We have reached a point in our society where we are too reliant on the Internet for conducting business and criminals are often one step ahead of the latest security measures.
Get Instant Access to This Article
Subscribe to Hartford Business Journal and get immediate access to all of our subscriber-only content and much more.
- Critical Hartford and Connecticut business news updated daily.
- Immediate access to all subscriber-only content on our website.
- Bi-weekly print or digital editions of our award-winning publication.
- Special bonus issues like the Hartford Book of Lists.
- Exclusive ticket prize draws for our in-person events.
Click here to purchase a paywall bypass link for this article.
Congratulations, your data has been held hostage. A criminal has hacked into your computer and taken control of your critical files. On your screen is a message, “For $10,000, you can have your computer back.”
Sound like a movie? Unfortunately, this happens every day to unsuspecting business owners and remarkably, this type of criminal act is one of the least costly hacks that can happen to your network compared to other more sophisticated and less detectable cyber-attacks.
In the previous scenario, the FBI advises that you pay the ransom as it will ultimately be less expensive than trying to crack the code. This is the hacker's intent. They figure the majority of businesses will pay the ransom rather than hire a forensics company to try to break the hacker's encryption. More times than not, the hacker will leave with the money; but how can you ensure that your computer is protected?
The truth is that you can't. We have reached a point in our society where we are too reliant on the Internet for conducting business and criminals are often one step ahead of the latest security measures.
Thinking that your organization would not be a target would be a false sense of security as criminals are looking for all types of information and there is a good chance that your network has something they are interested in.
Hackers use various methods to steal private information such as personal identifiable information, client records, financial information, proprietary data, health records and more. Malware may also be launched on your computer devices in order to spread their virus across your entire network and other networks.
Regrettably, criminals have become very knowledgeable in the way they leverage stolen information for financial gain and the effects of a breach can be so crippling that a single event can bankrupt an organization overnight.
To put this into context, a 2015 report from the Ponemon Institute found that on average a breached file will cost an organization $217 per record. A small organization with 10,000 records would be on the hook for over $2 million in order to recover from a single breach.
With these damages, it is not surprising that an AERIS Secure report found that approximately 60 percent of small businesses close within the first six months of a data breach. Larger organizations may be able to fair through the fall out, but their losses are often much more severe and damages extend beyond financial, impacting an organization's reputation and trust with its clients.
Having a solid understanding of the life cycle and vulnerability of data within an organization is a critical step to mitigating and understanding your exposure to a cyber-attack. Employees make up a significant exposure that most organizations may not think about as a cyber risk.
Human error or corruption makes up approximately 19 percent of a cyber exposure to an organization and while it may take the form of a rogue employee deleting or manipulating data, it is more often than not a result of an accidental release of information by an unsuspecting employee who opened a file they shouldn't have or clicked on a corrupted link.
So what is the best way to protect your organization from a devastating cyber-attack? The first step is to work with a specialist to do the following:
• Review contracts with all vendors
• Review your organization's data information security policy
• Review incident-response plan and determine the response team
• Review your organization's social media policy
• Enforce strict computer-usage policies
• Review document-retention policies
• Audit security of the organization's protection of physical devices
• Conduct training on all security policies
• Require confidentiality agreements of employees, vendors and visitors
The next step is reviewing the remaining risk and choosing a proper cyber insurance policy to protect your organization. Choosing an appropriate cyber policy is critical, however, because cyber insurance policies vary dramatically from carrier to carrier.
Cyber breaches are only going to become more common and while it may be impossible to stop every criminal, it is possible to mitigate the effects of such an attack. Computers are the lifeblood of most organizations and business owners need to be proactive in protecting their company against cyber terrorism.
Scott Garcia is a professional services risk advisor at Smith Brothers Insurance. He can be reached at SGarcia@smithbrothersusa.com.
Read more
State late to modernizing health industry oversight
High-end home sellers need patience as buyers push for value
What small business owners should know about paid family, medical leave
