If your small-to-midsized business is like most, you’re playing a game of chicken with cyber-criminals. You probably know that your defenses probably aren’t able to repel today’s sophisticated, persistent attacks, yet you hope that you’ll be overlooked.
IT security is complex, and security professionals are mired in a nonstop arms race against cyber-criminals. It’s easy to read headlines and think, “If the DoD can be penetrated, how am I going to ward off would be attackers?”
True enough, but there’s an old security maxim to keep in mind: You don’t have to have the most secure house on the block; you just have to have better security than your neighbors.
[ALSO: Hot security startups]
If you follow these five security best practices, if nothing else, you should be more secure than the majority of your SMB neighbors:
1. Be sure you’ve covered the security basics
You know that you should have antivirus and firewall protection on every computer in your company, and you know that you should train employees about safe email and web practices. However, have you verified that proper security tools are up to date? Have you verified that your employees understand the risks that come from clicking weird attachments?
According to the security and compliance team at System Experts, other security basics that you should be sure to follow include:
- Be sure employees are given user-level, not administrator-level, credentials (but be sure at least one or two employees have admin-level access, of course).
- Keep patches up to date, and enable auto-updates when possible. “Patch first, ask questions later,” System Experts counsels.
- Use a shared network drive to archive important data.
- Educate employees on emerging threats, such as mobile malware and social media phishing.
2. Tame email
So many security problems start out with email. However, most phishing attacks can be cut off at the pass by good spam filtering tools. Not only is a spam often the key vector for malware, but it’s also a bandwidth and storage hog.
If your email is hosted off-site, you can prevent much of this spam from ever reaching your internal corporate network by deploying gateway-based spam filtering. In the long run, this is more effective than desktop-based spam filtering.
For businesses on the small side of the SMB continuum, desktop spam filtering is always an option. Or a cheap workaround is to forward emails to Gmail, which uses Postini, to filter out the dreck. Making this manageable really involves giving each employee two email boxes (a headache, obviously, but if you’re doing this on the cheap, you can’t really complain much). Mail is delivered to first in-box, which then forwards it to Gmail for cleaning, and then you just set up Gmail to forward it back to a second address – or you can rely on Gmail as your second email address, since you can set Gmail to reply with your corporate email address.
Aggressively removing spam will eliminate many potential threats. Now, figure out how you’re going to do it.
3. Move beyond basic passwords
With automated password cracking toolkits widely available online, businesses need to embrace strong password practices, or, ideally, move to multifactor authentication.
According to Deloitte, in 2013 more than 90% of user-generated passwords are vulnerable to hacking, even those considered strong by IT departments.
[ALSO: 10 funny videos about computer passwords]
The trouble with strong passwords – those that are very long and include numbers, special characters and capital letters – is that they are nearly impossible to remember. Either you write them down or you rely on mnemonic tricks. I.E., “the Red Sox broke the curse of Babe Ruth (and stopped the 1918 jeers) in 2004.” The password would be tRSbtcoBR(ast1918j)i2004.
When you’re not sure about the strength of your password, test it with tools like Microsoft’s Password Checker or How Secure is My Password. I prefer the later, not only because it’ll estimate how long it’ll take a desktop PC to crack the password (3 septentrigintillion years for the Red Sox example above), but also because of its warning label: ” This site could be stealing your password . . . it’s not, but it easily could be. Be careful where you type your password.”
I’ve tried mnemonics, but I always end up forgetting a word or symbol. In the case above, I’d forget, say, the “the” at the beginning, or I wouldn’t remember that a particular site didn’t accept parentheses, so I substituted stars.
It makes sense, then, to invest in password management software or services, most of which are pretty cheap. LastPass (free to start; $12 per year for the premium version, which supports mobile devices and gives you the ability to create USB tokens for two-factor authentication ), 1Password ($49.99), OneID (free for personal use) and PasswordBox (free for up to 25 passwords; $1 per month for more than 25) will all help you manage your passwords without writing them down, and none will break the bank.
Compared to the cost of a single breach, these services will pay for themselves many times over.
4. Protect more than your network
These days, bad guys can attack your web page, your applications and even your databases. “A network firewall is not enough,” advises David Maman, Founder and CTO of GreenSQL, a database security company.
A web environment has four layers that need protection: the network level, the application level, the operating system level and the database level. “Most people think of these layers as being one within the other, like concentric circles,” Maman says. “They reason that if they protect the outermost level, the inner levels are automatically protected. This isn’t true.”
Maman pointed out that a very common attack, SQL injection attacks, aren’t stopped by firewalls. He recommends a web application firewall (WAF) to help with this, but notes that WAFs cannot see database attacks that don’t have basic signatures, which means that the database needs its own layer of security.
Similarly, if anyone can directly connect to your database, you could be in trouble. “For example, when a bank is using a database consultant in order to fine tune the main bank website database, the outside consultant connects to the database for maintenance purposes, but he can actually do whatever he wants, like change information or copy the customer list without anyone ever knowing about it.”
Investigate database security tools from companies like GreenSQL and website protection from vendors, such as CloudFlare, which will help protect your website from distributed denial-of-service attacks, SQL injections and email harvesting.
5. Keep up with trends – and turn to the cloud
Many complex security tools are moving to the cloud, as vendors move away from shrink-wrap, on-premise software to services. Even something as complex as MDM (Mobile Device Management) – or Enterprise Mobility Management (EMM) or Mobile Application Management (MAM) or whatever the acronym du jour is – can now be consumed as an affordable cloud-based solution from Apperian, Fiberlink and Citrix (through the Zenprise acquisition).
Meanwhile, Bullguard, Lookout Mobile Security and Marble Security all offer cloud-based protection against mobile malware.
There’s plenty of feature creep between mobile anti-malware, MDM, MAM, etc. Be sure to do your research so you’re only paying for the features you really need.
Jeff Vance is a Santa Monica-based writer. He’s the founder of Startup50, a site devoted to emerging tech startups, and he also runs the content marketing firm, Sandstorm Media. Follow him on Twitter @JWVance.




