Cyber maturity in your business

CyberStartup

Free Member
Aug 15, 2023
6
2
I'm after some insights from this community. I'm feeling there's a gap currently in helping SMEs with improving their cyber posture. There's lots of information and tools out on the internet, but not in a format that SMEs can quickly digest, work out what does and doesn't apply to their business and then implement, either by out sourcing or implementing in house. In the business I'm currently in, I'm too close to the cyber industry to have an impartial opinion.

Could you help us validate, or debunk that hypothesis?
 
Good call on the terminology. Looking at the NCSC which has done some good stuff - they're using Cyber Security rather than cyber posture. Has anyone used the guidance and found it useful? Google NCSC SME to get the guide - can't post the link here.
 
Upvote 0
...The National Cyber Security Centre (NCSC); which many individuals do not know exists!

ncsc.gov.uk/section/information-for/self-employed-sole-traders

...The self-employed and small traders group represent the majority of the business landscape.

ncsc.gov.uk/section/information-for/small-medium-sized-organisations

What the government think are 'small businesses' can be surprisingly big; and have a different set of challenges and priorities.
 
Upvote 0
...The National Cyber Security Centre (NCSC); which many individuals do not know exists!

ncsc.gov.uk/section/information-for/self-employed-sole-traders
I doubt most sole traders give two hoots about cyber security.
 
  • Like
Reactions: MRQ
Upvote 0
Gobbeldygook.

Your customer wants to know one thing. WIIFM?
Isn't that fairly obvious though? I get that businesses just want to trade. but fact: cyber incidents are on the increase. businesses are more likely to be impacted by a cyber incident. So is there a lack of awareness? Or a lack of understanding of the risks posed?
 
Upvote 0
I doubt most sole traders give two hoots about cyber security.

I wouldn't disagree in the slightest... Most people generally, are led by the nose to buy into whatever fad or fashion happens to be the digital soup of the day; wherein there be dragons...
 
Upvote 0
Isn't that fairly obvious though? I get that businesses just want to trade. but fact: cyber incidents are on the increase. businesses are more likely to be impacted by a cyber incident. So is there a lack of awareness? Or a lack of understanding of the risks posed?
A lack of interest & engagement. 'It won't happen to me'.

In layman's terms, what are the realistic risks to me/my business? What are the sensible/practical precautions?
 
  • Like
Reactions: CyberStartup
Upvote 0
Simon our builder does everything on his phone. Doesn’t care about cyber anything.

I communicate using email and WhatsApp. I code on my Mac and upload to my server using svn. Secure passwords and 2FA. What else do I need?

Most people run micro businesses. A small business isn’t the same thing.
 
  • Like
Reactions: MRQ
Upvote 0
You still use Subversion? ?
Yes, because it works and is how Wordpress wants me to upload to their servers.

How else do you suggest I do this?
 
Upvote 0
Yes, because it works and is how Wordpress wants me to upload to their servers.

How else do you suggest I do this?
Subversion works fine but the most widely used source code management system is git which is why I was surprised. I haven't heard of people using svn in a long time.
 
Upvote 0
Subversion works fine but the most widely used source code management system is git which is why I was surprised. I haven't heard of people using svn in a long time.
It's a WordPress thing:


I also use sFTP when doing dev work as I don't need version control, I just need to upload files adhoc. Despite umpteen attacks daily it's never been compromised - mainly because they attack the server not my Mac. Once complete the files get zipped and delivered via dropbox.
 
Upvote 0
It's a WordPress thing:
Surely your risk here is with Wordpress? I'm assuming it's hosted externally and therefore must be getting scanned. Use plugins? A lot have been known to have vulnerabilities... Strong passwords to access the admin portal?
 
Upvote 0
Surely your risk here is with Wordpress? I'm assuming it's hosted externally and therefore must be getting scanned. Use plugins? A lot have been known to have vulnerabilities... Strong passwords to access the admin portal?
An explanation:

Your own WP site is your responsibility. If you choose a weak password and don't take advantage of the multiple levels of security available then expect to get hacked.

If you get a theme or plugin from the WP repository it will have been checked for insecurities and will be safe to use.

If you get a theme or plugin from any other source your are at risk as there are almost no vulnerability checks.

If you are a theme or plugin developer you submit either to WP for publication. Before your product is published in the WP repository it has to pass all sorts of checks. Once it passes you get an email with details of your SVN repository. You upload the plugin and it's good to go.

