Three Key Factors That Small Business Owners Must Consider To Enhance Their Cybersecurity

Awareness
Awareness (Photo credit: Emilie Ogez)

By now most small business owners are aware that Cybersecurity is an issue. But, how much time and capital should be spent on cybersecurity protection? This article discusses three key factors that should play into that decision.

Factor #1 Awareness.

According to some experts, the biggest problem that small business owners face is simply awareness of the risk. This includes awareness by employees as well.

Most data leaks and other security incidents are caused by employees who are either unaware of security protocols or indifferent to them. Regardless of the level of security in your data center  or the strength of encrypted communications, the weakest link will almost always be the human beings interacting with the network.

To address this risk, small business owners need to focus on training and awareness for employees. However, company management is usually focused on sales and customer service. Further, owners often lack the time and expertise needed to properly assess security risks. Companies in any industry should look to partner with a third-party security firm to asses risks and develop appropriate training.

Factor #2 Employee Training.

Training is the first line of defense against cyber threats. This training needs to include the entire company, and should cover three key areas: (a) proper password management on all company services and devices, including clear procedures for new and departing employees, as well as day-to-day usage; (b) clear guidelines for the sharing of information with remote employees, partners and third parties; and (c) a plan for monitoring usage and privileges to the company’s digital assets.

Employee training needs to account for how the public will access your company’s products or services. For example, what if a hacker got into a system by pretending to be another user? By rolling out new features slowly, its easier to identify and fix security loopholes.

All stakeholders need awareness of: (a) the type of information you’re transmitting (e.g. payment information), (b) the visibility of information you’re transmitting (e.g. highly-publicized public launch vs. a quiet rollout of some new software), and (c) the level of security inherent in the transmission (e.g. encrypted emails and documents shared via a secure server or data shared publicly through public networks and via social media sites.

Factor #3 Vigilance (Monitoring).

For some companies everything is available and accessed online. Since online relationships are built upon trust, it is critical that the company actively monitor the security and transparency of this relationship. Many tools are available to measure and respond to risk factors and gauge likelihood of an impact to help determine the level of investment required. Resources can be assigned to anything with high likelihood and high impact.

For example, monitoring potentially fraudulent user accounts has an immediate commercial benefit as well as reducing risk.

Unfortunately, a common misconception is that putting up basic defenses like firewalls will protect security vulnerabilities. However, after reinforcing your Cybersecurity defense, the focus should shift to monitoring and alerting. In many cases, this may require up-front investments to enable tracking and alerting to irregularities in network and data activity. Fortunately, in the event of a breach or a loss of data, this monitoring information will be the key factor in addressing the problem and pinpointing the issue. Managers, employees and business partners need to understand that Cybersecurity is an ongoing process. Awareness, training and monitoring will go a long way toward enhancing a small business’ Cybersecurity preparedness.

About the Author:

David M. Adler, Esq. is a partner in the Chicago office of Leavens, Strand, Glover & Adler, LLC, a boutique intellectual property and entertainment law firm in Chicago, Illinois whose mission is providing businesses with a competitive advantage by enabling them to leverage their intangible assets and creative content in order to drive innovation and increase overall business value. The practice is organized around five major substantive areas of law: Intellectual Property Law, Commercial & Finance Law, Entertainment & Media Law, Corporate Law and Contract Law.

Contact us for a free consultation today. Dadler @ lsglegal (dot) com or (866) 734 2568

Adlerlaw’s International Cyber Security Legal News

Experts: State Needs Long-Term Cyber Security Plan
WLTX.com

By TIM SMITH — The Greenville News. A month after state officials learned of a massive data breach at the Department of Revenue, officials are still discussing what security measures to take to protect all of the state’s computer systems.

How Obama’s reelection may spur work on cybersecurity in the United States
The Next Web (blog)

Now that the President’s electoral and popular vote victories are in the books, their various ramifications are still being felt. One key element of the addition of four more years to the President’s legacy is the issue of cybersecurity.

Israel’s HLS 2012 Event Highlights Cyber Security Innovations
Defense Update

The Cyber Security panel taking place in Tel-Aviv this week at the HLS 2012 event is attracting considerable interest on the backdrop of the recent revelations of massive Iranian cyber attacks crippling the networks of Aramco Oil Company in Saudi Arabia.

Cyber security facility launched
Alpena News
YPSILANTI, Mich. (AP) — Michigan Gov. Rick Snyder has announced the opening of a facility designed to help electronic security professionals detect and prevent cyber threats and attacks.

Evolving Cyber Crooks Waiting For That Click
The Borneo Post
On the final day of the three-day Cyber Security Awareness campaign, Mohd Izuddin bin Hj Md Hussin, Learning Solution Specialist from Tech One Global, who delivered a public talk on ‘Protect your Computer, Your Family and Yourself’ at Times Square.

Is Obama’s Cybersecurity Executive Order Imminent?
Of course, there remains the chance that Congress will pass some version of a cybersecurity bill before the president can issue his edict.

