How do we make SME owners care about cybesecurity

D

Deleted member 360015

I have been desperately trying to get SME owners to care about their cybersecurity but I have got very little response from their sides. Since this is an SME forum I was wondering if anyone had any idea why that could be the case. We ("experts") know that the risk is all too real and that a cybersecurity threat left unattended (ransomware as an example) could bring a small business to its knees and potentially put it out of business. We have also made ourselves available for free and provided the awareness that could get these people to understand their exposure risk but these actions, too, got little-to-no traction.

Why, then, I wonder such a lack of interest? Is it the message? Is it the content? Is it the language used? Any opinion will be much appreciated as it might shed some light on the matter.
 
Small businesses don’t care because it’s unlikely to affect them. Cyber criminals aren’t going ransom Bob the builder and his godaddy website.
 
Upvote 0
Define what, in your mind, is an SME. Are you, in fact, talking about someone like Bob the builder, as fisixc mentions above? Or do you mean someone with 10 employees turning over a million a year? Both could be described as SMEs.
I was about to reply on this as it is, indeed, important to specify it. Let me go with the official EU definition of SMEs, which can be one of the following:

Micro SME: < 10 people; < 2M turnover
Small SME: < 50 people; < 10M turnover
Enterprise SME: < 250 people; < 50 M turnover
 
Upvote 0
If I was in the market for cybersecurity, I would expect to see a professionally crafted website (the face of your business), not a cheap, cartoon style Godaddy template.
Fair point. Too many cybersecurity sites are (way) too serious and may seem unaffordable and out of touch with an SME but I get the point, thanks!
 
Upvote 0
Small businesses don’t care because it’s unlikely to affect them. Cyber criminals aren’t going ransom Bob the builder and his godaddy website.
I wish that was the case :( An SME could be just targeted by chance (not all attackers know who they are dealing with at the beginning) and having *any* web presence is a risky business if you don't have at least the essential protections. ENISA (EUROPEAN UNION AGENCY FOR CYBERSECURITY) regularly issues stats and reports that shows that, indeed, what you are saying is, unfortunately, not the case. Like in this example (taken from one of the latest reports):

"

The majority of SMEs (>80%) process critical information, making cybersecurity a key concern.


The term critical information as defined in the survey refers to information that if it is stolen or lost, the organization would face serious legal repercussions and the owners of the personal information could encounter significant or even irreversible consequences (e.g. misappropriation of funds, blacklisting by financial institutions, property damage, loss of employment, subpoena, worsening of health, inability to work, long-term psychological or physical ailments,).
 
Upvote 0
I'm really curious how exactly you tried making SME owners care about cyber security? Perhaps, the problem is not that they did care. Maybe it was through some cold emails everybody just deleted without reading?
 
Upvote 0
A couple of points here

First, SME is far too broad as a target market (its pretty much a media cliche covering 98% of businesses. Focus on a target to make your message relevant and specific.

Second. You are essentially selling insurance. Nobody is interested in cyber security, they might be concerned about the potential repercussions of not being secure.


Quantify it. Give examples that will resonate with them.
 
Upvote 1
I was about to reply on this as it is, indeed, important to specify it. Let me go with the official EU definition of SMEs, which can be one of the following:

Micro SME: < 10 people; < 2M turnover
Small SME: < 50 people; < 10M turnover
Enterprise SME: < 250 people; < 50 M turnover

Under £2 million? I would hazard a guess that the majority of people who come to or join this forum are barely reaching £200,000, although there are lots of exceptions.

For most 2-3 man bands, cybersecurity risks are no greater than their personal risk. You aren't going to sell cybersecurity to Aunty Doris from no. 15, so why would you expect to sell it to Doris the florist? If Doris is a reasonably modern florist, she'll have some antivirus installed, and that's as far as he ever needs to go.

In the same way that you'll never convince a business that keeps all their stock in a lockup that they need to take the same H&S precautions as in an Amazon warehouse, you'll never convince a small business that they should take cybersec as seriously as say, a bank. And if the examples of cyberattacks on banks, supermarkets, the NHS etc. are what you are using to convince them, you'll quickly be dismissed as a scaremonger.

In fact, my main job is for a company that falls into the "Small" category above. We take our own cybersecurity very seriously because we sell and manage cybersecurity, amongst other things, to much larger firms who are themselves at risk of cyberattacks and terrorism. But we do not waste time or effort selling high end products to our smaller clients, unless they are in high-risk sectors, because they simply don't need or want it.
 
Upvote 0
Why, then, I wonder such a lack of interest? Is it the message? Is it the content? Is it the language used? Any opinion will be much appreciated as it might shed some light on the matter.
In response to what you've posted, who knows. You've not shared any of that detail, nor who you are targeting.

The EU definition is not a target, nor who you should be targeting. That's almost all businesses other than the very large and corporations. To try target and educate SMEs as part of a marketing or content plan would be a waste of time and doomed to failure, unless you have an enormous marketing budget.

That's not how marketing works. Unless you're the government, there is no point in trying to educate SMEs about cyber security. Marketing works by targeting people who have a problem and are looking for a fix, or who already know they need a particular solution and are looking for it.

It sounds like you are targeting the wrong people, with a service or product they're not interested in. Tell us who you have targeted, and how, plus what that content and messaging looks like. That might help you get to the heart of the problem.
 
Upvote 0
I have been desperately trying to get SME owners to care about their cybersecurity but I have got very little response from their sides.
Why?

Why are you desperate about it? Does this comes across well? Do you like dealing with desperate companies?

Probably not.

As has been mentioned, the term SME is completely meaningless, covering 99% of businesses in the EU.

Getting back to basics, what is Cyber Security? What do you actually sell?
 
Upvote 1
I'm really curious how exactly you tried making SME owners care about cyber security? Perhaps, the problem is not that they did care. Maybe it was through some cold emails everybody just deleted without reading?
Ah, no. We don't do these things. It was mostly reaching out to potentially interested customers via LinkedIn offering a (totally free!) risk assessment. But absolutely no-one seemed interested.
 
Upvote 0
A couple of points here

First, SME is far too broad as a target market (its pretty much a media cliche covering 98% of businesses. Focus on a target to make your message relevant and specific.

Second. You are essentially selling insurance. Nobody is interested in cyber security, they might be concerned about the potential repercussions of not being secure.


Quantify it. Give examples that will resonate with them.
Good point. Much appreciated.
 
Upvote 0
What are you saying to these potential customers, what's your pitch?
After all the comments I've received (and thanks everyone for spending the time to write here!) I think I will need to "niche down" and make a clear value prop!
 
Upvote 0
Thanks SO MUCH to everyone who pitched in the conversation. I know that time is precious for everyone so I greatly appreciated your chiming in. I will treasure your comments and... well... go back and reflect :). I care about making businesses more secure first and selling later!
 
Upvote 0
@paolo-bc - stop selling cybersecurity and start selling the benefits of a system assessment.

You need to get the small engineering company making high tech widgets realise that an assessment will lower their costs, increase production and improve company well being. If it doesn't then they won't be interested.

Note: your assessment questionnaire needs a lot of work if you are going to get people involved. I just gave up.
 
Upvote 0
@paolo-bc - stop selling cybersecurity and start selling the benefits of a system assessment.

You need to get the small engineering company making high tech widgets realise that an assessment will lower their costs, increase production and improve company well being. If it doesn't then they won't be interested.

Note: your assessment questionnaire needs a lot of work if you are going to get people involved. I just gave up.
Thanks for your feedback Graham (?) and for attempting the assessment. *Usually* these types of assessments run over 100+ questions and they are *so technical* that, if you can answer the question, you probably already know what needs to be done. I have tried to make mine (a) as little as technical as possible and (b) as short as possible, or so I thought (!). Can I have more feedback on what you found taxing? The lenght? The questions? That will give me something to work with from a "real world" point of view.
That will be much appreciated!

PS: You were almost done ;-)
 
Upvote 0
Website reviews are only permitted for business members.

But it was the length, the questions, the limited options to answer and so on. I’d expected you to give me a call to find out more about my business.
 
Upvote 0
Spamming by email or spamming by LinkedIn is pretty much the same thing.
Maybe so. But I wasn't selling - I was trying to help. There is an interesting picture that, to me, really captures the issue that non-tech companies face when it comes to cybersecurity. Since I don't seem to be able to attach a picture, let me try to reproduce it to the best of my ability: imagine a Venn Diagram with two circles that (slightly) overlap; on the left, that is the "perception" of reality that we have (in our case, how I think my business is secure, or not); the other circle on the right is the "factual" reality (or in this case what we should know and that we don't). In most cases, these two circles are quite far apart, unfortunately, and that creates either a false sense of security or, in some cases, an unnecessary fear. Either way, in my view, the job of a cybersecurity professional is to make sure these two circles overlap as much as possible. Hence, my frustration ;-)
 
Upvote 0
Website reviews are only permitted for business members.

