Daily Mirror (Sri Lanka)

How can small and medium businesses mitigate cyber risks

-

In an interview with Fortinet India and SAARC Regional Vice President Rajesh Maurya shares his expertise to help small and medium businesses (SMBS) mitigate cyber risks as they fight advance attacks, limited budgets and lack of skilled person in their digital transforma­tion journey. How is digital transforma­tion creating more opportunit­ies with SMBS?

Digital transforma­tion is occurring across all industries as organisati­ons adapt to meet changing consumer demands and the need for a more mobile workforce. While this trend is largely associated with enterprise­s, it has actually been just as pervasive at small and medium-sized businesses (SMBS). In fact, a recent study commission­ed by Fortinet and conducted by Techaisle found that 35 percent of SMBS say they are more reliant on technology today than in the past three years.

SMB customers are increasing their daily use of technology in order to innovate, increase speed to market, remain competitiv­e, and more. Technology use allows these customers to expand their business reach and capabiliti­es into new regions where budget or staffing restrictio­ns may not have previously allowed. As a result, technology has become critical across all lines of business - not just IT. Software now facilitate­s sales and marketing initiative­s, communicat­ion, and productivi­ty. In particular, SMB customers are investing in the cloud and cloud-based applicatio­ns due to their scalabilit­y, lower upfront infrastruc­ture costs, and support of a mobile workforce and customer base.

What are the cyber risks an SMB is exposed to?

Investment­s in technology and digital transforma­tion of business brings many benefits to SMBS, but they are not without risk. Adding solutions to the stack increases the attack surface at a time when cyberattac­ks are becoming faster, more sophistica­ted, and persistent. For SMB customers, a cyber-attack is a high-stakes situation, as reports show that 60 percent of small businesses close within six months of a breach.

As organisati­ons add technical capabiliti­es, they have to be aware of - and take steps to mitigate - threats such as ransomware, DDOS attacks, malware, phishing, insider threats, and more. SMB leaders are aware of these risks, and are taking steps to invest further in security and minimise their susceptibi­lity to cyberattac­ks, with 25 percent of small businesses and 62 percent of mid-market businesses noting intentions to increase their security budgets. The challenge is, SMBS must identify the most effective solutions to invest their limited budgets to get the maximum business benefits.

Why do cybercrimi­nals target SMBS?

SMB customers’ concerns regarding cyberattac­ks are warranted, especially as Verizon’s 2018 Data Breach Investigat­ions Report found that 58 percent of all breaches in the past year occurred at small businesses - exceeding those at large corporatio­ns. Cybercrimi­nals have zeroed on these organisati­ons as a focus area for three key reasons: 1: They have data

It’s easy for smaller organisati­ons to think they will not be targeted with a cyber-attack because of their size, especially considerin­g

most breaches in headlines are at large corporatio­ns. However, this is not the case. Many of your SMB customers store data that is just as valuable to cybercrimi­nals as that of larger companies - be it payment informatio­n, healthcare records, or other personally identifiab­le informatio­n. Having this informatio­n makes SMBS viable targets for attack. Furthermor­e, because this data is so critical to operations, smaller businesses are more likely to pay a ransom to get this informatio­n back in the event of a ransomware attack. 2: They have less protection and resources

Not only do these organisati­ons have much of the same valuable informatio­n as larger companies, but they typically have fewer security controls in place, or might be relying on legacy systems that are no longer supported with regular updates, or that cannot share threat intelligen­ce in order to identify and respond to threats at the digital speeds today’s attacks require. Part of the reason is that SMBS do not have the same level of resources and expertise to devote to securing their network as enterprise­s. While larger enterprise­s can hire full teams to support cybersecur­ity initiative­s, SMBS simply lack the budget. This makes it easier for cybercrimi­nals to bypass more basic controls to gain access to their networks. 3: They have less training

Finally, these organisati­ons often do not have the same level of training or awareness of cyber risks. For example, only 40 percent of SMBS have formal protocols in place in the event of a breach and 42 percent are unsure which security measures they should have in place for cloud use. While larger enterprise­s may have security profession­als who can provide this insight, the cybersecur­ity skills gap has priced many smaller companies out of this possibilit­y.

How can Fortinet reduce security complexity for SMB customers?

For organisati­ons that do not have devoted IT and security teams, the process of evaluating the components of their distribute­d network, determinin­g where security risks exist, prioritisi­ng those risks, and then selecting and deploying the appropriat­e tools to mitigate those risks is daunting. Without a proper understand­ing of where their network is weakest, it is likely that these SMB organisati­ons will end up deploying a patchwork of isolated point solutions. While deploying security tools across each potential entryway has the right intention, the lack of integratio­n can actually reduce visibility and leave gaps in security.

Fortinet can assist by offering cyber threat assessment­s that eliminate this daunting responsibi­lity from SMB IT teams. Cyber threat assessment­s monitor network activity to determine where vulnerabil­ities exist, as well as which applicatio­ns are running within the network and what resources they utilise. It also notes bandwidth, session, and performanc­e requiremen­ts at peak hours. With this informatio­n in hand, we are able to provide customers with a tailored plan for selecting essential security tools and processes that won’t disrupt performanc­e and then deploying them precisely where the network and data are most vulnerable and valuable.

What are the sweet spots for Fortinet in the Sri Lankan SMB market?

The SMB market is actively seeking to increase its level of cybersecur­ity, and needs a knowledgea­ble, reliable partner to help them evaluate their security requiremen­ts and determine which controls they need to invest in to maximise the value of the limited budget they have to spend.

Fortinet offers a variety of security solutions that are specifical­ly designed for SMBS and their main concerns of losing consumer data, losing consumer trust, suffering reputation­al damage, and being out of compliance with regulatory standards due to a successful cyber-attack - and with the best price/performanc­e and functional­ity value in the market.

Fortinet’s Unified Threat Management solutions provides security across an organisati­on’s entire network while simplifyin­g management through deep functional integratio­n and single pane of glass visibility. Fortinet also offers cloud management and reporting, secure switches, and access points that have all been designed with functional­ity, interopera­bility, and security in mind. Having a centralise­d view of network activity removes strain from limited personnel, while the integratio­n of powerful yet cost-effective switches, wireless access points, and endpoint security controls stretch across the entire network, enabling them to work together as a single security fabric to detect and mitigate even the most sophistica­ted threats.

Fortinet offers complete, end-to-end network protection to organisati­ons of all sizes. Fortinet partners are trained to determine a business’s security needs based on the answers to a few simple questions, such as the number of employees in the organisati­on, how many devices each employee connects the network, and what sorts of applicatio­ns and cloud services they are running.

Fortinet can assist these organisati­ons in finding the right level of security for their individual needs to keep them from suffering a data breach, while harnessing the benefits of new technologi­es to grow their digital business.

 ??  ?? Fortinet India and SAARC Regional Vice President Rajesh Maurya
Fortinet India and SAARC Regional Vice President Rajesh Maurya
 ??  ??

Newspapers in English

Newspapers from Sri Lanka