In this episode, host Aaron Crow addresses the pressing issue of cybersecurity for small and medium-sized businesses. With their limited budgets and resources, these enterprises are often prime cyberattack targets.
Aaron explains why these businesses are particularly vulnerable, the potentially devastating impacts of a cyber incident, and practical measures they can adopt to strengthen their cybersecurity without incurring significant costs.
Listeners will uncover insights on establishing basic cybersecurity policies, the critical importance of monitoring, and strategies for preparing for potential breaches.
This episode is filled with valuable tips that could ensure the survival and success of your business amid today's escalating cyber threats.
Key Moments;
00:00 Cybersecurity challenges and solutions for small businesses.
03:24 Startups are vulnerable due to inadequate cybersecurity measures.
06:30 Use secure passwords, educate employees, and use tools.
11:26 Segregate networks to protect sensitive data.
14:46 Effective monitoring requires time, effort, and setup.
16:10 DNS filtering blocks malicious sites, prevents attacks.
20:29 Plan proactively to manage events before crises.
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Aaron Crow (0:1.016): Hey, thank you for joining me. This episode I want to dive into cyber security for small and medium sized businesses. And before I do that, I just want to say today I'm recording this on Sunday, November 10th, which happens to be Veterans Day weekend, but also today specifically is the birthday of the Marine Corps. So want to do a shout out to all my veteran friends and all those who served.
Aaron Crow (0:29.762): Thank you very much. I appreciate your service. All that you stood up to stepping up and and you know, that call. So thank you very much. With that said, want to dive into, like I said, cyber security for small business. In this episode, I'm going to dive into specific cyber challenges faced by small medium sized enterprises. Unlike large companies, know those those small medium sized companies, they they offer.
Aaron Crow (0:57.518): They many times operate with limited budgets and resources, which really makes them a target, makes them a target for cyber criminals, not because they are a small company, but because they don't have the resources and the skill set to really protect their environment. By the end of episode, the goal is to gain a deeper understanding of the steps you can take to improve your cyber posture without breaking the bank, because you don't have to have huge budgets and teams of people.
Aaron Crow (1:25.206): to do simple basic things that can really drastically improve your cyber posture. So with that said, let's dive in. Why businesses are prime targets for cyber attacks? Statistics set the scene. According to Verizon data breach investigations report, over 43 % of cyber attacks target small business. The National Cybersecurity Alliance found that 60 % of small businesses that suffer a cyber attack
Aaron Crow (1:55.086): will go out of business within six months. That statistic is huge, right? You cannot afford to have a cyber attack in these small and medium sized businesses. They'll literally put you under. I did an assessment not too long ago of a not so, I mean, when we say small, we don't mean, know, it's just not the size of Amazon, right? So I did an assessment on a company, a manufacturing facility.
Aaron Crow (2:20.674): and it doesn't matter what they manufacture, but you know, they're in their first year of this company. Now it's a pretty good sized company, know, hundreds of employees and a big factory and, know, multiple millions of dollars of revenue. And if they had a cyber event, they would absolutely close, close office, right? They can't sustain it. They're, still in that process. They are profitable, but I guarantee you if they were impacted more than, you know, very limited.
Aaron Crow (2:48.754): If they were a day or two or definitely a week or more of without production and revenue, they would close shop. They wouldn't be able to continue. So that's why it's so important in these small and medium sized businesses that you do have some kind of focus on it. Again, you don't have to have the same budget, but it needs to be. You can't just say, I'll do that later. We see that there was an article here recently around startups and how all these startups don't necessarily put their budget towards cybersecurity.
Aaron Crow (3:17.190): And it can be the detriment to that company. You can have a great product, but you get hit with cyber incident, ransomware, anything like that. And your great idea just went out the window because you can't sustain. So why are they vulnerable? Lack of dedicated security staff or budget, use of outdated systems and or software. I would add onto that even just lack of integration and maybe we're using the best stuff, Office 365 and
Aaron Crow (3:45.236): and GitHub and GitLab and all the different things. But if you don't know how to configure them and you're not an expert, there's things you can miss and you can misconfigure something or just forget to lock something down. And that can be the door in. Not to mention a lot of these small businesses, know, people are bringing their own devices and that's fine. But you have to know that's a risk and what to do about that, right? So if you are allowing those things, you've got to have
Aaron Crow (4:12.546): other controls and mitigations around those things to make sure it limits the impact backups and all that kind of stuff, right? So what's at stake is, you know, loss of customer trust could be regulatory fines, significant downtime. We talked about the other one that could shut down. Even just a minor breach can impact production. The ability to sell your product and not to mention that, you know, if if your customer PII type information gets out,
Aaron Crow (4:40.964): you that could be just a loss. That customer trust could go away. again, it doesn't matter that you have a great product. There's many, many examples of products that are really good that, you know, get him hit with ransomware or, you know, customer data gets stolen. And it doesn't matter. Customers don't trust you and they'll go to an inferior product potentially that their information isn't going to get leaked. So call to action, you know, really.
Aaron Crow (5:7.994): the importance of cyber awareness, cybersecurity awareness, even for small businesses. I've heard it a lot that people think, I'm too small. Nobody would target me. Why would a bad actor come after me? They don't care. Like they are literally looking at showdown and places like that and just seeing, can I get in? They don't care if it's, I can get 5,000 from you. I can get $10,000, whether it's ransomware. It doesn't matter, right? They will go after everyone. You don't have to be, it's not all nation state.
Aaron Crow (5:37.946): you know, North Korea and other company countries that are going after you. A lot of times it's just, you know, criminals going after money. So what are basic cybersecurity measures? I say this a lot, but it's not all technology and fancy and whiz bang and blinky lights. Sometimes it's many times it needs to start with you with just a cyber policy, right? Establishing basic cybersecurity policies.
Aaron Crow (6:7.222): understanding even if it's just a single page, like, hey, we're gonna have dual factor authentication. We're gonna use secure, you know, complex passwords and, you know, we're gonna, you know, not put our customer data into chat GPT and any number of example, right? And then educate your employees on things, phishing activities and, you know, where can I download software from and what information can I put where and, you know, really just having a policy and a procedure around those things.
Aaron Crow (6:35.040): Where is it safe to store my data? Can I can I put it in my Dropbox? Is there a company location to have those things right? And then you know there are affordable tools DNS filtering right open DNS cloud flare they can acts they can really block your malicious sites use a password manager. I tell tell people in your home in your personal life, but also at work right? You should use tools password managers that can.
Aaron Crow (7:3.290): can help you generate and store complex passwords. And you should do that in a way, especially if you think about, you know, an IT person, a systems administrator in a small company, if that person gets hit by a bus, wins the lottery, you know, whatever, if they leave and they have all the passwords, you're having to recover that, right? You're having to, assuming that they don't do a good transition, then...
Aaron Crow (7:28.322): then you're struggling. You're trying to find the piece of paper or dive through their documentation if there is any to try to figure those things out. So again, that's not even a cyber incident. That's just good operational running, right? Is understanding all those, right? And the other piece to this is also just knowing what your systems, how your systems are critical, really mapping out all the systems that you have, whether you're a production company and you're...
Aaron Crow (7:53.594): You're building widgets, right? You're, you're manufacturing things like you, need to understand that, that, that process, but also the back office stuff, right? How is my payroll done? Like how is my banking done? How is my, you know, front office, my email, like all of those integrations, how do I do, you know, remote access? Like all of those things matter and really understanding what those pieces are and which ones are critical to your business. there, there's pretty easy steps, with these that you can do to really, impact.
Aaron Crow (8:23.482): Dual factor, two factor authentication is definitely another one. The easy quick wins are make sure that all of your software and systems are updated to known patches and vulnerabilities. Use antivirus software, make sure you're backing up your systems, that you have an offline backup, a bright glass in case of emergency. If one of your devices or multiple of your devices get hit with ransomware, how can you recover?
Aaron Crow (8:49.454): Do you have your your proprietary information someplace, you know, in a vault that you can get to if you need to? How long can you be down and still function? And what is that process to go from? I'm down to back up, whether it's I've got a spare machine. I've got my stuff backed up and I've tested that process. A little bit deeper dive in the architecture of thing, and it really depends on the type of business, but network segmentation.
