiting for automatic updates -- is also critical: "It's a necessary nuisance that you have to keep up with," Larsen said. Education, too, is important: Larsen recommends blogs such as Threatpost, Krebs on Security, and, of course, Blue Coat's own security blog as good ways to keep tabs on what's out there. Staying in the loop is especially important as newer technologies, such as HTML5, emerge and evolve.
Larsen said the rapid rise of online marketing channels such as social media and turnkey blogging platforms has likewise increased exposure to security risks. "It's become really easy for someone who sets up a Web site now to add all kinds of cool stuff to it just by clicking a check box," Larsen said. "By checking that box, I've now introduced another security hole."
A marketing manager with virtually no Web development chops, for example, can launch a company blog within a matter of minutes today. But if no consideration is given to the blog as a potential entry point for an attack and monitoring it accordingly, it could easily become vulnerable. Larsen said he encounters countless instances of malware that can be traced back to dead blogs and wikis, particularly those that are still running on older versions of the software platform.
In 2011, staying offline likely isn't a feasible sales and marketing approach for most SMBs. But doing business online requires a certain amount of vigilance.
"You now have a moral responsibility to keep an eye on how the bad guys might try to use your Web site as a way as a way to get into your customer database," Larsen said. "If you're not willing to do that, you need to find somebody who will, or have the discussion that maybe this isn't worth the hassle, it's not worth the risk."
2 of 2