Sunday, July 1, 2012

Why Smaller Businesses Can't Ignore Security and How They Can Achieve It On a Budget

A repost of an earlier blog that I wrote a few years back. 

In the back of the Pizza Schmizza restaurant in Vancouver, Washington sat humming an old computer. An unwitting customer would walk into the restaurant to order a slice of pizza, and the next day his credit card number will go on sale at a hacker’s forum. A few years and millions of dollars later, the FBI learned the root cause of the breach: The computer was running old unpatched software, which made it remotely accessible without a password by a hacker Max Butler (aka “IceMan”) (as detailed in Kevin Poulsen’s book “The Kingpin”).

This story is not unique. We often hear of security compromises of large companies such as Sony or TJX in the news, but we don’t hear about daily compromises of thousands of small to mid-sized businesses. One of the reasons is that many of those businesses, such as startups, motels, mom and-pop shops, pizza shops, never find out that they were compromised in the first place. Another reason is that disclosing these compromises can often be catastrophic for their survival. According to a study from Price Waterhouse Coopers, 70 percent of smaller companies that get hacked go out of business within a year.

Smaller businesses often have no security personnel on staff. They prefer baking pizza or building a UI prototype for investors rather than fixing security holes. They think that they are too small to get hacked and that they have nothing to lose or that security is a distraction, which is too time-consuming and too costly.  Others argue that their biggest security risk is “running out of money.”

In this article, we dispel these misconceptions. We show that security is both important and achievable for smaller companies without breaking a bank.

Why Should You Care?

If you think your company is too small for hackers to notice, think again.
Most home invasions don’t happen in castles with moats and armed guards, but happen in regular houses next door. Similarly, majority of security attacks in 2011 decreased in sophistication and targeted smaller businesses. Your company is the target and there are two reasons you should be worried.

First, regardless of your company’s size, it all boils down to its reputation.
Customers need to feel you will do a good job protecting their personal data. If you don’t then they will take their business elsewhere. Depending on what information is exposed, you could also be a subject to expensive government fines.

Second, the phrase "time is money” is true here. Let’s assume you are an owner of a small startup, which doesn’t store any customer data or intellectual property, and then one day you get hacked. How much damage do you suffer? Most typically, you will hear the answer “none” which is why security is never a priority for these companies. In reality, you will have to repair your systems, find the cause of the breach, possibly reinstall operating systems, etc.- all of which can take months.   For a small startup, not focusing on their core product for months could be tantamount to a bankruptcy.

What Can You Do?

Despite what vendors would like you to believe, you don’t need to buy their security technologies to protect your company. You can become a more secure company for free without impeding business agility. I now describe six simple rules for achieving that.

1.      There needs to be an executive buy-in for your security strategy to be successful. Many companies hire a CISO and think they magically became secure. A year later a frustrated CISO quits and they get hacked because security is always put to the side of business objectives. When there is executive buy-in, your CISO will have the backing to get things done. Hyundai Capital CEO Ted Chung said, “IT security needs a philosophy and only the CEO can make that kind of a decision.”

2.      Make sure that no weak or default passwords are used in your company. In 2011, almost half of the data breaches, reported by Verizon, involved weak or stolen passwords.  Don’t assume that stringent password policies ensure your employees will select good passwords. Often users choose a dictionary word or a company name and add “123” or “!” at the end just to satisfy a password policy. Any hacker worth his salt knows these tricks and will circumvent them. Teach your users how to use mnemonics to generate secure passwords (e.g. a phrase “I love chocolate 24x7!” results in a secure password Ilc24x7!”). Wear the bad guy’s hat for a day and try to break into your company’s servers. There are many free tools available, such as Hydra ( that you can use to brute-force guess the passwords.

3.      Institute security awareness training for all company employees.
No computer in the world operates without some form of human intervention. That’s why security education should be a pivotal tool in the security strategy of any company. Security can be a very dry subject. Have some fun with it! (Don’t tell people that it’s dangerous to download malicious attachments. Show them a screenshot of a user downloading Hallmark greeting card on his computer, and a screenshot of a bad guy across the globe getting access to user’s computer as he opens the greeting card.)   The awareness training should be mandatory for all employees, which will be easy to achieve if you follow recommendation #1.