Aaron Crow (9:18.004): Like we've done this for years and it's really, really important. I have network segmentation on my home network that I'm at now. Like I have my corporate, my business stuff separate from my kids' network, separate from my IoT network. And there's a reason for that, right? Is as I'm plugging in all of these smart devices and I've got a guest network, I don't want my guests on my production network. I don't want my guests in my IoT network. I don't want my guests on my kids' network, right?
Aaron Crow (9:45.566): I want to have separate environments. just maintains each of these environments. And if one environment gets impacted, if it's one big network, then everything can pivot. You can pivot from one device to the next. Whereas if I have network segmentation, yes, it's a little bit more complex, but that complexity also makes it more difficult for things to propagate through your environment, right? So really separating your business network into different segments and
Aaron Crow (10:12.546): understanding again it doesn't have to be you don't have to have 50 and you don't have to have a whole bunch of really complex hardware again my home network has it right and and I'm using you know simple commercial or not even commercial you know home use products that that support that right and and yes it takes a little bit configuration and maybe you don't have the in-house capability it's vastly cheaper to fix this now
Aaron Crow (10:39.532): especially as you're growing for your small business, if you design it right in the beginning, it's really easy to expand it, whereas it's harder down the road to redo everything, right? To go out and change configurations and really dive that up down later is more difficult. Creating guest network for visitors and employees, right? That is crucial. You're going to have people that are coming from outside of your company in, and they're gonna want internet access. Well, you can easily give them that, but you don't wanna give them, put them on your corporate network. You don't want them...
Aaron Crow (11:9.198): having access to your printers, you don't want to have access to your file shares, you don't want have access to your production line, whatever those things are. And then even beyond that, really segregating critical systems, financial data, even locking down if I have a share environment, like I don't want my janitor having access to the accounting data, people's salary and customer information, right?
Aaron Crow (11:35.706): If you run a small business or a small retail business, segmented network, so your point of sale systems are isolated from your employee Wi-Fi that's isolated from your guest Wi-Fi, that prevents attacks like the target breach. Again, the target attack targets a big company and they were breached, but it wasn't through their corporate enterprise front. It was from a vendor back door. So somebody had access to that target network and they hit that vendor.
Aaron Crow (12:5.592): that then got them into the target network and that's how they expanded, right? So a few changes to your network setup can greatly reduce potential impact to your cyber incident. It's not a matter of if. Cyber attacks are coming. It's really a matter of when. You're going to be impacted. The real question is how big is the impact? How quickly can you respond? How quickly can you recover?
Aaron Crow (12:33.590): And honestly, like we said earlier in the in small businesses, can you survive? It's literally that critical. Can you survive if you got hit with a with a cyber incident? Monitoring is the next piece. So once you've gotten all those base things, I've got to I've got some kind of policy and procedure. I've done some basic network segmentation. I'm not allowing guests onto my corporate network. I'm not you know, my my employees are segmented. So, you know, accounting and financials are separate from, you know, engineering and
Aaron Crow (13:2.680): you know, my Salesforce monitoring is kind of that next step. Importance of monitoring tools, utilizing tools and there's, I'm not going to list out tools, but there's an unlimited number of tools, both paid and open source that you can monitor network activity. speaking really quick on paid versus open source, open source is great. There's a lot of free tools out there.
Aaron Crow (13:31.970): And when I say free, mean, you don't have to pay for a license. That said, they're not free. And what do mean by that? Well, you have to spend a lot of time to implement, to architect, to stand up, to support, all that kind of stuff, right? So some of the things that you're buying when you pay for a commercial product is the setup and the support, right? That is, especially if you don't have in-house expertise, you're the CEO.
Aaron Crow (14:1.528): You really shouldn't be spending your time on monitoring of your of your environment, right? It's not your single best use. That said, you may have to in the beginning how small you are. But again, that's where it if you can open a ticket with a support company for this product and monitoring and all this stuff, that's that's a lot easier and it takes less of your time away from running your business as opposed to trying to go as cheap as possible and not have that monitoring. That said, a lot of people are still going to have to use open source, and that's fine.
