There are a handful of simple measures that SME business owners can implement to limit their exposure to a cyber attack.
After first ensuring that antivirus and other security software is up-to-date, Chubb recommends the following Cyber risk mitigation steps:
Develop a strong password policyDevelop and enforce a strong password policy with a mix of letters, numbers, and symbols that are frequently changed.One of the easiest ways for cyber criminals to access SME assets is by walking through the virtual “open door” that employees provide when using weak passwords. To correct that situation, it’s a good idea for SMEs to establish a written password policy requiring strong passwords (e.g., a mix of letters, numbers and symbols) that are frequently changed. Passwords should also be changed automatically or accounts marked inactive when employees leave the company.
Train your staff on cyber securityConduct regular training for employees about how to be cyber aware.SMEs should inform employees of the role they play in preventing a cyber breach. It’s all too easy for malicious software to hitch a ride into the company server when company laptops or other devices are used off-site and later connected to the internal network.
The best ways to establish positive and secure habits within your company’s workforce is with regularly scheduled training and education.
You should also restrict access to sensitive information by only allowing management or those who require that information for company operations, to have access.
Update IT equipment and deploy security softwareEven basic security offerings feature similar technology to those used by major companies.Outdated operating systems and computers can be a risk because they are vulnerable to more sophisticated hacking techniques and newer forms of malware. At the same time, it’s important for SMEs to monitor those who have legitimate access to their computer network, as well as to monitor the network itself. Although SMEs do not typically have information security experts within their organisation, they can access basic downloadable software offerings that deploy some of the same technology solutions used by major companies within minutes.
Create a Cyber Incident Response PlanA dedicated and prepared team of cyber responders consisting of both employees and outside service providers can work toward a resolution for certain cyber incidents more quickly.
Purchase Cyber InsuranceIn addition to the above steps, SMEs can more fully cover their assets and cash flow by purchasing cyber insurance.
The cost of insurance will almost always be far less than the cost of shutting down a business in the wake of one or more cyberattacks. And cyber insurance, such as Chubb Cyber ERM can be pre-packaged with some of the services mentioned above.