Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 13 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

How do SMEs fight off cyber-attacks?

by The Gurus
July 18, 2017
in This Week's Gurus
Threat Detection
Share on FacebookShare on Twitter

In this article I want to address some of the concerns that small and medium sized enterprises may have around cybersecurity, especially in the wake of the WannaCry ransomware attack and a continuous news flow around successful attacks on high profile companies. Does the fact that well-known brands are successfully attacked and breached mean that SMEs are even more at risk? If SMEs can defend themselves, how should they go about doing so? I’ll look to address these questions and concerns here, providing tips that can help SMEs weather the ever more frightening cybersecurity storm.
 
1) Where should SMEs be investing money for their tech security?
 
Historically, legacy antivirus has been a staple of security and, currently, the market is experiencing a natural evolution to next-generation antivirus (NGAV). SMEs should be looking to upgrade away from ineffective, signature-based legacy AV to an NGAV solution that can provide visibility across the enterprise. It’s critical for both SMEs and large businesses to know what’s going on with their business. NGAV can help provide that visibility. If SMEs are looking for a way to boost their security postures, implementing a free, two-factor authentication for email will make it harder for attackers to gain access to corporate emails. I would also recommend anti-phishing-based email services.
2) What are the priorities?
 
SMEs should look to protect their most valuable assets, which more often than not revolve around data. It’s very rare that attackers are able to access data directly. Most often they look to compromise endpoints and specific accounts. Easy investments SMEs can make today to protect access to endpoints involve implementing an NGAV solution and protecting accounts through multi-factor authentication. These investments will be well worth it and provide a significant ROI.
3) What security weaknesses do SMEs have that larger companies tend not to?
 
The biggest security weaknesses for SMEs are often the result of limited resources, both financial and personnel. If you look at the cost to implement above average security, the cost often exceeds the budget for SMEs. The additional reality is that as these businesses grow, their costs also increase. Security skillsets can be tough to come by and are often expensive. Very few capable security professionals are willing to be the lone security person on staff. If SMEs don’t have the money to hire robust security staff, they may feel hamstrung. There are a number of free and cost effective solutions, such as NGAV, that SMEs can implement without having to break their budgets.
 
4) Should they be updating their operating system?
 
Upgrading operating systems, while considered a best practice, is not by itself necessarily worth the cost. That is to say, simply updating the operating system is often not enough to help a business owner sleep better at night. For many modern operating systems, enabling the additional security configurations require their own level of maintenance that often exceeds those the business might gain from using specific security software. So, in principle, updating outdated OSs (especially those that are end-of-life) is a good practice, but it should not be the lone security measure considered.
 
5) How should they protect from cyber-attacks if they can’t afford a dedicated service?
 
Keep it simple. Keep your environment simple and keep your controls simple. Entropy differs across an environment. If an SME allows employees to bring their own devices, for example, that may breed problems across the enterprises. By keeping the environment homogenous and implementing and sticking to security standards, SMEs can go a long way in establishing good security hygiene from the start. SMEs should leverage their smaller sizes as an advantage.
 
6) What can happen in the worst case scenario?
 
SMEs are built on their brand and reputation. Unfortunately these smaller business are unable to absorb the same brand hit associated with a breach that larger organisations can. One compromise can have a much bigger impact and potentially cripple an SME. One wire transfer that doesn’t come in because it was redirected to an attacker’s account has the potential to bankrupt the business. While I wouldn’t say that’s extremely common, it’s certainly a fear that keeps SMEs awake at night.
This advice should help SMEs to feel more confident in their ability to successfully defend themselves in a world experiencing ever more cyber-attacks. SMEs shouldn’t feel that the fact big brands are being successfully breached means it is inevitable that they will be or that they shouldn’t invest in defence. The price is too high not to. Simple measures can be put in place to keep SMEs secure.

Tags: attackCybersecurityTechnology
ShareTweet
Previous Post

IBM Mainframe Ushers in New Era of Data Protection

Next Post

Sonatype 2017 State of the Software Supply Chain Report: DevOps Practices Reduce Use of Defective Open Source Components by 63%

Recent News

Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026
artificial-intelligence

The More Confident Organizations Are in Their AI Security, the More Likely They’ve Been Breached, New Research Finds

June 11, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol