According to the International Labor Organization (ILO), small businesses have become the engine of economic growth and social development across all countries, accounting for a staggering 70% of employment worldwide.
Obviously, these small businesses rely heavily on the internet and other online platforms and resources, which form integral components and enabling tools for their transactions. This has become even more prevalent since the pandemic period. Regarding online safety, it is estimated that over 40% of these small businesses have experienced a cyber attack. The type of cyber attacks that are more commonly aimed at small businesses include Social Engineering attacks like Email Phishing and telephone phishing otherwise known as "vishing"
There are a few factors that make small businesses to be vulnerable to attacks. Cyber criminals assume that small businesses have weaker security measures in places, making them easier to crack than the larger enterprises. Also, they have smaller budgets which means they are not financially prepared for an attack, and most do not have cyber insurance. Poor or non-existent employee cyber awareness education/training is another huge factor, considering the fact that 95% of cybersecurity breaches are attributed to human error.
What is Cybersecurity Health Check?
The Cybersecurity Health Check is aimed to help small businesses understand and minimize their cybersecurity risk by systematically identifying the weaknesses and strengths of their cybersecurity policies and implementations. It provides a checklist showing areas where they are doing well and where they can improve in order to mitigate risks. It can include vulnerability scans of the organizational local or cloud infrastructure and systems.
A cyber health check also offer the advantage of helping the small business to establish and proof compliance with regulatory information security requirements such as the ISO 27001.
What activities are involved in Cybersecurity Health Check?
- Conducting vulnerability assessment on IT assets - internal IT infrastructure, cloud platforms and end-user devices
- Document identified risks and understand remediation actions needed
- Determine level of preparedness and response to possible cyber attacks
- Determine the level of staff cyber awareness
- Provide a snapshot of the current cybersecurity posture
Outcome/Benefits of Cybersecurity Health Check?
The outcome of a cybersecurity health check is a detailed report describing current risk status and vulnerabilities/exposures - with reference to best practice frameworks such as the ISO 27001, NIST controls, CIS 20 Critical Controls, Cyber Essentials, etc. and of course some recommendations for reducing the identified cyber and compliance risks effectively and in line with business objectives. Other benefits include:
- The small business can focus more on innovation and growth
- Financial losses due to data theft or ransomware are drastically minimized or eliminated
- New business opportunities can be secured such as government contracts because of compliance to regulations.
Comments
Post a Comment
Kindly drop you comments, love to hear from you. Thank you.