Top Tips on Mastering Cyber Security

By The Innovator Trust on 07 Aug 24

Top Tips on Mastering Cyber Security“Everybody who has an internet connection is faced with cyber exposure,” those were the words from Prevan Pillay, MD of Maxtec, a leading IT cybersecurity solutions provider, and one of our special guests for our latest webinar, warning SMMEs against the risks of cyberattacks. Joined by Jaroshen Naidoo, Senior Segment Manager: Medium Business for Vodacom South Africa, the "Smart SMMEs Master their Cyber Security" webinar provided crucial education for SMMEs on the kinds of cyber threats that exist, the importance of investing in cybersecurity, and effective, affordable solutions and products that exist specifically for the SMME market.
 
In South Africa, small, medium, and micro enterprises (SMMEs) are vital to the economy, contributing significantly to job creation and innovation. However, as businesses increasingly rely on digital tools and online platforms, they become more vulnerable to cyber threats.

Cyber security is a pressing challenge for South African SMMEs due to limited resources and expertise, which often hinders effective defensive strategies, making SMMEs attractive targets for cybercriminals. As the digital landscape evolves, it is crucial for South African SMMEs to prioritise cyber security awareness and implement best practices to safeguard their operations, customer data, and overall business integrity.

More than 60% of small businesses shut down within 6 months of experiencing in a cyber-attack – National Cybersecurity Alliance

Top Tips on Mastering Cyber Security as an SMME:

  1. Authentication is more than just username and password protection which many of us rely on as the first and sometimes only method of securing our profiles and devices. This is extremely risky as an SMME because authentication is the first manner in which hackers will attempt to gain unauthorised access to your systems and data. Multi-factor authentication is therefore essential as an SMME because having multiple forms of verification makes it harder for a hacker to gain unauthorised access, ultimately reducing the risk of a cyber-attack.
  2. Passwords that are used across more than one device, profile or account, remains a common problem for the cybersecurity of SMMEs because users tend to create weak or easily-guessed passwords that are stored or used on easily accessed or compromised password managers. These habits ultimately increase vulnerabilities and the risk of attacks. To mitigate this risk, make use of strong passwords that are not shared among users and are stored securely with only single-use access to them.

On average, weaponised vulnerabilities within a business are only patched 57.7% of the time, with each patching instance taking up to 30.6 days to be completed. It takes a hacker 19.5 days on average to exploit the same vulnerabilities.

  1. As an SMME, it is important to understand and better manage the vulnerabilities within your business systems ecosystem. This is more than just having a firewall in place. It is a practice that should be done daily within the business and involves the scanning and examination of your systems, networks and applications for any security weaknesses. The proactive approach is to be able to obtain regular visibility of your business’ cyber exposure so that you are able to prioritise your vulnerabilities based on what is most critical and then address it. As an SMME, it is recommended that you focus on tackling and mitigating the top 15% of vulnerabilities within your business as those are often going to be the ones most exploited by hackers.
  2. Frequent, automated data back-ups are one of the most critical practices to institute in your business routine as an SMME. Backing up to the cloud daily in this instance, is a non-negotiable. Beyond just backing up, testing your back-ups regularly is just as vital to ensure that if and when you are in a cybersecurity crisis where your data is compromised, that you have a reliable, protected source to recover your business data, saving you valuable time, money and allowing for your business operations to continue.

72% of businesses will tolerate less than one hour of downtime.

  1. Phishing is one of the most common types of cyberattacks one will encounter as an SMME. This is a type of attack where malicious actors are able to impersonate legitimate instructions (banking SMS, SPAM emails etc.) from sources that appear trusted and familiar, but are actually attempting to capture sensitive information such as passwords, credit card numbers, or personal details which can then be used for identity theft and financial fraud. Through education and cybersecurity training, you can ensure that your employees are more aware of common phishing signs like spelling and grammar errors, strange email addresses, generic greetings, urgent threatening language, small discrepancies in branding banners, logos, layouts etc. and thus more cautious in how they respond when they receive texts, emails or links to click on that may appear to be safe but could be a trap for malicious activity.
  2. One of the most unfortunate and scary experiences as an SMME is to get caught in a ransomware cyberattack situation where your business and/or client data has become completely inaccessible to you, and hackers demand money in exchange for the access and decryption of your data. Ransomware is a type of malware cyberattack that often stops business production immediately and data recovery can sometimes take weeks, months, and even years to obtain. This results in the business suffering reputational damage, revenue loss and sometimes having to close shop altogether because they can’t recover their data. Making use of anti-virus and anti-malware software throughout your business ecosystem, with regular patch updates turned-on, is one easily implanted way that you can increase the security and protection of your business from a ransomware incident.

Software, products and services recommended by our cybersecurity experts for SMMEs to better secure their business ecosystem:

 

Authentication

Vulnerability Management

Data Security

Phishing

Malware

Training & Education

VDSM (Vodacom Device Security Management)

x

x

x

 

 

 

Forti Authenticator

x

x

Enterprise Wifi

x

 

 

 

 

 

Keep-It

x

x

x

 

x

 

Microsoft NC OneDrive

x

 

x

 

 

 

Qualys

x

x

x

x

x

x

Norton

x

x

x

x

x

x

Trend Micro Email Security

 

 

 

x

x

 

CyberSafe

 

 

 

 

 

x





Loading