Risk
5/7/2009
08:02 PM
Connect Directly
RSS
E-Mail
50%
50%

SMBs In Cyber Criminals' Crosshairs

When it comes to IT security, small and midsize businesses are in the unenviable position of being not only more attractive to criminals, but also having fewer resources to defend themselves.

When it comes to IT security, small and midsize businesses are in the unenviable position of being not only more attractive to criminals, but also having fewer resources to defend themselves.Botnet attacks may be hammering large enterprises, but even in these dire economic conditions big companies have resources to respond to immediate threats and create layered defenses that can help thwart intruders. At the other end of the spectrum lies the largely unprotected mass of consumers. Attacking the home network of your average soccer mom or NASCAR dad is easy pickings for a savvy cyber criminal. However, easy as it may be to breach consumer-level security, the rewards of doing so are slim.

Guess what? Cyber criminals can do an ROI calculation just like you can. And the result of that calculation leads them straight to your small or midsize business.


Don't Miss: SMBs Often Hit Hardest By Botnets


Why? Because you have stuff worth going after and you don't have the defenses of a large enterprise. As Phillip Lin, director of marketing for FireEye, a data protection firm, says, "The key reason SMBs might be more attractive to botnets is they have business-class machines but limited resources in IT to protect them. And their all-in-one security approaches can be easy to bypass."

And in an assessment that should make you shudder, these bad actors targeting SMBs aren't particularly focused in what they take from you. "It kind of a Swiss army knife of malware [they figure] they might as well get all the goodies they can out of" the SMB, says. David Setzer, CEO of an e-mail security service provider Mailprotector. In other words, this isn't smash and grab opportunism -- these crooks are backing up a truck and stripping your business down to the studs.

Unfortunately, there's no silver bullet to put a stop to these threats. Although small and midsize businesses do have one enormous advantage over large enterprises: nimbleness. That oft-cited ability to change direction and adapt to changing conditions has already proved a huge boon to SMBs in weathering the recession as businesses shift and dodge to meet changing markets. Security threats are not static and the ability to adapt -- to be nimble -- allows smart business owners to keep pace with evolving threats.

And smart security doesn't automatically mean big budgets. But don't my word for it. Instead, check out the on-demand virtual event bMighty bSecure: SMB Security On A Budget, where you'll find sessions that address improving and refining your business security in a host of areas all with today's budget realities in mind.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1544
Published: 2014-07-23
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger cer...

CVE-2014-1547
Published: 2014-07-23
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2014-1548
Published: 2014-07-23
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2014-1549
Published: 2014-07-23
The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not properly allocate Web Audio buffer memory, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and applica...

CVE-2014-1550
Published: 2014-07-23
Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.

Best of the Web
Dark Reading Radio
Listen Now Botnet Takedowns: Who's Winning, Who's Losing
Sara Peters hosts a conversation on Botnets and those who fight them.