SMBs should put information and people at the heart of security strategy

Computer Weekly has an insightful article on how small to midsize businesses should develop security strategies to protect valuable information while enlisting the help of employees.

Invest time and effort into making every member of staff a security champion. It is false economy to not utilise every means at your disposal to protect organisational assets, and the staff are actually the biggest threat when it comes to information assets. But they could also be your best ally in rolling out really effective policy that people actually use and understand. If they know they are protecting their organisation/brand they will want to be a part of it.

The article gives areas that SMBs should focus on:

Confidentiality, integrity and availability

Identify information assets, and objectively assess their importance and the criticality of the components of confidentiality, integrity and availability (CIA).

Make information assets brand assets. Put the brand assets at the heart of behaviour and culture, and put the information at the heart of the security strategy.

Risk-based approach

Adopt consistent, repeatable and realistic risk assessment processes, fed by intelligence-driven threat assessments. The risk and threat landscape evolves constantly. Effective risk mitigation can only come from regular threat and risk assessment.

Security as a business process

Introduce robust, but not overly bureaucratic or onerous change and configuration management processes, that encapsulate changes to working practices and not just changes to information, communication and technology (ICT) components.

IT health checks

Invest in regular IT health checks (often referred to as penetration testing), but make sure this testing is appropriately targeted according to the risks (another reason for having we developed risk-based approach) – so test web-enabled services with dynamic and attractive back-end content more frequently.

Education

Inform yourself and your staff about security threats and mitigations. Use open-source information sources on security matters to keep yourself and your staff informed. This can be available online as well as from the free-to-attend educational seminars that are often hosted at security events.

In time, we can hope that security will be included in many business events which will make it easier for business leaders to get information and guidance on security in the correct context, as a pan-business service.

When it comes to staff, educate and encourage all colleagues to communicate with each other. Do not assume that, because you know of a new issue – for example a new phishing scam – that all your colleagues do too. It might even have missed the attention of your security manager, so encourage people to talk – even create a forum, maybe a space on an intranet for people to register security issues they have heard about, read about or experienced.

Security strategy and policy frameworks

A small amount of investment in independent external audit/health checks can identify potential issues before they become security incidents and thereby provide significant amounts of assurance as well as being a valuable mechanism to drive continuous improvement.

Prepare for the worst

SMEs often think they are not targets and so actually make a nice initial way in for any attacker. They do not realise they frequently hold significant information that may be valuable or sensitive or provide a way in to a larger supply-chain partner.

The best approach is to assume that, if you have information assets, you will be a target – and so will your supply chain. You have accountability for your data and partners will probably hold you accountable for their connections and data too, if you share information or systems.

These are some practical things you can do to ensure that any budget allocated to security is well spent and clearly accounted for. A business’s biggest asset and vulnerability is its people, so never underestimate or under-budget on training and awareness. They can be your best defence or your worst nightmare.

badge w light burst white (1)
Exclusively for Our MSP Partners

Now Available: Gen AI Certification From BSN

Lead Strategic AI Conversations with Confidence

Breach Secure Now’s Generative AI Certification helps MSPs simplify the AI conversation, enabling clients to unlock the value of gen AI for their business, build trust, and drive growth – positioning you as a leader in the AI space.

More on blogs

How BSN Training is Transforming the Way MSPs and Organizations Work

Cybersecurity isn’t just about protection, it’s about potential. At Breach Secure Now, awareness training is driving real productivity gains. In fact, 92% of BSN users

IT Nation Connect Takeaways: AI Is Here to Stay and Many MSPs Don’t Know Where to Start

Many MSPs walked away from IT Nation Connect excited about AI—but unsure where to start. Here’s a practical breakdown of why MSPs feel stuck, the
Take the First Step

Experience Training That Makes a Difference

during the demo you’ll:

Take the First Step

Experience Training That Makes a Difference

During the demo you’ll:
monk4d slot dana slot gacor SBCTOTO DAFTAR toto slot deposit 1000 joker123 top1toto pucuk138 idrtoto daftar hoki99 toto toto slot pulsa toto togel slot88 gacor slot thailand Login shope168 Login shope168 interwin situs toto situs toto toto situs toto toto 8KUDA4D 8KUDA4D situs toto situs toto situs toto toto toto toto situs toto toto toto situs toto slot server Thailand slot maxwin gacor mulantogel top1toto xyz388 city4d petir135 daftar pgs4d slot ltdtoto gbk99 bwo99 bwo99 toto HK4D dana100 NIX77 indo4d paijitu slot maxwin monk4d kepo66 pewe4d monk4d XIN77 pajaktoto XYZ388 alam4d Streameast pajaktoto login dolantogel pajaktoto login toto rp888 xyz388 toto situs toto toto togel toto https://www.slimfluorescent.com/specifications.php ollo4d login ollo4d login toto slot gacor situs toto situs toto ilmutoto situs toto hk4d naruto88 naruto88 leon188 Wikatogel https://linktr.ee/miminbet99 toto macau batmantoto toto togel toto toto besttogel birototo slot gacor toto Situs Slot QRIS Terpercaya toto toto toto toto toto traveltoto naruto88 babeh188 Streameast nicetogel justogel situs toto situs toto