Aaron Crow (14:30.490): Just know it's going to take time and it's going to be a lot of work to maintain and get the value, even if you're not paying for a license, to get the value out and make sure that you're monitoring and you're seeing all the things, right? So how do you monitor your devices? Obviously, you really need to start out with, what do you have? Like, do I know what devices I have? Do I know what systems I have? What critical systems? Like, how can I monitor Office 365, making sure my setup is correct?
Aaron Crow (14:59.000): monitor my endpoint devices, make sure I've got antivirus on those things, make sure that I'm scanning my corporate network so that I know devices as they get plugged in and I'm monitoring the switches and the firewall and I'm looking for denial of service attempts and malware coming across. You can use logging type devices, Splunk and others, right? Again, I don't wanna dive too much into which products, but there are free and low cost
Aaron Crow (15:28.096): options out there for many of these things. But again, remember those free low cost licenses are not free because somebody has to maintain them, set them up, support them, configure them, all that kind of stuff. Right. So, but monitoring doesn't have to be expensive. You can get real time insight into your network. It just takes some time and effort to set up DNS filtering. That really helps with
Aaron Crow (15:52.736): as your devices are going out, if somebody's clicking on a phishing link, right, if you've got some of these things set up, even clicking on that link, it's going to block it from being able to go out. So, know, blocks, DNS filtering blocks malicious sites before they can infect devices, especially important for preventing phishing and malware attacks. There are affordable DNS services. If you don't want to run your own, you can use OpenDNS and Quad9 Cloud for DNS, but they're free.
Aaron Crow (16:20.382): or low cost options to implement. can also do, you know, Raspberry Pi has a pie hole and there's a lot of things again that are not super expensive but provide very, very big value. There's a lot of other things that are built into enterprise level firewall type devices. So FortiGates and Palo Alto and those guys, they have a lot of these things built in. So you can buy one device and get a lot of capabilities. You you've got the 40-SIM and you've got,
Aaron Crow (16:49.826): the AI threat data that's coming in these environments from Palo and FortiGate and all this stuff, right? And those things really get you that next level. But again, they're gonna be more expensive. You can also do it with a PFSense box or any number of the open source firewalls or Ubiquiti. There's a lot of them that are more affordable. But again, remember that affordability comes at a cost.
Aaron Crow (17:14.895): and it's really a time versus experience versus capability. And that's where you really need to figure out what's right. As long as you're doing something, it's better than nothing, right? So figure out what those low-hanging fruit are for you and really focus on them. And it goes back to that original documentation and processes. What is important? What are my crown jewels? And I wanna protect those crown jewels.
Aaron Crow (17:39.714): If my workstation goes down, but I've got a good backup and I know I can recover in an hour, maybe I don't have to spend the expense on really, know, endpoint protection as much as I do on the other. I'm not saying an important protection is not important. I'm just saying you can begin to decide what is the most important for my business, right? So getting a little bit more advanced is that instant response and business continuity planning, right?
Aaron Crow (18:6.520): And that goes into how long can I survive? What is my recovery process? If this system goes down, how do I get it back? And again, small businesses are really struggling to survive after a massive event like this, right? And massive to a small business isn't the same as massive to target. You know, a massive event for a small business could be hours. Like you could lose enough revenue and reputation in a few hours of downtime.
Aaron Crow (18:35.396): that it's gonna be hard to dig out of that hole. So make sure you outline the steps that you would take in an event of a breach, containment, communication, recovery, and you shouldn't do that in a vacuum. Those are things, you know, go through a tabletop exercise. There's great tools out there. ThreatGen has that auto tabletop they do, which allows you to use the capabilities of AI and language models to...
Aaron Crow (19:2.520): Go through those scenarios. You're not an expert. You might also not also be able to pay for a consultant to come in and do it, but you can use tools that will help you, you know, kind of get a leg up on these things. Make sure you have backup strategies. You know, you need to have some kind of strategy and have multiple copies of your data, two different types of media, at least one of them off site. That's that 321 backup rule. You know, so three copies of your data on two different media and one off site, right? So that that
Aaron Crow (19:33.375): You see the memes, the server goes down and, hey, where's the backup? it's on the server that just went down. well, that's not fair. If I've got a VM, a virtual environment, and all of my backup servers on the same hardware as the rest of my environment, and I'm backing it up to the backup server, I'm not doing much good, right? I need to have an offline copy. Think about, I don't want it in the same room if that room catches on fire. If there's a lightning strike and it takes out everything on a circuit, like,
Aaron Crow (20:1.088): All of those things are impactful. So you need to think about those things. So I wanna have, make sure that I'm thinking through all of those things so that if the worst case scenario happens, I have a path out. It may not be pretty. Maybe it's manual for the short term, but at least I've thought it through and it's not the first time I'm thinking about it after the event. You wanna do it left of bang. If bang is the bad thing that's happening, everything left of bang is before it happened and everything right of bang is, I'm reacting and responding.
