SMEs Wake Up – You ARE the low-hanging fruit for cybercriminals

August 2024 Information Security

According to an IBM report, on average, it takes nearly 287 days to detect and contain a data breach. A lot of damage can be done in such a long period of time. For one thing, your reputation can go down the drain, along with your dream of selling this great little business it has taken you 20 years or more to build. This is according to Ethan Searle, Business Development Director, LanDynamix.


Ethan Searle

Searle says many SMEs are under the illusion that their size makes them impervious to cybercriminals. “Too often, small business owners underestimate the knowledge, skills, and ability of cybercriminals to pick the low-hanging fruit – those are the businesses that are most likely to lack cybersecurity measures, with the excuse that it is too costly for a company of their size.

“Cybercriminals today are no longer single hackers, but entire collaborative networks on a global scale. It is delusional to think these organised hackers only target large corporations with vast resources. It is never a case of the bigger the organisation, the more attractive the hit will be because the yield will be bigger. In fact, the opposite is true; smaller organisations are more vulnerable due to lack of focus and investment in protection, making them prime targets for hacking, as they require minimum effort and resources,” says Searle.

He explains how a cyber breach can have far more sinister implications for small businesses than large enterprises with greater financial reserves and investment in recovery systems. “SMEs are characteristically founded by entrepreneurs with a vision to grow their business into a saleable entity; however, a cyber breach can do irreparable damage operationally, financially, and of course, reputationally. All these impacts can be devastating to the resale value of a business. SMEs need to ask themselves if they are willing to risk this outcome.”

Digital security awareness is vital

Searle says while modern technology has enabled access to business data from anywhere, at any time, it has also vastly expanded the attack surface and presented hackers with new points of entry.

“So, you have small business owners with a limited number of employees, but all of whom have been supplied with the necessary apps and tools that enable them to perform their duties to the highest standard and with speed and ease. However, many SMEs are unaware of what is called ‘Shadow IT’, which is when employees are using tools that are not officially sanctioned by the company. These are convenient access points for cybercriminals. In addition, the proliferation of smart devices broadens the opportunity landscape even further,” notes Searle.

Don’t overlook security patching

“Security patches are defined as software and operating system updates that aim to fix security vulnerabilities in a program or product. These updates literally ‘patch’ a hole in your defence, preventing a hacker or piece of malware from exploiting a way into your network. The Ponemon Institute has reported that nearly 60% of data breaches could have been prevented by better patch management. Updating your software — whether through a rapid alert or regular software updates — can help keep your information secure against evolving threats. Remember these software updates not only help your cybersecurity, but also your compliance, and a compliant business is a far more saleable entity.

“If you are clever enough to have taken on a managed service provider (MSP), security patches are often sent as push notifications from the MSP administering your operating system, email, and web applications. One of the major advantages for small businesses who take this approach is cost, often an outsourced team suits SME budgets better than managing a full internal team – that’s even if you can find the necessary skills to do it effectively. Patching is an important practice to protect your company against malware, ransomware, and hacking attempts. A good MSP will ensure relevant patches are applied to your devices as soon as possible, thereby greatly reducing the risk to your business. A skilled MSP will deliver not only best practices in cybersecurity, but advice on the right technology solutions that will grow and secure your business and turn it into a highly saleable entity.

“If you didn’t think your ability to sell your business is intrinsically linked to your technology deployments and security practices, think again,” Searle concludes.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Buying more security tools is not building a defence
Information Security
Sophisticated attacks are specifically engineered to bypass individual security tools, and companies absorbing the damage are those who have confused procurement with protection, says Richard Frost from Armata Cyber Security.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
BlueVision launches Fusion Cloud
BlueVision Information Security Products & Solutions
Most businesses have moved to the cloud, including Microsoft 365, Azure, AWS and more, and in doing so assume they're protected because they're using a reputable platform; however, the reality is somewhat different.

Read more...
Tools detect threats: Cyber resilience protects businesses
Information Security
If your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it ‘done’, then someone has sold you a story, not a strategy.

Read more...
Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.