Cybersecurity for your SMME

Issue 6 2022 Information Security

In today’s interconnected world, effective cybersecurity is as important to the success of any business as capital funding, skills mix, innovation and good management. This is especially true since the widespread move to remote and hybrid working over the past two years, which has made both individuals and organisations more vulnerable to cyberattacks. And not only are users on open networks more vulnerable to these attacks, cybercrime is becoming more sophisticated every day.

Large companies have the benefit of firewalls, dedicated IT departments and advanced security protocols, but even they are vulnerable to cybercrime, so SMMEs have to be alert to the threat it poses to both business information and continuity. Yet many don’t know where to start when it comes to preventing cyber intrusions, data theft and malicious attacks.

Forewarned is forearmed

The first line of defence against cybercrime is awareness and vigilance. In 2021 alone, there were 230 million cyber threat detections in South Africa, with phishing attempts being the most common. Around 96% of businesses and organisations in the country were targeted by this form of attack during the course of the year, with the number targeted by data and business email attacks not far behind.

And these are no longer simple end-point attacks. Criminal syndicates have developed complex, multi-stage operations that are designed to compromise computer networks through their most vulnerable points, usually their people. All it takes is a careless click on a suspicious link in an email and the damage is done. This is how most cybercriminals gain access to sensitive information and bank accounts, or deliver malicious software like ransomware.

Ransomware, which is designed to block access to a computer system until a ransom is paid, has become a widespread threat, with 75% of known ransomware having been used to initiate attacks on three out of four organisations worldwide.

What’s the solution?

In SMMEs, where entrepreneurs and their staff often perform multiple functions, protecting individual and networked computers from attack can seem like an overwhelming task. There are, of course, some important steps that everyone who uses a computer should take.

For a start, it’s important not to use the same password on multiple platforms as this makes it more difficult for hackers who’ve discovered a password to gain access to all of your online accounts. You should also be vigilant of suspicious links in an unexpected email, even one that looks as if it could come from a known service provider. Cybercriminals mirror the mails sent out by trusted organisations, hoping to catch users unawares. In fact, it’s a good discipline never to click on a hyperlink in an email. Make it a practice to copy hyperlinks and open them separately in your browser instead. And always remember the golden rule: think before you click.

The importance of training

Ideally, all members of staff who make use of computers, whether standalone or networked, should attend a cybersecurity training course conducted by an established and reputable provider so that they can learn to understand cybercriminals and the way they operate. As much as individuals and businesses benefit from new technologies, so do hackers. Many make use of AI tools such as machine learning to mine for data that may make computers or networks vulnerable – and many even use bots to maximise the reach of their phishing attacks.

Cybersecurity skills are as important to a business as functional, financial and managerial skills – and training helps entrepreneurs and their staff to understand more than just the basics. Formal training will, for example, help them to recognise and strengthen vulnerable points in the business’s IT and data systems. They’ll also learn more about how AI works, about the metaverse and blockchain technology, and about how using these technologies can create system vulnerabilities. Most importantly, they’ll learn all about ways to protect the business’s technology and data systems.

The bottom line is that data is one of the most valuable assets in any business today and, with so much sensitive information now online, nothing can be left to chance.

Fourth Industrial Revolution Incubator is an enabling technology platform for SMMEs. Find out more at https://4iri.co.za/




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
AI augmentation in security software and the resistance to IT
Security Services & Risk Management Information Security
The integration of AI technology into security software has been met with resistance. In this, the first in a series of two articles, Paul Meyer explores the challenges and obstacles that must be overcome to empower AI-enabled, human-centric decision-making.

Read more...
Milestone Systems joins CVE programme
Milestone Systems News & Events Information Security
Milestone Systems has partnered with the Common Vulnerability and Exposures (CVE) Programme as a CVE Numbering Authority (CNA), to assist the programme to find, describe, and catalogue known cybersecurity issues.

Read more...