4.      Contrary to what security vendors want you to believe, there are plenty of free alternatives to commercial products.  To give a flavor:
-          Immunet offers free anti-virus ( which you can install on all your computers.
-          Snort is a free intrusion detection system for your network, albeit it could be tricky to properly configure (
-          TrueCrypt offers full-disk encryption for your employees’ laptops for free. (
-          You can perform static analysis of your source code for security bugs using YASCA (
The list goes on, but it illustrates that most security products have free counterparts.

5.      Secure coding training for developers.
If your company develops its own software, make sure to train all developers on secure coding principles. Familiarize them with the OWASP Top 10 ( list of web application security bugs.

6.      Finally, stay proactive. When people started leaving laptops unattended at Cinchcast offices, we began walking the floors and taking the laptops away. When we felt that people aren’t engaged enough, we established a “security champion award” for the person outside of Security team, who contributed the most to company’s security.  At Gilt Groupe, we set up a “Hack Day” where any employee is challenged to break into the company’s website in order to win the coveted IPad. By engaging people, we managed to thwart many attacks.


Smaller companies have a misconception that security is hard to achieve because it’s expensive and time-consuming. In this article, we have described six simple rules by following which you can dramatically improve security in your company.
The 80-20 rule applies as much to security. By focusing on the basics, such as ensuring that no weak passwords are used, all employees have attended security awareness trainings, and developers are trained in secure coding principles, your organization can become more secure without spending any money or impeding business agility.



Thanks for your suggestion well written article with lot of helpful information.
security systems

So that’s how you do it! I may have to suggest this to our supervisor in rfid for inventory management company. So we could secure our properties and to flourish our business.

Now here is something all business owners should pay attention to. These days, just because you're into the home improvement business doesn't make you any safer from hackers, especially with attacks that target point-of-sale.

Very interesting discussion glad that I came across such informative post. Keep up the good work friend.

Every business whether it is a large or small, requires protection and security against unwanted criminal activities. Even small retail businesses should know the fact that robbery and crimes can occur at any time so having a prior preventive measure is quite essential. There are so many ways to provide security to your business and the most effective one is installing surveillance cameras in and out of the office premises. Along with using security cameras, it is also essential to use the services of reliable security company which can provide protection against such criminal activities.

Thanks well for offering outstanding details here... i like your web page. Thanks well and keep mercantilism..... I’m looking forward to your new material.
cloud billing software

I am thoroughly convinced in this said post. I am currently searching for ways in which I could enhance my knowledge in this said topic you have posted here. It does help me a lot knowing that you have shared this information here freely.
Locksmith Florida

The post is definitely fantastic! A whole lot, thank you so much for the useful material talk about with us, please keep make such material. I will be your reliable viewers. Thank you again.
cloud billing software

This helps a lot to know just what to do and what not to do!! houston telephone systems

I have some property in a garage at my workplace that has been broken into. I need to implement a worthy alarm system to help me keep my stuff safe. How do I set up a consultation?


I am usually to writing a blog site and i actually appreciate your material. The material has really mountains my interest. I am going to protect your web page and keep verifying for item new information.

I really believe this awesome web page has got some very awesome information for everyone Incredibly Nice! I think Search engines should seem ahead to it. They can opt to the same seem and experience for item websites to be able to bring development. Magento Web Development Company Bangalore

I have research your publish. Awesome content you done here. This details is useful to for all.
Web Design Company Bangalore | website redesign services in bangalore

Thanks for sharing the information. Enjoyed reading it - Please can you read my Businesses For Sale article and give me some feedback. Will highly your comments.

Some franchises demand high investments with ongoing fees and royalties, moreover, you need to be in for the long run. It is always a better option to let a business broker evaluate everything.

Amazing post with respect to ideal use of capacity units. Before getting a storage room, you ought to be really mindful of the stuffs that you will be putting away into it. Having an arrangement of tangibles will back off your anxiety. aerial installation london

thank you for sharing,,

To place furnishings, discuss with your family how and what Vancouver corporate housing you want to place where in your home.

The Universalist Church involving America am a good Christian Universalist religious denomination in the country and in addition affiliated churches in some other parts of the world universalists

This is all such interesting information that every business owner should know. It makes me think so much more on how security is so important. I am going to look into security for my home and workplace.

I agree that smaller businesses are more likely to get robbed. I need to find a good security system for my toy shop. I do not want to get robbed and if I do I want to catch those that have robbed me. I will use these tips to get a security system.

Repeated Individuals any shifting organizations will always give profitable transportation alternatives and costs will also be quite lesser and cost-effective which we evaluate it with any other tariff charged by several issues.
Hyderabad Packers and Movers
Mumbai Packers and Movers
Pune Packers and Movers
Chennai Packers and Movers

It is so essential to get On Time Delivery from exterior alternatives in situation of personal or expert shifting alternatives.
Bangalore Packers and Movers
Gurgaon Packers and Movers
Delhi Packers and Movers

Nice. Important points for start up companies including Secure programming. good!

With the Facebook 5 Star Scores there has actually been more focus on real involvement of customers and also notably less focus on fluffy metrics of vanity. The customers could now effortlessly transform their scores which recently was a really complex procedure. you can buy pinterest followers

Get a wide range of packing and moving companies at We endeavour to furnish the best packers and movers companies in your city at ease of Internet. Packers and Movers Bangalore

Security is necessary for all human and their assets and do you need a guidance and advice regarding security guard training and license. Get it from security guard pedia, we will provide complete guidance on how to obtain the Security Guard Training in Vermont.

I am always searching online for articles that can help me. There is obviously a lot to know about this. I think you made some good points in Features also. Keep working, great job. SeoDevil15

You have raised a paramount issue..thanks for sharing..i might want to peruse more present issues from this blog..keep posting..Seo Baclinks Social Bookmarking And Backlinks Service.

best free vpn service, is the best and free for everyday vpn tunneling usage. It has 10gb free vpn account for lifetime.

Thanks for sharing such a great article and it’s helpful for everyone. Great Post..
Packers And Movers Bangalore
Packers And Movers in Bangalore

An excellent information provided thanks for all the informations i must say great efforts made by you.
thanks a ton for all the information you provided.
please visit our official website for further details-
Packers And Movers Chennai

very nice blogs!!! i have to learning for lot of information for this sites...Sharing for wonderful information.Thanks for sharing this valuable information to our vision. You have posted a trust worthy blog keep sharing.
Pega Training In Chennai

very nice blogs!!! i have to learning for lot of information for this sites...Sharing for wonderful information.Thanks for sharing this valuable information to our vision. You have posted a trust worthy blog keep sharing.
Pega Training In Chennai

An excellent information provided thanks for all the information i must say great efforts made by you.
thanks a lot for all the information you provided.
please visit our official website for further details-

Your website content is fabulous and awesome but I would like to say your website also good.
Thanks for sharing... Keep it up..
With the many years of experience in supporting people with this requirements and colossal assortment of packers and movers organizations Chennai, we require push to invest you with the better choices. In this way, how about we come us and get help with the best help.
Packers And Movers Chennai

Maruti International Packers and Movers are transporters also provides transport services in all over India and are reliable transporters.
Packers And Movers Pune
Packers And Movers Bill Pune
Packers and Movers pune To Chennai
Packers and Movers Pune to Hyderabad
Packers and movers pune
Packers and movers pune to bagalore
Packing and moving pune
Packers and movers mundhwad pune
Packers and movers kalyani nagar pune
Packers and movers koregaon park pune
Packers and movers kothrud pune
Packers and movers kondhwa pune
Packers and movers pimpri chinchwad
Packers and movers hadapsar pune
Packers and movers magarpatta city pune
Packers and movers kharadi pune
Packers and movers vishrantwadi pune
Packers and movers viman nagar pune
Packers and movers pimple saudagar pune
Packers and movers pashan pune
Packers and movers hinjewadi pune
Packers and movers waked pune
Packers and movers baner pune
Packers and movers aundh pune
Packers And Movers Pune
Packers and movers pune
Packers and movers pune

What a great idea amazing post thanks for sharing i really happy read this post keep sharing..:) e commerce website design and development

On pre-move overview you can likewise get definite data about your mover which benefits you are going to procure.

Packers and Movers in Bangalore @
Packers and Movers in Noida @
Packers and Movers in Ghaziabad @
Packers and Movers in Chennai @

Thanks you for this article. Really interesting and awesome article.

225/2B, Upendranath Banerjee Road, Behala, Parnasree, Kolkata, West Bengal 700060
Phone: 9830233978

After apply the ESTA VISA ,then you get the authorization status.Then you must click the “Next” after getting your ESTA VISA application number.After completing the registration process it will provide only the notification.If your received the approval you need to printout or write down the ESTA VISA application number for checking of the ESTA status.In ESTA VISA Application has the three types of response there are Authoriztion Approved,Authorization Pending and Travel Not Authorized.Candidates who are receiving the ESTA Authorization Pending response need to check the websites updates within 72 hours will receive the final response.

Good Packers and Movers in Bangalore @
Good Packers and Movers in Noida @
Good Packers and Movers in Ghaziabad @
Good Packers and Movers in Chennai @

The best system to Get Miracle Bust courteous supporter Accustomed Breast Accession Review

Slants It contains standard purpose of repression that are perceived to upgrade the admeasurement of the mid-sections and instigate mid-section and ladies' wellbeing. A pleasant augmentation to anaplasty and afflictive mid-section agreeable bras. The decorations are contract and not overpowering. They secure an ambrosial complete knowledge about the old abnormality in their FAQs page. They aswell board you with a yearly to examination the cachet of your requesting. They advancement International Shipping.

Packers and Movers Bangalore - Get Best Movers and Packers in Bangalore offers packing and moving household goods, office and local business shifting, Car and Bike or Vehicle Transportation services from Bangalore to all over India. Quote to Best Packers and Movers in Bangalore, save money and select the best one. Visit More : Top Packers and Movers in Bangalore @

Packers and Movers Bangalore - Get Best Movers and Packers in Bangalore offers packing and moving household goods, office and local business shifting, Car and Bike or Vehicle Transportation services from Bangalore to all over India. Quote to Best Packers and Movers in Bangalore, save money and select the best one. Visit More : Top Packers and Movers in Bangalore @

Packers and Movers in Gurgaon
Packers and Movers in Mumbai
We are providing you free Relocation from up to top 5 packers and movers companies of this city. Make sure you will hire the one that will perfectly, flawlessly and nicely cater to all you’re moving, shifting and relocation needs at the budget you have planned for your movement.

Packers and Movers in Pune
Packers and Movers in Bangalore
Packers and Movers in Mumbai

The lymph vessels are a system of vessels that channel blood polluting influences; they contain an unmistakable, dismal liquid called lymph. Lymph goes from vessels to lymph vessels and moves through lymph hubs that are situated along the course of these vessels. Cells of the lymph hubs phagocytize, or ingest,

Hey @BobySingh & @YasSingh you can also be rely on us for shipping ur vehicle from one destination place to another with low cost fleet services

Phen375 is a popular diet supplement drug in the US. It is manufactured in a FDA (Food and Drug Administration, US) authorized facility. Phen375 is an alternative to a popular prescription drug named Phentermine. Phen375 is so powerful that after taking only 2 diet pills you can literally see the pounds disappearing. For More Information Visit:

Packers and Movers in Indore - Best Movers and Packers in Indore for packing and moving household goods, office and local shifting, cat transportation services at affordable prices, by Indore Packers and Movers @

All the best blogs that is very useful for keeping me share the ideas
of the future as well this is really what I was looking for, and I am
very happy to come here. Thank you very much
earn to die
earn to die 2
earn to die 3
Hi! I’ve been reading your blog for a while now and finally got the
earn to die 4
courage to go ahead and give youu a shout out from
earn to die 6
Austin Texas! Just wanted to tell
earn to die 5
Hi! I’ve been reading your blog for a while now and finally got the
happy wheels
strike force heroes
you keep up the fantastic work!my weblog
age of war
good game empire
Find helpful customer reviews and review ratings for Garcinia Cambogia Select - 100% Pure Garcinia Cambogia Extract with 50% Hydroxycitric Acid (HCA).

What a fun and upbeat read! I wanna start a blog now after reading this!,
Event Management Companies in Delhi

Great! Thanks for sharing the information. That is very helpful for increasing my knowledge in this fiel
Red Ball | | duck life | Slitherio
Red Ball 2 | Red Ball 3 | Red Ball 4

Get fast amazing weight loss results with Phen375 and lose upto 20 pounds a month on average!

Packers and Movers Bangalore @
Packers and Movers Gurgaon @
Packers and Movers Chennai @

Packers and Movers Bangalore @
Packers and Movers Bangalore @
Packers and Movers Indore @
Packers and Movers Kolkata @
Packers and Movers Delhi @
Packers and Movers Ahmedabad @
Packers and Movers Bhopal @

MoversPackersOnline.Com provides you the best Office relocation solutions by professionals. Whether the moving is local, or you are moving to another state.
Packers and Movers
Packers and Movers Bangalore
Packers and Movers Hyderabad
Packers and Movers Delhi
Packers and Movers Chennai

Get transferring answer via high-quality Packers and Movers Bangalore. offers free fees of pinnacle Movers and Packers Bangalore. Compare to store cash and choose the exceptional.

Packers and movers in Bangalore to to hack android game lucky patcher This post is to good for me. Then i want to introduce my on site at fishdom | abcya slitherio | . Give us our feedbacks if you want some change in my site. don't hesitate!

Jyoti Speed Packers And Movers Company is the highest quality professional packing and moving services at the most affordable prices.Indore In India
packers and movers Hoshangabad
packers and movers Coimbatore @

Crazy bulk is one of those stacks that not only increase up the lean muscles but it also increases the internal strength, stamina and power.Crazy Bulk products are made up purely of legal elements that have no damaging effects, whatsoever, rendering it completely non-toxic and safe to use.

Looking for proven, effective Dianabol for Sale without side effects? Discover premium Dbal-Max Pills currently helping guys build mass safely.

Professional Expert level Android Training in chennai, Android App Development
Android Training | Android App Development | Training in chennai

Your article is nice. Thanks for sharing such a wonderful post and keep updating,it's helpful to anyone.....Android Project Center in Chennai | Android Training Institute in Chennai

Thanks for the nice post

Packers and Movers Bangalore Will Ensure Tension-Free Move

Ready to move? Request free quotes today!

Packers and Movers Bangalore @

. Efficient while using the assistance meant for moving together with taking using packers and movers within Delhi, switching provider within Delhi, packers in addition to movers Delhi along with packers movers around Delhi.
Packers and Movers Pune
Packers and Movers Noida
Packers and Movers Delhi
Packers and Movers Gurgaon

Packers and Movers in Bangalore List
We supply our packers and movers courses of action over the India, with select-usaduring Bangalore. From single question finish houses, we're going to safely conveyance
Packers and movers in bangalore@
Packers and movers in delhi@
Packers and movers in mumbai@
Packers and movers in gurgaon@
Packers and movers in chandigarh@
Packers and movers in pune@
Packers and Movers in Zirakpur@
Packers and movers in kolkata@
Packers and movers in bikaner@
Packers and movers in ahmedabad@

Thanks for sharing your info. I really appreciate your efforts and I will be waiting for your further write.
Thanks for sharing !
tanki online 2 | game 2048 online

This comment has been removed by the author.

Post a Comment