The system works well and in 10+ years of plugin development I've never had a problem. You just need to follow standard security procedures. It's not complicated.

Which brings us back to your question. A WP site owner has access to security plugins. So there is nothing you can sell them. They usually have gmail or similar so again nothing for you. They use SAAS for their accounts. They have trade accounts with their suppliers.

What can you offer that's going to improve their existing business?
 
Upvote 0
Still won't let me post links but:

google cyber trends 2023.

NCSC has a report which suggests 39% of businesses will face a cyber incident
I didn't find it in the first page of results.

First, define "cyber incident.

If 39% of businesses are going to "face a cyber incident" (in what timeframe BTW?), that's at all serious, then I suggest the rest of us are all going to be f****d by the fallout.

So from https://www.gov.uk/government/stati...rvey-2023/cyber-security-breaches-survey-2023

32% of businesses and 24% of charities overall recall any breaches or attacks from the last 12 months.


"Among those identifying any breaches or attacks, we estimate that the single most disruptive breach from the last 12 months cost each business, of any size, an average of approximately £1,100"

Note how they switch from talking about "breaches or attacks" to "single most disruptive breach".

What influence do the attacks have on the figures? Why are they glossed over?
 
Upvote 0
Interesting to note that phishing is still one of the top ways to gain access to systems. The Register wrote about this a while back and it seems that no matter how sophisticated your security systems you still get numpties clicking on links in emails.
 
Upvote 0
The irony is that the risks are huge and more common than some, including a few posts here, will believe.
I have sat on the regional cyber security council run by the police commissioner (as for a while I was a NED of a cyber security firm who covers some Government contracts), and the issue is that businesses who are impacted keep it secret. Many don't even report it as they fear reputation damage, loss of confidence, etc.

As a company, if we ever experience a period longer than one hour of peace where there are no script kiddies or hackers attempting to infiltrate our online systems we do a check to make sure we're still online ?. It's permanent, literally never stops.

We are regularly targeted by Phishing emails, and even just yesterday my finance team received an email from my wife (!?!) asking for details of the closing bank balance. The LOL is that my investors insisted I sack her and remove her shares before they invested, she's barred from any involvement in the company ?? (investors don't like family businesses to invest in). They often get emails from "me" asking for payments to be made or bank info, is rife, and these people have tried impersonating everyone from our chairman, me, my wife and various colleagues.

We run regular Phishing tests across the company testing staff knowledge and training.
In the past a member of staff did receive an email from a customer asking them to check some details which resulted in an automated forwarder being added to their account that sent all emails containing the words payment or invoice to a gmail account.

I have two friends who's businesses were shut down for weeks by ransomware and all their data being encrypted, again by an email a member of the staff thought was from a colleague. These are small companies with less than a dozen staff.

I would argue the plumber example @fisicx is the most vulnerable because they don't have the technical skills or support around them to put things in place, and they are a nice easy soft target. I've seen so much of it, heard so many horror stories, and my own business is under consistent barrage of it that many of our processes remain wet ink/paper based.
 
  • Like
Reactions: fisicx
Upvote 0
Gobbeldygook.

Your customer wants to know one thing. WIIFM?

Examples please.

I will give you my example. A couple of months ago I put up my website. It's still in test mode, which means it's not accessible for the wider public and yet, the minute I put it up (not speaking figuratively) I went into the logs and scanners were already attempting to find vulnerabilities.

So to answer Mark, Cybersecurity awareness means a lower likelihood of being attacked successfully.

If your business is online only, a successful attack will cripple you.

A better "cybersecurity posture", like the OP says, is like a better insurance policy for the business owner.
 
  • Like
Reactions: CyberStartup
Upvote 0
Thanks all. Great conversation. My takeaways are many and this has been a great insight into how business owners look at cyber.
  • I'm too close to it.
  • My terminology needs work if I'm talking to people who don't live in cyber.
  • It's a hard thing to convince other businesses that the investment is worth it.
 
  • Like
Reactions: AllUpHere
Upvote 0
A couple of months ago I put up my website. It's still in test mode, which means it's not accessible for the wider public and yet, the minute I put it up (not speaking figuratively) I went into the logs and scanners were already attempting to find vulnerabilities.
I could count on one hand the number of times I've been asked by a client, 'how secure is my site going to be?'. A borough council and an app builder did ask, as they had previously been hacked.

It's only around the time I send the client an extremely complicated username & password and talk them through how to activate 2FA that security is discussed.
 
Upvote 0

Latest Articles