Common Cyber Threats Every Business Should Know
You do not need to be a security expert to protect your business, but it helps to know what you are up against. Most attacks fall into a handful of familiar patterns. Here are the ones most likely to reach a small or midsize business, in plain terms.
Phishing and spear phishing
Section titled “Phishing and spear phishing”Phishing is a fake email, text, or message built to trick you into handing over information or clicking something harmful. It often points you to a lookalike website that captures your password or card details. Spear phishing is the targeted version. The attacker researches you or a coworker first, then poses as someone you trust, such as a vendor, your bank, or your boss. Because the message looks relevant, it is harder to catch. Phishing was behind more than 80% of reported security incidents in 2020, and about 98% of attacks rely on some form of this social engineering.
Ransomware and other malware
Section titled “Ransomware and other malware”Malware is any software built to harm or take over a system. Ransomware is the kind that locks up your files and demands payment for the key. It usually arrives through an email attachment or link, and roughly 92% of malware is delivered by email. Newer ransomware also goes after your local backups so you cannot simply restore and move on, which is why offsite and isolated backups matter. Cybercrime rose sharply during the COVID-19 pandemic, and ransomware remains one of the most expensive attacks a business can face.
Password attacks
Section titled “Password attacks”A password attack is any attempt to guess, steal, or crack your login. That can be as low-tech as someone reading a sticky note on your desk, or as automated as software trying millions of combinations. Reused passwords make this easy. About 73% of passwords are duplicates, so one leaked password can open many accounts. Locking accounts after a few failed attempts and turning on multi-factor authentication shut down most of these attempts.
Man-in-the-middle attacks
Section titled “Man-in-the-middle attacks”In a man-in-the-middle attack, someone secretly sits between you and the site or service you are talking to, reading or changing what passes through. Public Wi-Fi and unsecured connections are common openings. Using encrypted connections and a VPN on untrusted networks keeps your traffic private.
Drive-by downloads
Section titled “Drive-by downloads”A drive-by download infects your system with no action from you beyond visiting a booby-trapped web page or ad. It takes advantage of software that has not been updated. Keeping your browser and applications current removes most of the openings these attacks use.
Denial-of-service (DDoS) attacks
Section titled “Denial-of-service (DDoS) attacks”A distributed denial-of-service attack floods a website or system with junk traffic until it slows down or stops responding. The attacker does not steal data, but the downtime can cost you real money. Between January 2020 and March 2021, these attacks rose 55%.
What this means for you
Section titled “What this means for you”The rest of this guide covers the habits that block these threats. None of them require special skills. They require doing a few basic things consistently.
Need a hand with any of this? Call Robb Technology Group in Lubbock, Texas at (806) 370-4700 or email support@robb.tech.