No business too small to be hacked
Small and mid-size firms are susceptible to ransomware, a malware which holds data hostage in return for money
New York
JUST as the holiday shopping season neared, a toy company, Rokenbok Education, was navigating a nightmare situation: Its database files had been infected by malware.
Online criminals had encrypted company files, making them unusable, and were demanding a hefty ransom to unlock the data. Rokenbok, a California-based company that uses building blocks and even robotics to teach children how to think like engineers, lost thousands of dollars in sales in two days.
Rokenbok's founder and executive director, Paul Eichen, was already struggling to adapt his seven-employee company to a fast-changing toy world. Even worse, the malware attack was not Rokenbok's first. The company had been hit earlier with a denial of service attack that shut down the company's website. "I sweated that one," Mr Eichen said. "Customers' first impressions are critical."
Focusing on revenue over protection is far from unusual for small companies such as Rokenbok. But it is an increasingly dangerous path, specialists say. Limited security budgets, outdated security and lax employees can leave holes that are easily exploited by ever-more-sophisticated digital criminals.
The threat to small businesses is growing, some specialists say. Some 60 per cent of all online attacks in 2014 targeted small and mid-size businesses, according to Timothy Francis, enterprise leader of cyberinsurance at Travelers. "Smaller companies are easier to hack," said Clay Calvert, director of security at MetroStar Systems, a Virginia-based firm. "They don't have the resources to set up protective barriers."
Big companies, which have the financial resources to upgrade their security, have become less vulnerable.
These days, businesses such as Rokenbok are especially susceptible to a type of malware called ransomware, which holds data hostage in return for money. Data is slowly encrypted by criminals until the entire system is locked up. The process can take up to 42 days, Mr Calvert said.
Rokenbok's ransomware attack made its database files unusable. But rather than pay the ransom, the company reconstructed its key systems, a process that took four days.
Although figures are hard to come by, specialists say these kinds of attacks can be so damaging to revenue and customer expectations that many small businesses are forced to close after an episode like the one Rokenbok experienced. And increasingly, as in Rokenbok's case, criminals are going after cash through attacks using ransomware rather than through attacks on credit card data.
"Credit card numbers are harder to monetise," said Christopher Young, general manager of the Intel Security Group at Intel Corp. "You have to get the numbers and sell them to someone else before you make money."
Ransomware, he said, is high volume and requires no middleman. Hackers gain entry when employees click on malicious links in e-mails or download infected material. Phishing attacks, which use malicious e-mails to steal data, are also on the rise, security specialists added.
Given the increase in such attacks, being unprepared is like playing security roulette, said Robert Siciliano, chief executive of IdTheftSecurity.com. "If you're not deploying some level of security, you'll go under," he added. "You have to make time for quality control. The worst thing you can do is nothing."
Mr Siciliano recommends a security audit as a first step. The audit should take note of potential areas of risk, such as customer data or employee access.
Strengthening security can be inexpensive and simple - something small businesses can do on their own, specialists say. It can include updating anti-virus software, adding firewalls and strengthening passwords. Or it can mean putting data in the cloud rather than on company servers, which may be more vulnerable. But often, given lean staffing, it makes more sense and can cost less in the long run to hire a firm that specialises in digital security.
Steven Annese, owner of the lighting and home decor company EliteFixtures, knew he needed tighter security as his business soared. So he outsourced security to a Web performance and security firm, CloudFlare.
Mr Annese uses a checklist to make sure security updates are installed. And he logs onto CloudFlare every day to see what threats have been blocked and to review site analytics.
Among the simpler precautions small businesses and consumers alike can take is to create strong passwords. That has long been the advice of security specialists but many say it is stunning how many people and small businesses fail to heed the advice.
Hackers use Big-Data analytics to help crack passwords, said Mr Calvert at MetroStar Systems. "They have databases of passwords," he said, "and they analyse how we come up with them."
He recommends using passwords that are 20 characters or longer and that contain a mix of characters. The longer the password, the harder it is to crack. Password managers, which use software to encrypt passwords, are another option, he added.
Online security tutorials are helpful and free. They can be found on government sites like that of the Small Business Administration, which also has webinars, and the site of the Defense Security Service, part of the Defense Department. NYT
TRENDING NOW
US dollar falters after Iran’s offer to reopen Hormuz sends oil lower
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Floods compound Philippine growth woes from public-works scandal
Tokyo reverses baby bust with AI matchmaking and generous subsidies