Employees are the most important asset in any company. Demonstrate this fact by encouraging suggestions for improvement and growth of the company.

Question: We continue to hear about cybersecurity and the growing threat to small businesses. Our company is not large, and we do not have the budget for an information technology employee to manage these aspects of our business. Do you have a few basic tips and additional resources that can help our company in this area?

Answer: You are very wise and forward-thinking in addressing this issue. You are correct in your statement that small to midsize companies are more susceptible to cyberattacks than larger companies with their inability to employ information technology personnel.

We will provide some tips related to cybersecurity best practices as well as several free resources that provide more detailed information and solutions to potential attacks.

Best cybersecurity practices

As PROs we want to protect our company data, our network, our website, our computers, our payment systems and our employees from cyber criminals. Here are a few strategies to better protect your company:

System Hardware and Software

The most essential strategy is to back up all company computer data on a regular basis. Daily backup with storage either at a remote location and/or “in the cloud” is highly recommended. Hardware failure, power outages and natural disasters may disrupt current operations but data from yesterday, last month, last year and since day one will be preserved.

Make sure that your router is password protected and changed from the default password. Further, this device can be set up so that it does not broadcast the network name, also referred to as the service set identifier to anyone who attempts to access your network.

Secure your Wi-Fi by ensuring that it is encrypted, hidden and password-protected. The most popular security protocol for Wi-Fi networks has been WPA2, which was approved in 2004. The newer protocol, WPA3, was designed in 2018 to replace WPA2. Given the option, select WPA3 as it has more security features.

Protect your internet connection by both encrypting information and by taking advantage of firewall support that is available from your internet service provider. Encryption is a process whereby information is encoded during delivery or transmission of data and decoded upon receipt by the recipient. A firewall is a hardware or software link in your network that inspects all data being transmitted or received by your computer, allowing only authorized data and data sources to be received.

Install antivirus software on all computers and make sure that it is updated on a regular basis. Vendors provide updates on an ongoing basis as new viruses, spyware and ransomware are discovered so it is good practice to configure this software to update automatically.

If your company uses a credit card processing terminal, it should also be password protected.

A virtual private network is another security tool that your company may choose to provide. A VPN is an encrypted private connection that can protect laptops, tablets and phones when being used in public places or while working remotely to keep information from being intercepted. Choose a provider, a plan and install the VPN client software on the appropriate equipment and you are protected anywhere outside of the office or home.

Security

Control physical access to routers, computers and laptops. Having the router and the primary computer setup in a more remote area of the office — preferably in a separate room with a locked door for another layer of security. Laptops are also easy targets for theft and should be locked inside office desks or cabinets when not in use. If you have a credit card processing terminal, it should be secured at the end of the day as well.

Limit access to equipment and systems based on job responsibilities. Our suggestions include:

  • Only an employee(s) with information technology responsibilities and key personnel should have access to the router, the server, VPN and related hardware and software.
  • Designate only accounts receivable personnel or key managers to have access to the credit card processing terminal or credit processing software.
  • Financial data and personnel record access should be limited to designated personnel only.
  • Create individual user access for each employee to relevant systems. Ensure that former employees have access removed at the time of separation.
  • If employees are working at home or while on business trips, they should use the company VPN and not a local Wi-Fi system.

Training

Establish written company policies concerning use of systems — both in the office and remotely, password use and being cognizant of cyberattacks and potential scams to obtain company information.

Conduct training sessions on cybersecurity and discuss in company meetings on a regular basis. There are always new scams and technologies that can be shared and discussed with employees.

Establish company guidelines concerning password creation and duration. Some PROs mandate 8-10-character passwords with special characters and/or numbers required. Password duration should also be discussed and is sometimes dictated by the software itself. A key manager should maintain a master list of all passwords for all employees. This list should not be shared with any other employees. There are apps that can securely store this important information.

Two-factor authentication should be required wherever it can be implemented. This is an added security protocol whereby a random numerical code is sent to one’s cellphone or email address to gain access to a system or application. If a password is stolen, the thief would also have to access to your phone or your email password to gain access to the protected information.

Free resources to assist

Confused? Overwhelmed? Fortunately, there are several free resources that can provide valuable assistance and training regarding this growing topic of concern.

The Federal Communications Commission created the “Small Biz Cyber Planner 2.0,” an online resource where you select your topics of concern, and the program will create a planning guide that can be used to implement and to train employees concerning cybersecurity issues. This can be found at fcc.gov/cyberplanner

The Small Business Administration through its Small Business Innovation Research Program has information on preventive tools and training in addition to a 30-minute online course “Cybersecurity for Small Business” to help to implement a plan. This valuable resource can be found at sbir.gov

Another valuable resource is available through the National Institute of Standards and Technology. This organization has created a “Small Business Quick Start Guide” for studying risk management in your company. This guide is found at csrc.nist.gov

Finally, the Cybersecurity and Infrastructure Security Agency offers cyber guidance for small businesses as well as AI-driven threats. Its website is cisa.gov

FINAL THOUGHTS

Cybersecurity can be overwhelming and confusing, but it must be addressed. Talk with PROs and others in various industries. Take advantage of the free resources that are referenced above. Listen and learn and work hard to be cybersafe!

Continue reading for free

Forgot password?