THE SBDC NATIONAL INFORMATION CLEARINGHOUSE SERVING THE SMALL BUSINESS DEVELOPMENT CENTER NETWORK AND AMERICA’S SMALL BUSINESS COMMUNITY.

Follow Us:

Cybersecurity Defense

Cybersecurity Defense

Cyber Attacks & Defenses for Small Business

Cybersecurity defense is a critical aspect of cybersecurity efforts. Building on, Cybersecurity Basics, next we cover the various types of cyber-attacks, means for protecting small business from cyber threats, where to report cybercrime, fraud, and additional resources.

Cyber Attacks

Types of Cyber Attacks & Threats

Most cyber-attacks target everyday business workflows such as email, invoices, payroll, online banking, and customer data. The list below defines common cyber-attacks and threats that frequently show up in small business environments.

  • Malware is software built to perform unauthorized actions such as stealing data, deleting files, monitoring activity, or giving an attacker remote access. In a smaller organization, it commonly arrives through a poisoned link or attachment, a compromised download, or tools or programs offered as “free”. This can lead to credential theft, fraudulent payments, and an initial foothold that can later enable ransomware.
  • Ransomware is a type of malicious software designed to extort money by blocking access to files or the entire computer system until a ransom is paid. A recent study found that 60% of small businesses identify ransomware as a major concern because an attack can disrupt or even halt business operations until systems are restored and the issue is resolved. For small businesses, where finances are often more limited and disruptions can have a significant impact on cash flow and overall stability, a ransomware attack can create serious financial consequences while systems are being restored and the issue is resolved.
  • Phishing and social engineering use fake emails, texts messages, calls, or websites to trick individuals into revealing login credentials, financial information, or other sensitive data. In a small team, these attacks often appear as legitimate login pages, urgent requests from a “vendor”, or routine-looking invoice attachments. Successful phishing attacks can lead to account takeovers, malware infections, and fraudulent payment requests. Financial services and medical practices are among the industries most frequently targeted by phishing attacks.
  • Business Email Compromise (BEC) is when criminals impersonate a vendor, customer, or executive to reroute payments or pressure an urgent transfer. In an owner-operated business, it typically shows up as “new bank details”, last-minute invoice changes, look-alike domains, or requests to bypass the normal approval path. The damage is often wire or automated clearing house (ACH) losses that are hard to reverse, followed by vendor disputes and cleanup work. For small business manufacturers, a BEC attack can disrupt relationships with suppliers, customers, and delay production.
  • Spyware is software that is secretly installed into an information system, often through fraudulent emails or websites. Once installed, it quietly collects keystrokes, screenshots, browser data, and saved passwords. Sypware can also be introduced through malicious browser extensions or compromised devices, allowing attackers to steal login credentials and active user sessions. The result is often unauthorized access to financial accounts, payroll systems, email, and e-commerce platforms, potentially leading to data breaches and financial losses.
  • Denial-of-service (DoS/DDoS) DoS/DDoS overwhelms a website or network with excessive traffic, preventing legitimate users from accessing service. For businesses that depend on online ordering, booking, or e-commerce, these attacks can cause websites to become slower or completely unavailable during peak business hours. The resulting downtime can lead to loss in revenue, disrupted operations, and decreased customer satisfaction.

Here are some additional resources on the types of cyber-attacks, threats and key terms:

Reporting Cyber Attacks & Crimes

Inform law enforcement and the state attorney of any and all cyber-attacks and crimes.

In addition, most states maintain specific requirements for notification in the case of a security breach. These disclosure requirements are available from the Security Breach Notification Laws.

Cyber Defense Against Cyber Attacks

Cybersecurity defenses, often referred to as cyber defense, are proactive approaches to mitigate the risks of cyber-attacks and threats. They focus on preventing, detecting and providing timely responses to attacks so that no infrastructure or information is tampered with.

Software

Installing protective software is one way to guard your information systems. Antivirus and antispyware software can detect and eliminate malicious software that may be installed onto a computer. Firewalls prevent computers from outside your network from connecting and stealing shared data. Utilizing a WPA2 wireless network will ensure that only authorized users may access the Wi-Fi connection by requiring a secret password. Encryption software ensures that sensitive business information is unreadable to unauthorized users. For firms that rely heavily on email and cloud tools, strengthening account security and filtering suspicious messages is as important as traditional antivirus. For remote employees using their own devices, consider using a VPN and/or remote access desktop.

Examples: Antivirus, Antispyware, Firewalls, Encryption, Trusted Platform Modules, SSID, IDPS, WPA2, Secure Email Filtering, Mobile Device Management (MDM0)

Procedural

Developing policies and procedures for your employees can help prevent unauthorized access. Turn security practices into policies to protect sensitive information. Write short, plain-language rules of behavior describing how work will get completed. These include instructing employees to develop complex passwords that are changed often and follow the Digital Identity Guidelines set forth by National Institute of Standards and Technology. Other procedures include only providing employees access to the systems and information they need and preventing them from accessing fraudulent websites through web filters. Additionally, make sure that cybersecurity training is up-to-date and occurs on a regular basis, including policies specifically for remote workers.

Examples: Multi-Factor Authentication, Limited Access, Email/Web Filters, Activity Logs, HTTPS/VPN

Physical

Ensuring that your business and its devices are physically secure can prevent data theft that will compromise your business. Locking computers after use and utilizing a physical lock which attaches the computer to a desk can prevent an unauthorized person from taking the computer and extracting information. Enable remote wipe for company-managed mobile devices, and document what happens when a remote device is lost or stolen. Privacy screens can also help prevent people from viewing confidential data. Procedures should also cover money movement, since invoice fraud and payment diversion often succeed when staff follow urgent instructions without verification. Establish a simple rule for payment changes and high-risk requests: verify through a known, trusted channel before acting. Vendor and contractor access should be reviewed routinely, with documented offboarding steps when roles change or relationships end.

Examples: Drive Locks, Surge Protectors, Uninterruptable Power Supplies, Computer Locks, Privacy Screens

This list is not exhaustive. For more information, visit:

Advanced Cyber Defenses

In additional to the measures listed above, there are several advanced tools you can use to protect your business:

  • Next Generation Firewall (NGFW) (firewall)
  • Intrusion Prevention Systems (IPS)
  • Deploy Demilitarized Zone (DMZ)
  • Virtual Private Networking (VPN)
  • Local Area Networks Layers (LAN)
  • Digital Signatures (DSA, RSA, EDCSA)
  • Encryption (AES, Triple DES)

For more information on what these advanced measures mean, visit: NIST Glossary

Additional Resources

Take advantage of all the ways you can protect your business’s data. Purchasing cyber-insurance can reimburse the value of any stolen data. However, in order to receive payouts, the business must implement and maintain an up-to-date cybersecurity program. Performing background checks on employees is also an important measure that can prevent malicious actors from stealing your information from inside the company. If your business depends on an online storefront, booking page, or web portal, confirm what protection your hosting provider offers for traffic floods and service disruption, and write down the escalation steps before an incident happens.

For more resources on how to protect your business from cyber-attacks visit:

More on Cybersecurity for Small Businesses

To continue learning about Cybersecurity for Small Businesses, view the next sections:

Additional Small Business Resources

Already in business or thinking about starting your own small business? Check out our various small business resources:

Remember, you can also receive free professional business advice and free or low-cost business training from your local Small Business Development Center!

Categories
Archives

Business
Advising?

Economic
Study?

We can help....

GIS
Maps?

Learn more...

Market
Research?

Get started...