How cyber resilient really are businesses?

Aneesha Doal

Free Member
Jan 26, 2019
18
0
Would anyone know of the barriers preventing businesses to be 'cyber ready'

Are businesses actually prepared for attacks?
 
Entirely depends on the nature of the business. But, typically, most normal small to medium businesses use third party software which have the resources to maintain those problems (as a hypothetical example, using Stripe as your payment processor). Bigger companies or platforms which are more inclined to risk (fin-tech, data companies, gambling platforms) will normally have a team/freelancer ready in the event of an attack and will continuously update its platform to prevent such an event.
 
Upvote 0
Barriers?
Wasn't aware there were barriers preventing businesses buying in software and hardware to deal with what they perceive as the risks their business is likely to need protection from.


Except government limits on who can have automated lethal weaponry fitted inside their buildings.
 
Upvote 0
Entirely depends on the nature of the business. But, typically, most normal small to medium businesses use third party software which have the resources to maintain those problems (as a hypothetical example, using Stripe as your payment processor). Bigger companies or platforms which are more inclined to risk (fin-tech, data companies, gambling platforms) will normally have a team/freelancer ready in the event of an attack and will continuously update its platform to prevent such an event.


In relation to your response, would you agree that SMEs associate cyber security to be solely an IT/technical issue rather than everyone's responsibility in the organisation?
 
Upvote 0
Barriers?
Wasn't aware there were barriers preventing businesses buying in software and hardware to deal with what they perceive as the risks their business is likely to need protection from.


Except government limits on who can have automated lethal weaponry fitted inside their buildings.

When I say barriers, I am referring to the obstacles preventing organisations from undertaking cybersecurity strategies. For example, would you agree that the cost of investing in cybersecurity is a major barrier?
 
Upvote 0
Are businesses actually prepared for attacks?
Mine gets attached everyday. Was pretty simple to protect myself.

The bloke who cleans our windows has a password on his phone so he’s well protected.
 
Upvote 0
My wife knows how to log in to the PC but she isn’t really a threat. It’s hackers from Russia who seem more determined.

The window cleaner said he dropped his phone last week but he has a decent case so he was protected from internal threats.
 
Upvote 0
To get any sort of sensible response you will have to ask more specific questions.

In relation to your response, would you agree that SMEs associate cyber security to be solely an IT/technical issue rather than everyone's responsibility in the organisation?

Of 5.6 million business in the UK (2018) 77% were non employing. So, it doesn't matter if cyber security is considered IT/Technical or not, the risk assessment and the solutions are all at the door of the business owner.

If a business uses Office 365 or G-Suite the cyber security risk can be minimised just by using the tools available in the platform.

Why do you ask?
 
Upvote 0
To get any sort of sensible response you will have to ask more specific questions.



Of 5.6 million business in the UK (2018) 77% were non employing. So, it doesn't matter if cyber security is considered IT/Technical or not, the risk assessment and the solutions are all at the door of the business owner.

If a business uses Office 365 or G-Suite the cyber security risk can be minimised just by using the tools available in the platform.

Why do you ask?




I am a PhD researcher focusing on evaluating the cybersecurity readiness of UK SMEs. In order to achieve this, I am trying to build a general consensus of the current levels of preparedness so I can be in a position to offer solutions to improve the levels of cyber readiness. I am in my 2nd year so I am aiming to generate leads for potential interviewees to assist in my research.
 
Upvote 0
When I say barriers, I am referring to the obstacles preventing organisations from undertaking cybersecurity strategies. For example, would you agree that the cost of investing in cybersecurity is a major barrier?

Compared to not investing in cybersecurity?

No.

What they end up investing in may well be determined by risk assessment or some very persuasive salesman - but realistically is there any but the smallest businesses who cannot afford any protection?
 
Upvote 0
So you plan to pitch some sort of service if people tell your they are unprepared.

But as Chris suggested, most businesses don’t need cyber security. Many use a range of online tools or a password protected computer. They won’t need what you are offering.
 
Upvote 0
I am a PhD researcher focusing on evaluating the cybersecurity readiness of UK SMEs. In order to achieve this, I am trying to build a general consensus of the current levels of preparedness so I can be in a position to offer solutions to improve the levels of cyber readiness. I am in my 2nd year so I am aiming to generate leads for potential interviewees to assist in my research.

Perhaps helps if you provide all this info to start with. Some may be unwilling to engage with interviewers.
 
Upvote 0
My wife knows how to log in to the PC but she isn’t really a threat. It’s hackers from Russia who seem more determined.

The window cleaner said he dropped his phone last week but he has a decent case so he was protected from internal threats.

My father knows how to log into a PC. He's had multiple viruses, keyloggers and a couple of times had ransomware.
Knows enough to use, not enough to protect himself.

He's a lovely guy but not one I allow on my computers or my network at all.
 
  • Like
Reactions: fisicx
Upvote 0
To get any sort of sensible response you will have to ask more specific questions.



