top of page
close-up-data-center-computer-scientist-using-tablet-deploying-servers-network-hardware-it

INSIGHTS

Search

CyberSelf-Rescue

  • Owen Flynn
  • 5 days ago
  • 2 min read

Updated: 2 days ago

Today's Business Challenge

Small and Medium Business (SMB) leaders are finding themselves increasingly overwhelmed by the current volume and complexity of data breaches, hacking, and cybercrime. Unable to access the large funding and dedicated security staff of larger enterprise, SMB Leaders are having to become increasingly self-sufficient and almost 'self-rescue' to meet this enormous challenge to the operations and profitability of their business. In light of these challenges, the need for a solid foundation to enable any cyber security capability is vital. To assist SMB leaders in establishing and growing their cyber resilience, ZenITIL has gathered a number of foundational steps into three core domains (below). Additional information sources are also listed overleaf.

Operations

  • Enable Multi Factor Authentication (MFA)

  • Enforce appropriate password complexity and length

  • Restrict access to 'administrator' level or privileged accounts

  • Keep operating systems and applications current and secure with regular patching and updates

  • Keep anti-virus and malware protection up to date

  • Allow only trusted applications to be installed or run

  • Disable or block untrusted macros in the MS Office suite

  • Configure software and systems for increased security

  • Protect your data by enabling encryption on computing devices

  • Limit phishing by enabling DMARC (or SPF at the least)

Training & Policy

  • Train staff to recognise suspicious emails, links, and attachments

  • Generate and maintain a strong staff culture on cyber awareness

  • Create a Data Governance Policy and Cyber Incident Response Plan

Business Resilience

  • Ensure data and systems are backed up appropriately (daily)

  • Confirm backup integrity with a regime of regular test restores

  • Ensure IT Disaster Recovery and Business Continuity Plans are in place, current, and tested regularly

  • Invest in standalone cyber insurance (check policy pre-requisites, qualifications, and exclusions)

Australian Cyber Snapshot

  • 43% of data breaches involve small businesses

  • The average cost of a single cyber attack is $276,000

  • 60% of businesses that experienced a significant breach were out of business within 6 months

  • Regulators increasingly view Cyber as a part of every director's duties, yet 80% of boards have no experience in this area

  • Only 20% of smaller businesses have standalone cyber insurance

Future

With the basics established SMBs should look to grow their cyber maturity. We recommend looking at services received from your Managed Service Providers and taking steps to confirm the effectiveness of their internal processes and controls.


Further Resources

Small Business Cyber Security Guide

Australian Cyber Security Centre

Cyber Security Tips for Small Business

Australian Tax Office

Cyber Resilience

Australian Securities & Investments Commission

Cyber Security Playbook

Chartered Accountants (ANZ)

Business Cyber Security Hub

National Australia Bank

Cyber Security Governance Principles

Australian Institute of Company Directors

Notifiable Data Breaches

Office of the Australian Information Commissioner


 
 
 

Recent Posts

See All

Comments


bottom of page