Big cybersecurity challenges aren’t limited to large organizations. Small and medium-sized organizations are subject to the same vulnerabilities, exploits, and attacks that plague multi-national enterprises. Unfortunately, these smaller organizations don’t have the same resources as the big companies to use to defend themselves. That’s why it’s critical that small organizations make the most of the cybersecurity resources they do have.
Constraints on small business security resources aren’t limited to finances. Small organizations also have smaller security teams or, in most cases, a team of IT generalists who deal with security as part of their responsibilities. And while technology can be part of maximizing that small team’s effectiveness, technology alone can’t turn a small team of generalists into a large team of specialists.
That doesn’t mean that the small business situation is hopeless. When technology is deployed in support of well-considered policies developed through a thoughtful process, then small businesses can achieve a practical level of security that is as effective as that of larger organizations. The question, then, is which processes and policies will have the greatest impact.
[Want to see how other small IT teams have handled their security challenges? Check out sessions like “No CISO, No SOC, No Problem: Blocking Bigger Threats with Smaller Teams” and “When (and When Not) to Use a Managed Security Service Provider” at Interop19 in Las Vegas, May 20-23.]
The eight steps listed here aren’t meant to be taken one at a time like steps on a path. The first is a good place to start but after that they represent things that a small team should do — and can do — to get the most out of the security resources they have to work with. And these steps aren’t meant to be an exhaustive list of things to be done. We’d be interested to know which things you’ve found critical aren’t on our list — and whether there are any items on this list that you think are over-rated. Let us know in the comment section.
(Image: duncanandison VIA Adobe Stock)
Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and … View Full Bio