Of 5.6 million business in the UK (2018) 77% were non employing. So, it doesn't matter if cyber security is considered IT/Technical or not, the risk assessment and the solutions are all at the door of the business owner.

If a business uses Office 365 or G-Suite the cyber security risk can be minimised just by using the tools available in the platform.

Why do you ask?



Even sole traders can have an online presence. Anyone who is connected to the internet is at risk.
 
Upvote 0
So you plan to pitch some sort of service if people tell your they are unprepared.

But as Chris suggested, most businesses don’t need cyber security. Many use a range of online tools or a password protected computer. They won’t need what you are offering.



No not a service. As a PhD is an academic work, I would be proposing a theory or a holistic framework for businesses on how they can enhance their cyber readiness.
 
Upvote 0
Even sole traders can have an online presence. Anyone who is connected to the internet is at risk.

And many people do know they are at risk and at least use software to reduce the risk.

Your local shop owner has far more problems to worry about than just the one your research focuses on.
 
Upvote 0
And many people do know they are at risk and at least use software to reduce the risk.

Your local shop owner has far more problems to worry about than just the one your research focuses on.

Like I previously mentioned, anyone who is connected to the internet is at risk. Whether they acknowledge this or not is another matter. A lot of SMEs feel that they aren't as vulnerable or their information is not as valuable. But they are wrong, as latest cyber breach reports demonstrate SMEs are equally vulnerable if not at greater risk of being attacked.
 
Upvote 0
And telling it partway through doesn't do the trust element you need much good either.

I understand where you are coming from and I have no intention of deceiving anyone on here. My questions were nothing more than generating an idea of the current debates
 
Upvote 0
Like I previously mentioned, anyone who is connected to the internet is at risk. Whether they acknowledge this or not is another matter. A lot of SMEs feel that they aren't as vulnerable or their information is not as valuable. But they are wrong, as latest cyber breach reports demonstrate SMEs are equally vulnerable if not at greater risk of being attacked.

Yet you seem to miss that business owners can do their own risk assessments or have others do risk assessments for them.
Including cyber.

You feel they are at risk, great - show them. Just don't take it personally if someone ignores you because they do not accept you know what you are talking about.

I have a small ecommerce business. Around 7 or 8 emails a week about improving my cyber security from businesses around the world. Its low email numbers compared to website developing and ebay shop emails but its a few hundred emails a year.
Of which your email, if you sent one out, would be one more.
 
Upvote 0
I understand where you are coming from and I really appreciate your advice and shall take it on board. If businesses are seeking external support or devising their own risk assessments, then great! All I am saying is that there is always room for improvement.
 
Upvote 0
If businesses are seeking external support or devising their own risk assessments, then great! All I am saying is that there is always room for improvement.

I think you are missing an essential element here. Your demographic, UK SME, is far too broad. The 5.6 million SME businesses in the UK (2018) incorporates a wide range of technical capability. This runs from @fisicx window cleaner to those who sell high grade technical expertise to global corporations. The former probably runs less Cyber risk than the latter and the former is, probably, less capable of mitigating the risk that exists.

A simple percentage return on an SME analysis would be worthless.
 
Upvote 0
A lot of SMEs feel that they aren't as vulnerable or their information is not as valuable. But they are wrong, as latest cyber breach reports demonstrate SMEs are equally vulnerable if not at greater risk of being attacked.
The reported cyber breaches tend to be large organisations with big datasets.

Your average SME isn’t going be attacked in the same way. They are more likely to be the victim of a phishing attempt.

Maybe if you told us a bit more about the sort of protection you are researching you will get a better response.
 
  • Like
Reactions: Aneesha Doal
Upvote 0
There's already a Government-managed cyber framework in place, Cyber Essentials, run and operated by the National Cyber Security Centre.

It's a baseline standard for meeting the basic cyber-security elements for a small and medium business.

The UK Government are also pushing it hard with a voucher incentive scheme (worth around £1000 a pop; to get your business up to code and then certified).

The next steps would be the worldwide ISO 27001 certification framework: https://en.wikipedia.org/wiki/ISO/IEC_27001

Cyber Essentials is probably the closest you're going to get to what you're trying to achieve. And even then, it might be too much for a micro-business or sole trader.
 
Upvote 0
I'm not sure that the subject requires a doctorate to understand.

Cyber-readiness is determined by the level of priority attached to it by the decision-maker - very little in the case of most owner/managers until they experience a disruptive attack directly - and the budget that they allocate to it - which based on evidence here, may be simply to purchase AV software, etc.

But at least those helping with your research will be pleased that they might benefit from the outcome of it, by you offering something of tangible value to protect them from attack...

No not a service. As a PhD is an academic work, I would be proposing a theory or a holistic framework for businesses on how they can enhance their cyber readiness.

errm, no then!
 
Upvote 0

Latest Articles