SMEs appear ill-prepared for greater risks of cyberattacks as online workforce rises

Cybersecurity may not be top-of-mind for smaller companies facing looming recession, say specialists

Published Tue, Jul 28, 2020 · 09:50 PM

    Singapore

    SMALL and medium-sized enterprises face greater risks of cyber attacks and data breaches than they realise, as more of their employees work from home during the pandemic.

    Cybersecurity firm Trend Micro told The Business Times that in Singapore, it had blocked 23,000 phishing e-mails and almost 12,000 malicious URLs related to Covid-19 in the first half of the year. This was on top of the number of attacks the firm typically blocks, it said.

    "It's most likely that threat actors took advantage of the rising number of Covid-19 cases as a lure to victimise users who wanted more information," said Trend Micro's vice-president for South-east Asia and India, Nilesh Jain.

    Meanwhile, Singapore-based cybersecurity firm Polaris Infosec, a member of the Innovation Cybersecurity Ecosystem at Block71 (ICE71), said the number of attacks passing through its network more than doubled in the first half of the year compared to the second half of 2019.

    Ryan Murray, regional director for Asia-Pacific at New York-based cybersecurity firm White Ops, told BT that given the increase in online traffic as most people were forced to stay home to prevent the spread of Covid-19, it was expected that there were also proportionately more attacks per day.

    "No business - regardless of size - was immune."

    Unfortunately, smaller companies may be inadequately prepared for the greater risks that they now face.

    Specialists estimated that up to 80 per cent of SMEs in Singapore are not well-equipped to deal with the additional threats of opportunistic cyber criminals looking to exploit a burgeoning online workforce.

    Paul Hadjy, co-founder and chief executive of cybersecurity startup Horangi, which lists multiple SMEs as its clients, told BT that although its clients have not been cutting their cybersecurity budgets, security spend through the crisis has "generally stayed flat".

    The ones that do invest tend to be those in regulated sectors such as finance, fintech and insurance, he added.

    The Infocomm Media Development Authority has made funding available to companies for cybersecurity solutions under the SME Go Digital programme. SMEs can receive funding support under the Productivity Solutions Grant (PSG) of up to 80 per cent of the qualifying cost of pre-approved cybersecurity products and services. But only 69 SMEs had adopted these solutions as at end-June.

    Reasons for the lack of preparedness vary. Some SMEs may have a limited cybersecurity budget while others may incorrectly assume that they are not at risk.

    "A common misconception is that cyber criminals go only after large enterprises, but the reality is quite the opposite," said Trend Micro's Mr Jain.

    Smaller companies also have sensitive, high-value information that cyber criminals can use to their advantage, he added.

    With a recession looming and companies trying to cut costs, specialists also acknowledged that cybersecurity might not be on the top of business owner's minds.

    "Some SMEs simply lack the time, budget and expertise to hunt for cyber threats. Unless there is government intervention, SMEs are likely to prioritise other business spending over cybersecurity, which is usually seen as a pure expense," said Mr Jain.

    Lim Yi Hao, principal analyst for Fire Eye's Mandiant Threat Intelligence, added: "Many startups or SMEs don't look upon security as a revenue generator, but instead, as a cost. If times are hard, it's not surprising that cybersecurity would be one of the places owners would try to cut costs in."

    Trying to save on cybersecurity solutions, however, could end up costing companies more.

    According to IBM's 2019 report, the average cost of a data breach is estimated at US$3.9 million. The pain can be felt by businesses for years after the incident. This includes lost business costs, detection and escalation costs, notification costs, and the costs associated with reparation to data subjects and regulators.

    The same report found that small businesses face "disproportionately larger costs relative to larger organisations", which can hamper their ability to recover financially from the incident.

    "It is a business imperative for SMEs to invest in basic cybersecurity tools, which is far less costly than paying the price of a data breach," said Trend Micro's Mr Jain.

    A comprehensive cybersecurity strategy could total around S$500 to S$1,000 per employee, according to Polaris Infosec's co-founder, Lee Heng Yu. He said the cost would vary depending on the size, scope and scale of data that the company collects.

    Smaller businesses can also implement cost effective measures to help them improve their cybersecurity posture - such as having a basic antivirus software, training employees, encrypting and backing up documents, and limiting the amount of data collected from consumers.

    "SMEs should be cyber aware and either work with a trusted cybersecurity partner or harness training grants from the government to meet international ISO and Singapore's standards for information security," said Trend Micro's Mr Jain.

    Garage is BT's startup vertical. Read more news, analysis and opinions at bt.sg/garage

    READ MORE: Remote working creates higher risk of online attacks for firms: specialists