But it was the length, the questions, the limited options to answer and so on. I’d expected you to give me a call to find out more about my business.
Agreed. The best way to gather this info is on a live conversation but the point of the survey was really to show that the two circles in my mental Venn diagram are not aligned and this should at least spur the interest from the other party to understand. I am glad to review these questions with you if you are genuinely interested in finding out more about them.
 
Upvote 0
Upgrade your membership and I and others can help you refine the questions.

You really need conditional fields.
 
Upvote 0
Agreed. The best way to gather this info is on a live conversation but the point of the survey was really to show that the two circles in my mental Venn diagram are not aligned and this should at least spur the interest from the other party to understand. I am glad to review these questions with you if you are genuinely interested in finding out more about them.
Yes, but you're missing the point completely, and that's why you're failing to gain any traction here.

The venn diagram sums up your issue, you're basically saying reality and perception are far apart. However, the perception of most of these people is that they are fine, they don't need your cyber security. That may not actually be the case, but that's irrelevant, they think it is.

So, how do you help them (in reality sell to them, as that's what they think you're doing), you need to show them that they need cyber security. This could be by running some sort of analysis of their current setup to expose the flaws, but they are very unlikely to fill in a questionnaire, as they don't think they have an issue.

This is why businesses generally market to people with fixes for problems, or those looking for particular solutions. Unfortunately, selling to (or educating) people who don't know they have a problem is a waste of time, as they have almost zero interest in what you're saying/selling, as they don't think they need it.
 
  • Like
Reactions: fisicx
Upvote 0
But I wasn't selling - I was trying to help
Why do people say things like this?

Lets imagine for a minute that you're trying to help and that's what you really want to do.

Great, create free videos and put them on YouTube/LinkedIn; make sure that the videos explain all of the issues and how to resolve them. Start with a super basic dummies guide—"no, that email isn't from a Nigerian Prince"—and run right through setting all the security options in Office 365 premium, AWS, Unix servers, Wordpress, and anything else you can think of correctly.

Then, write a series of books that follow the same structure, going from "Daddy, should I click this link" to Advanced Website Penetration Testing. Give all of the books away for free.

Then, start doing talks, find small business groups, talk to people and then share the videos on YouTube.

Create apps that analyse and recommend, like antivirus software, and give this away free, too.

Then, when people watch, read, attend, download, let them come to you and ask for advice and to hire you.

It works, in fact it works very very well, but you've got to do all the years of free stuff first.

Thats assuming of course, that you "care about making businesses more secure first and selling later"

Spamming people on LinkedIn and trying to sell them stuff isn't part of the above.

As an aside, hiring someone you've never heard of because they message you on LinkedIn is a very big cyber security, isn't it?
 
Upvote 0
It's not unusual (as Tom Jones said), but your knowledge and passions for systems is seriously obstructing your marketing.

The most basic rule of marketing is that your prospect doesn't care what you are selling.

They care about how it will improve their life or business. (WIIFM?)

  • Solve a problem.
  • Address a fear.
  • Create an opportunity.
  • Give competitive advantage
  • Flatter their ego etc etc
Fear is a tricky sell - best converted into benefits.

Fear of data breach = Benefit of full compliance.

Above all, speak the language of your prospect & their business, not the language of a cyber-security geek!
 
  • Like
Reactions: ctrlbrk
Upvote 0
Many years ago when ISP's were sending out insecure routers I set a young lad up with a laptop & WiFi antenna. He'd get his mum to drive him around housing estates & every 'open' WiFi he detected he'd drop a note through their doors explaining that their WiFi router was unprotected & instructions on how they could set a password, also offering his services to do it for them for £10. He made a fortune, so much £££'s that he bought his mum a new car & paid most of his way through Uni. It wasn't just about securing the routers, it was everything about computers in general. For £10-£20 he'd sit with 'em & show 'em how to do it, install the printer, upgrades etc, but the notes through the door kicked it all off . . . . !
 
Upvote 0
I have been desperately trying to get SME owners to care about their cybersecurity
Why? Because you want to sell something to them?

Smaller companies, who can take simple steps to dramatically improve security are more focused on making money and surviving! Maybe you could give them 10 simple steps to follow to improve things.

