Vulnerabilities / Threats

7/5/2018
09:00 AM
Steve Zurier
Steve Zurier
Slideshows
Connect Directly
Twitter
RSS
E-Mail
50%
50%

9 SMB Security Trends

SMBs understand they have to focus more on cybersecurity. Here's a look at the areas they say matter most.
Previous
1 of 10
Next

Image Source: Shutterstock via Profit_Image

Image Source: Shutterstock via Profit_Image

Two recent surveys offer insight into why small to medium-sized businesses (SMBs) are taking security more seriously.

In one study, by Webroot, 600 IT decision makers pinpoint their top concerns (think: phishing and ransomware), as well as areas where they are becoming more relaxed, due largely to increased security awareness and training, as well as much-improved access control management. 

"The press has made people aware of the threat landscape," says Charlie Tomeo, vice president of worldwide business sales at Webroot. "The bad actors keep coming out with new forms of malware, and everyone is getting hammered. There's a heightened awareness, and SMBs really know they have to do something."

The other study, by Kaspersky, examines IT budgets and high-level staffing considerations, given that "most SMBs can't afford a full-time CISO," says Jason Stein, vice president of channel at Kaspersky Lab North America.

We talked with both Tomeo and Stein to develop this list of SMB security trends. For more information, check out the Webroot report "Webroot SMB Cybersecurity Preparedness" and the Kaspersky study "On the Money: Growing IT Security Budgets to Protect Digital Transformation Initiatives." The Webroot study only involves SMBs, while the Kaspersky study covers both SMB and enterprise markets. 

 

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Previous
1 of 10
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
7/5/2018 | 2:30:52 PM
Webroot, ransomware, and other malware
Interestingly, Webroot has identified another issue with ransomware and security trends. In a conversation I had with one of their marketing people not long ago, I was told that Webroot had found that a lot of laypeople do not often do not necessarily identify ransomware as a virus or malware -- thus leading the company to explicitly mention and include ransomware in a recent survey asking people's experiences with malware.
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: White Privelege Day
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-6504
PUBLISHED: 2018-09-20
A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Cross-Site Request Forgery (CSRF).
CVE-2018-6505
PUBLISHED: 2018-09-20
A potential Unauthenticated File Download vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Unauthenticated File Downloads.
CVE-2018-14796
PUBLISHED: 2018-09-20
Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be used to perform a denial of service attack.
CVE-2018-14821
PUBLISHED: 2018-09-20
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated threat actor to intentionally send a malformed CIP packet to Port 44818, causing the RSLinx Classic application to terminate. The user will need to manually restart the software to r...
CVE-2018-14827
PUBLISHED: 2018-09-20
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally send specially crafted Ethernet/IP packets to Port 44818, causing the software application to stop responding and crash. The user must restart the software to regain functionality.