Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

8/21/2019
08:45 AM
Kelly Sheridan
Kelly Sheridan
Slideshows
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

7 Big Factors Putting Small Businesses At Risk

Small organizations still face a long list of security threats. These threats and vulnerabilities should be top of mind.
Previous
1 of 8
Next

(Image: Rawpixel.com - stock.adobe.com)

(Image: Rawpixel.com stock.adobe.com)

Cybercriminals are increasingly taking aim at smaller organizations. This puts small and midsize businesses (SMBs) in a tough spot. Faced with a long list of cyberthreats, they also are operating with smaller budgets and staff constraints, both of which can lead them to make poor security decisions.

Over the past year, Alert Logic has observed a "steady increase" in attacks and changes in attack methods affecting SMBs. An analysis of 5,000 attacks per day across its customer base from November 2018 to April 2019 reflected a variety of ways small businesses leave themselves exposed. Depending on the industry, SMBs typically invest less in security programs, says Jack Danahy, senior vice president of security at Alert Logic. Their weak spots can put them at risk.

"It is more likely that an attack focused at an older, unpatched vulnerability, or a relatively simple phishing attack, will find more success at these smaller organizations," he explains. "So from my perspective, attackers are focusing on what they perceive as softer targets." Danahy also says he has "no doubt" of a higher level of successful public attacks on smaller businesses.

As George Anderson, product marketing director at Webroot, points out, some of the threats SMBs face today are different from the security challenges they faced just a few years ago.

"I think the changes have been very dramatic," he notes. As an example, he points to nation-state actors now targeting data SMBs hold. "That wasn't very common four to five years ago," Anderson explains, but activity has started to ramp up since it was first spotted back in 2016.

It's imperative small businesses know how to maximize their limited security resources. To do so, they must be well-versed in the threats and vulnerabilities putting them at greatest risk. While it's possible to have the same security as large firms, different steps need to be made. Reading up on SMB threats can help inform policies and procedures they should put in place.

Here, we outline the attacks SMBs should be aware of and the vulnerabilities putting them at risk. Did we miss anything? Feel free to add your thoughts in the comments.

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "5 Ways to Improve the Patching Process."

 

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
steven09
50%
50%
steven09,
User Rank: Apprentice
8/25/2019 | 7:41:26 AM
Useful Adnetwork
Wonderful post! a bundle of thanks for sharing this with your followers around the world. I found something new and classic here in this post and now going to share it with everyone via FB and twitter as well. Have you any idea about the AdFly Network? then check all the information about this wonderful network in 2019 and start using it.
Commentary
How SolarWinds Busted Up Our Assumptions About Code Signing
Dr. Jethro Beekman, Technical Director,  3/3/2021
News
'ObliqueRAT' Now Hides Behind Images on Compromised Websites
Jai Vijayan, Contributing Writer,  3/2/2021
News
Attackers Turn Struggling Software Projects Into Trojan Horses
Robert Lemos, Contributing Writer,  2/26/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Sure you have fire, but he has an i7!
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27217
PUBLISHED: 2021-03-04
An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device. Out-of-bounds reads performed by aes_remove_padding() can crash the running proce...
CVE-2021-22128
PUBLISHED: 2021-03-04
An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality.
CVE-2021-23126
PUBLISHED: 2021-03-04
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.
CVE-2021-23127
PUBLISHED: 2021-03-04
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.
CVE-2021-23128
PUBLISHED: 2021-03-04
An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat.