Small Business IT Strategies
Phishing is the biggest threat to small businesses. The hacker tries to trick targets into providing their personal information or installing malicious software. The US Department of Justice believes that $5 billion in financial loss is attributed to such scams each year.
The dramatization of cybercrime in the media leads us to believe that most breaches involve a sophisticated hacker, furiously typing on his laptop in a darkroom to break through a company's network. First, few hackers are that good; second, why not just trick a human into opening the door?
Opponents who use phishing techniques effectively are generally very persuasive and have a more social than technical sense. They are very good at convincing employees to just hand over the 'keys'. Unfortunately, they also understand that small business employees tend to be much more vulnerable than their corporate counterparts who are trained to avoid such traps.
What are the phishing methods?
The most common form of phishing that companies are exposed to is 'spray and pray' campaigns. It is the least sophisticated technique, in which a generic message is emailed to millions of users requesting them to provide information or click on a link that subsequently downloads malicious software. This method is easy to recognize, but a victimized employee can have serious consequences for a small business. That single click could install ransomware , causing business systems to shut down unless a substantial payment is made.
Email is not the only platform where small business employees are vulnerable to phishing attempts. Opponents also try to establish a bond with victims via websites, text messages, and social media. In fact, 1,3 million fake web pages are created every month with the sole purpose of tricking users into entering their personal information. These fake login portals are quite well done, and even the most discerning eye can be fooled during a busy day.
The most effective form of phishing is “spear phishing”, where the adversary engages a particular individual to develop trust and maximize their ability to make them do what they want. Often this involves pretending to be someone within the organization, usually someone in management, and more often than not, the CEO. The criminal collects enough information about the target company, the department and the person in advance to appear authentic. Usually, all you need to do is quickly comb through social media to get a sense of the target's interests and hobbies to build trust.
Spearphishing can be a very effective way to grant an employee unauthorized access. The ultimate goal is to breach the employer's network and gain access to funds or intellectual property, rather than exploiting the intended user themselves. One of the most common tactics these criminals use involves malicious “payloads” hidden in forwarded documents. As soon as the employee opens the documents, they are prompted to download macros to view the file correctly. These macros subsequently turn out to be malware or ransomware .
Defending against phishing? Here are some tips
So what is the best defense against phishing ? Here are 4 strategic steps that small and medium-sized businesses should implement.
-
Train employees to detect phishing attempts
The first step is to make employees aware of the threat. Security guidelines must be established and enforced – don't be afraid to be strict and set consequences for non-compliance.
Next, it is critical that all employees are trained to distinguish between genuine correspondence and phishing. They also need to know the basic trends. Mass phishing attempts often have grammatical errors, attackers often use high-profile events as a lure, and low-ranking employees in finance and human resources departments are usually the most targeted.
-
Keep all software and systems up to date
Phishing attacks, like most other forms of cybercrime, try to exploit outdated software. In a perfect world, employees would detect phishing before they fall victim to it, and malware wouldn't even be downloaded. But by ensuring that all software is patched and updated, your chances of exploits from successful phishing are drastically reduced.
-
Mailbox Security
Intelligent users are the best line of defense against phishing attempts, but software can also help. Anti-spam and anti-malware products, such as BitDefender GravityZone Security for Exchange , can flag suspicious correspondence. Powerful security products offer multi-layered protection against spam and phishing without overloading email servers with security processes.
-
Antivirus software
The steps above, if followed fully, should protect a small business. However, it is still necessary to make plans to limit the damage if a phishing attack penetrates a company's network. All small businesses should use proven antivirus software, such as the Bitdefender product line. Feel free to contact us for more information without obligation.







