Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

10/23/2019
11:45 AM
50%
50%

10% of Small Businesses Breached Shut Down in 2019

As a result of cybercrime, 69% of small organizations were forced offline for a limited time and 37% experienced financial loss.

Ten percent of small businesses hit with a cyberattack in 2019 were forced to shut down as a result, researchers found in a new survey focused on the consequences of cybercrime for small and midsize businesses.

To compile the report, commissioned by the National Cyber Security Alliance and conducted by Zogby Analytics, analysts polled 1,006 small business decision-makers on cybersecurity topics. They learned 88% consider themselves a "somewhat likely" target for attacks, including 46% who believe they are a "very likely" target. Nearly two-thirds (62%) say security is a top priority. One-third of respondents have an in-house IT department with 10 or more people, 30% have an IT department with fewer than 10, and 55% have an annually updated cybersecurity plan.

The numbers say small businesses are preparing for a future attack: Nearly half (46%) of respondents feel "very prepared" to quickly respond to a security incident and limit its impact, and 58% have a response plan they could immediately put into action. One-third say they would be able to full operate their organization without computers. Bigger companies are better prepared: 73% of those with 251–500 employees have a prepared response plan.

Still, cyberattacks can be devastating. Nearly 30% of businesses surveyed have experienced an official security breach within the past year, a number that ranges from 11% for businesses with 1–10 employees, to 44% among companies with 251–400 employees. Following a breach, 69% of these respondents were knocked offline for a limited time, 37% experienced financial loss, 25% filed for bankruptcy, and 10% went out of business, researchers report.

Read more details here.

This free, all-day online conference offers a look at the latest tools, strategies, and best practices for protecting your organization’s most sensitive data. Click for more information and, to register, here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
10/27/2019 | 3:19:58 PM
Re: On small business support
"..they do not have the resources for a full CSirt department...."

This is a common problem in the industry, unfortunately.

 

 

 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
10/27/2019 | 3:09:17 PM
37?
"As a result of cybercrime, 69% of small organizations were forced offline for a limited time and 37% experienced financial loss."   37% seems to be a little bit small to me. We keep hearing about breaches. I would have expected a little bit bigger number.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
10/24/2019 | 8:23:08 AM
On small business support
I provided managed service support for small accounts a few years ago -- they do not have the resources for a full CSirt department of course or really an on-staff engineer skilled in the field.  So they are vulneable by default.  A real opening for consulting is to provide such support to clients with more emphasis on the cyber side than simple and relatively dull server management and workstation management.  The latter are endpoints of course but also good TEACHING AND INSTRUCTION to staff is a fine thing too.  That would solve a ton of problems right there.    Small firms have almost no financial depth too, so lack of income or hit to perception can drive business away real fast and their cashflow cannot tolerate that.  They also do not see the need for tech protection as miuch as larger organizations do that have, after all, a runnning CSirt department.  Smal business sees risk as small - so goes their name.  Risk = large but their size mitigates against that perception.  They ARE small so who would be interested in them?   Well, any hacker is interested ---- any one of them. 
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4095
PUBLISHED: 2019-12-10
IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158015.
CVE-2019-4244
PUBLISHED: 2019-12-10
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518.
CVE-2019-4521
PUBLISHED: 2019-12-10
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 165179.
CVE-2019-4663
PUBLISHED: 2019-12-10
IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245...
CVE-2019-19251
PUBLISHED: 2019-12-10
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.