Welcome Guest. | Log In | Register | Membership Benefits


Topics:   Security Views : SMB Security Tech Center

Four Must-Have SMB Security Tools

Regardless of their size, many SMBs still need to meet strict compliance regulations, such as PCI and HIPAA. In addition to any special requirements, there are a few security technologies every small business should have in place. Here are my four SMB security must-haves.

Jul 28, 2010 | 10:12 PM | 

By Jennifer Jabbusch
Dark Reading

Regardless of their size, many SMBs still need to meet strict compliance regulations, such as PCI and HIPAA. In addition to any special requirements, there are a few security technologies every small business should have in place. Here are my four SMB security must-haves.1. Firewall. It sounds passé, but firewalls are still the de facto solution for minimum security. Small businesses are no exception. I frequently hear vendors trying to coax SMB owners into boxes bigger than they need, with full redundancy and licensing out the yin yang. As expected, most small organizations will balk at the $20K-plus price tags that hang off these shiny new boxes. The truth is, for bandwidths typical in SMBs (let's say T1s up to 10Mbps), a small ASIC-based firewall even with gateway services (such as gateway anti-virus, anti-spyware, IDS or IPS) can be found for just a few thousand dollars. Even if it's not tweaked to perfection, some firewall is better than none. And no organization should rely on their Internet provider for this security.

2. Client anti-virus. Whether your small office is three people or a hundred, client AV is a must-have. Depending on the number of users, an organization may opt for boxed consumer licenses and manual management, or a centrally-managed AV solution. All mainstream AV vendors will have both options available, but the licenses may not be upgradeable or transferable. Meaning, if you buy AV in boxes at Walmart or Best Buy, you probably can't turn those into centrally managed client licenses if your needs grow or change. Take the time to do a little research and you'll be pleasantly surprised at the affordable licensing structure of centrally managed AV.

3. Password management tool. These are great little tools and I've found they're an easy and inexpensive solution for small offices that aren't using single sign-on or authenticating to a directory (such as Active Directory) for management. These tools allow a team or entire company to post, update, and share key passwords used in the organization. They can contain login info for bank accounts, the server admin account, email management or CLI logon for switches. They reduce the use of default passwords and re-use of shared passwords while making it easier to incorporate complexity into all credentials.

4. Backups. I can't overemphasize the importance of a good backup and disaster recovery plan. You don't have to have a fully-executed DR methodology, but if your small business currently has no backups, I urge you to start here as your next step in securing your business. From experience, I can say you never know when there will be a fire, a flood, or a disgruntled employee who decides to wreak havoc before leaving. The fire and the flood my company survived through, the latter has happened to small businesses I've worked with in the past. Even if you're not taking backups of all the computers, identify your key data -- such as accounting records, customer data, and anything critical to operating your business such as emails, website content, intellectual property and marketing materials or graphics -- and back it up. Look for software-based backups that can take regular snapshots of servers or storage, or consider a hosted online backup solution.

The first step is to keep backups locally. The next progression is to also find a remote site or hosted solution in case your location experiences a disaster or even theft.

Jennifer Jabbusch is a CISO and infrastructure security specialist at Carolina Advanced Digital. By day she architects enterprise security solutions and by night, well, she does the same thing. For Dark Reading, she melds her enterprise experience and intimate knowledge of small business operations to deliver relevant security guidance for SMBs everywhere.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



SMB Security Reports

report Small Businesses, Big Losses: How SMBs Can Fight Cybercrime
Small and midsize businesses are falling prey to cyberattacks that cost them sensitive data, productivity and corporate accounts cleaned out by sophisticated banking Trojans. SMBs are typically on the hook for these losses and lack effective means to prevent them. In this report, we explain what makes these threats so menacing, and share best practices to defend against them.

report Five Security Flaws, Five Security Fixes For Small And Midsize Companies
Take a sneak peek at data from the Dark Reading/InformationWeek 2011 Strategic Security Survey, with a focus on the five biggest problems faced by small and midmarket companies. You?ll get a look at key security practices and processes for managing the complexity of security; enforcing policies; assessing risk; preventing data breaches; and managing scarce IT resources.

report SMBs in the Crosshairs: Understanding the Threats, Defending the Business
Cybercriminals are not only exploiting small and midsize businesses -- they're targeting them. While thefts of hundreds of thousands or even millions of credit card numbers and personal information records make headlines, many small companies' accounts have been cleaned out. In this Dark Reading Tech Center report, we identify how SMBs are exploited, where their security fails and how they can shore up their defenses.

Other reports from the SMB Security Tech Center:




Featured Webcasts
Featured Whitepapers
Featured Reports