Risk
10/27/2009
02:03 PM
Keith Ferrell
Keith Ferrell
Commentary
50%
50%

SMB Security Survey Shows Sorry State Of Cyber Safety

A new survey of small business cybersecurity offers a bleak picture of the state of things. Bleak unless you're a cybercrook, of course.

A new survey of small business cybersecurity offers a bleak picture of the state of things. Bleak unless you're a cybercrook, of course.The National Cyber Security Alliance (NCSA)/Symantec survey of close to 1,500 small businesses (51 or fewer employees) shows that when it comes to cybersecurity, most small businesses are neither fully aware of the problems nor prepared to meet them.

The two are not necessarily mutually exclusive. A small business that, for example, turns over security to a reliable and competent third-party, may not have deep awareness of the threat environment and its dangerous nuances, but is investing in protecting itself from those threats.

Evidently most of the businesses participating in the survey are doing neither.

To wit:

Only 28% of have formal Internet security policies in place

Only 25% provide even minimal Internet use/Internet security training to employees

Those companies that do train, do so less than 5 hours per year on average

The typical small business is flying blind when it comes to tech security:

86% of the survey respondents do not have an employee focused on Internet security

Which goes a long way to explaining the lack of awareness and policies.

It's unrealistic, I believe, to expect most small business to have a fulltime information security officer -- not in the budget.

But not in the budget shouldn't be matched by "not on the radar" when it comes to cybersecurity. Not in a world where the threats multiply hourly, the amount of customer and other data even the smallest businesses have grow almost as fast, and the variety of security choices and options at every budget level and business size are more robust than ever.

Of course, the businesses may not be any more aware of those options than they are of the threats they need to protect themselves from.

Lack of awareness is a fine breeding ground for overconfidence:

More than 90% of the businesses believe they are protected from malware and viruses

That belief is strong, too:

Barely half the businesses check anti-virus weekly to insure they're up to date

11% never check security tools to make sure they're current

Is it any wonder that crooks increasingly see small businesses as rich grounds for plucking data and dough?

The survey was conducted as part of National Cyber Security Awareness Month -- an initiative that clearly needs to run 24/7/365.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4632
Published: 2015-01-31
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 does not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certifica...

CVE-2014-7287
Published: 2015-01-31
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

CVE-2014-7288
Published: 2015-01-31
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.

CVE-2014-8266
Published: 2015-01-31
Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body field.

CVE-2014-8267
Published: 2015-01-31
Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the RID parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.