Assuming you are selling something, your target audience is businesses that have an IT person, but they are employed to know what you want to sell - the steps to security are probably the same, whoever applies them!

As mentioned, knowing who your target audience is (SME is too wide a net) will help you preach better!
 
  • Like
Reactions: NickGrogan
Upvote 0
Many years ago when ISP's were sending out insecure routers I set a young lad up with a laptop & WiFi antenna. He'd get his mum to drive him around housing estates & every 'open' WiFi he detected he'd drop a note through their doors explaining that their WiFi router was unprotected & instructions on how they could set a password, also offering his services to do it for them for £10. He made a fortune, so much £££'s that he bought his mum a new car & paid most of his way through Uni. It wasn't just about securing the routers, it was everything about computers in general. For £10-£20 he'd sit with 'em & show 'em how to do it, install the printer, upgrades etc, but the notes through the door kicked it all off . . . . !
i was going to say why not have a tool which just looks to see if they have open ports - click here to see if you are at all secure - if I can see xyz you are not and should carry out these simple safegaurds. Or if you want more in depth advice contact us.

We went in with a company in 2009 they wanted us to merge the networks but as all of their machines had permanently open remote access to allow their lazy 3rd party support guy to do things I refused. We sat there behind our Linux CentOS server and in the next 10 years had zero security issues (to the best of my knowledge) whilst they had several major virus attacks and a some kind of attack that corrupted their server. They needed security but wouldnt have bought from you as the person they used for support was causing the vulnerability and they had no way of knowing (wouldnt listen to me )
 
Upvote 0
I did add some conditions already but of course there is always room for improvement. I guess a compromise will need to be found between the length of the survey and the details that are required to give meaningful results.
 
Upvote 0
Unfortunately, selling to (or educating) people who don't know they have a problem is a waste of time, as they have almost zero interest in what you're saying/selling, as they don't think they need it.
Wise words.
 
Upvote 0
All jokes aside, it really is a serious problem and I do agree with you that there isn't a lot of emphasis on cyber security for SMEs, particularly small businesses. I wanted to jump in before reviewing your website, @paolo-bc. Not having cyber security in place is a bit like not locking up the the front door! :oops:

It's most likely down to knowledge and budget, and perhaps not having the experience of a cyber threat and just generally unaware of the potential imminent threat it as on your business. Anyone can be a target, no matter your size. So there's needs to be an emphasis that it can happen to anyone.

Case studies of victims would be a great start. It's a very interesting topic, especially as we're all digitalising at great speeds, and I think there's a lot of content you could explore there too!
 
Upvote 0
@fantheflames , I have recently run a brainstorming session and here are my top 5 reasons why small businesses might not care about cybersecurity - and how to tackle these. Interestingly, they are very similar to your analysis:

  • Top 5 objections and how to tackle them
    • using the cloud is 'secure'
      • explain the concept of 'shared responsibility' model
    • i don't use 'the cloud'
      • teach them the importance and the risks of 'shadow it'
    • I don't need to worry about my security &
    • no-one is after me
      • stats show that everyone can be a target today
    • I don't need to comply
      • educate about who regulators are targeting with their laws and how this could apply to them
 
Upvote 0
Don’t use the word cybersecurity.

Talk about business failure and consequences of data breaches.

Provide case studies of companies who thought they were safe but you showed them how insecure their systems.
 
Upvote 0
@fantheflames , I have recently run a brainstorming session and here are my top 5 reasons why small businesses might not care about cybersecurity - and how to tackle these. Interestingly, they are very similar to your analysis:

  • Top 5 objections and how to tackle them
    • using the cloud is 'secure'
      • explain the concept of 'shared responsibility' model
    • i don't use 'the cloud'
      • teach them the importance and the risks of 'shadow it'
    • I don't need to worry about my security &
    • no-one is after me
      • stats show that everyone can be a target today
    • I don't need to comply
      • educate about who regulators are targeting with their laws and how this could apply to them
That's very interesting! Thank you for sharing.

I think it's important that these are very obvious on your website. I'd suggest, as you're working with a marketing agency that could help you with this, create a quiz that helps users determine how secure their online security and setup is. A diagnostics if you will!
 
Upvote 0
.create a quiz that helps users determine how secure their online security and setup is. A diagnostics if you will!
They already have one of these. And it need a lot of rework. I couldn't even answer some of the questions.
 
  • Like
Reactions: fantheflames
Upvote 0
Upvote 0

Latest Articles