Aaron Crow (20:30.596): I wanna make sure I plan this stuff left of bang before the bad event happens so that when the event does happen, everything to the right of bang, at least I've not, it's not the first time I've thought about it. At least I have a plan, right? My plan's not gonna necessarily work exactly as I think it through. The old Mike Tyson quote, everybody's gotta plan until they get punched in the face. But at least I have a plan of some kind. I know which direction to go in and I know where to start. I have a backup, I know where it is. I've tested it before.
Aaron Crow (20:58.570): Now you're you're troubleshooting, but not from a place of I've never thought about this before. So being prepared can literally save you thousands of dollars in downtown or recovery costs. It can literally save the difference between your business continuing to run and closing up shop. So not to end on a dramatic note, but you know, conclusion of final thoughts are, know that cybersecurity is a continuous journey. You're never done. It's not something you implement. You know, it's like you go to the gym. You don't just go once.
Aaron Crow (21:27.384): lift some weights and I'm done. You have to have a plan and continue to do these things. You're having to constantly, as your company grows, as the threat environment changes, as your risk profile, all these things are going to change. So you need to constantly be remembering, just like you have to budget and every month is different. You have to look at your cyber and make sure that you're considering all the right topics and all the things that are important to your business. And it's not a standard test. You can't cheat off your neighbor.
Aaron Crow (21:56.600): because the things that are important to you are different than even another company, one of your competitors. Theirs is different because they have different back office systems and different people and different geographies and different customers and all these things are gonna be a little bit different. So yes, you can get some templates to start, but you're gonna have to customize it for your environment. Make sure to take immediate steps, even if it's just implementing one tactic. Understand your environment. Make sure you have an asset inventory.
Aaron Crow (22:24.728): Make sure where your backups have you tested that? Do you have backups? Are they on the same server as the rest of your stuff? Do you have one in a fire safe in a different room that you can come back to from, you know, a known good state? Like these are the types of questions you need to be looking at and you can solve for pretty simple. Like you can take a backup of your stuff, put it on a USB drive, put that drive in a fireproof safe, put that safe in another building, right? Put it at home. That way it's off the ground. It's not going to get flooded. It's not going to get burned like
Aaron Crow (22:53.990): and do that two or three times. That's not expensive, especially as a small business. Obviously, targets data would not fit on a USB drive, but yours may, right? And maybe it's not a USB drive. Maybe it's a network attached storage. Maybe it's a cloud based, like whatever that is for you, make sure you know where that you have a backup and you can get to it. I've got three copies and two different types of media and at least one offsite location, right? So with all that said, again, don't don't overthink it.
Aaron Crow (23:23.874): Also don't think that you're immune or too small because nobody is. Bad actors don't care who you are, what you are, how big you are. They're coming after money. Like there's so many different types of things that people are going after a fishing attack. They're just broadly sending out and anybody they can get, right? That's why it's called fishing. They're not picking the individual fish, but if you're the small fish and you bite the hook, you still got hooked. And that's really the point of it, right?
Aaron Crow (23:51.414): Again, all that said, thank you for listening. Do me a favor and definitely make sure that you like and subscribe on YouTube, on wherever you listen to your podcast. Definitely leave us a review. We love getting reviews and feedback as well as if there's a topic you want to cover or hey, you want to come on the podcast. Please reach out info at protectedall.co.
Aaron Crow (24:18.714): You can also see the info in the show notes here, but definitely shoot me a message. Love to have interesting conversations with folks around all cybersecurity things from IT to OT, cloud, AI, just about everything that's there. So again, happy Veterans Day. Thank you for all those veterans that are out there and I really appreciate all that you guys have done. Thank you to the listeners and until next time.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.