Outrageous! Seven Rent To Own Firms Used Nefarious Software to Spy on Customers in Their Homes

On September 25, 2012, the Federal Trade Commission announced a settlement with seven rent-to-own companies that secretly installed software on rented computers, clandestinely collected information, took pictures of consumers in their homes (WTF?!) and tracked these consumers’ locations.

If you haven’t vomited on your computer from the sickening outrage, you can read the FTC press release here.

Software design firm DesignerWare, LLC licensed software to rent-to-own stores ostensibly to help them track and recover rented computers. The software collected the data that enabled rent-to-own stores, including franchisees of Aaron’s, ColorTyme, and Premier Rental Purchase, to track the location of rented computers without consumers’ knowledge

According to the FTC, the software enabled remote computer disabling if it was stolen, or if the renter failed to make payments. It included an add-on purportedly to help stores locate rented computers and collect late payments. Alarmingly, the software also collected data that allowed the rent-to-own operators to secretly track the location of rented computers, and thus the computers’ users.

When activated, the nefarious feature logged key strokes, captured screen shots and took photographs using a computer’s webcam, according to the FTC. It also presented a fake software program registration screen that tricked consumers into providing their personal contact information.

“An agreement to rent a computer doesn’t give a company license to access consumers’ private emails, bank account information, and medical records, or, even worse, webcam photos of people in the privacy of their own homes,” said Jon Leibowitz, Chairman of the FTC. “The FTC orders today will put an end to their cyber spying.”

“There is no justification for spying on customers. These tactics are offensive invasions of personal privacy,” said Illinois Attorney General Lisa Madigan.

A complete collection of the 38 federal acts governing U.S. information privacy law.

A complete collection of the 38 federal acts governing U.S. information privacy law.

1. Bank Secrecy Act
2. Cable Communications Policy Act
3. CAN-SPAM Act
4. Children’s Online Privacy Protection Act
5. Computer Fraud and Abuse Act
6. Communication’s Assistance for Law Enforcement Act
7. Computer Security Act
8. DNA Identification Act
9. Dodd-Frank Wall Street Reform and Consumer Protection Act
10. Drivers Privacy Protection Act
11. Economic Espionage and Protection of Proprietary Information Act
12. Electronic Communications Privacy Act
13. Electronic Signatures in Global National Commerce Act (ESIGN)
14. Employee Polygraph Protection Act
15. Fair and Accurate Credit Transactions Act of 2003 (FACTA)
16. Fair Credit Reporting Act
17. Family Educational Rights and Privacy Act
18. Federal Computer Crime Act
19. Federal Privacy Act
20. Federal Trade Commission Act
21. Foreign Intelligence Surveillance Act
22. Freedom of Information Act
23. Gramm-Leach-Bliley Act
24. HIPAA Regulations
25. Identity Theft Assumption and Deterrence Act
26. Medical Computer Crime Act
27. OECD Privacy Guidelines
28. PATRIOT Act
29. PIPEDA Privacy Act
30. Privacy Protection Act
31. Real ID Act
32. Right to Financial Privacy Act
33. Safe Harbor Privacy Principles
34. Telecommunications Act
35. Telephone Consumer Protection Act
36. Uniform Computer Information Transactions Act (UCITA)
37. Veteran’s Affairs Information Security Act
38. Video Privacy Protection Act

International Cybersecurity & Information Security News Roundup

UVU receives $3 million grant for cybersecurity training
Deseret News

26 2012 4:39 p.m. MDT. Summary. With the help of a $3 million grant from the U.S. Department of Labor, officials at Utah Valley University are working to meet the demand for workers trained in information technology and cybersecurity.

Cyber-security contest in RI opens to students
Boston.com
PROVIDENCE, R.I. (AP) — Students interested in the field of cyber-security are being urged to enter the state’s third Cyber Foundations Competition. U.S. Rep. Jim Langevin (LAN’-jih-vin), who is co-chair of the Cybersecurity Caucus in Congress, says.

Government said to be making larger strides in cybersecurity
FCW.com
Michael Daniel, special assistant to the president and cybersecurity coordinator at the NSC, highlighted progress in a number of initiatives including short-term, medium-term and long-term plans. “Right now cyberspace seems to favor the intruder…”

Verizon Joins Cybersecurity Group
Personal Liberty Digest
GAITHERSBURG, Md. (UPI) — Communications company Verizon has joined the Lockheed Martin Cyber Security Alliance to counter cybertreats to U.S. information technology infrastructure.

Media Advisory: Minister Toews to Make Announcement Related to Cyber
U.S. Politics Today
MISSISSAUGA, ONTARIO — (Marketwire) — 09/26/12 — The Honourable Vic Toews, Minister of Public Safety, will launch Cyber Security Awareness Month. He will be joined by Michael Kaiser, Executive Director of the U.S. National Cyber Security Alliance.

Lieberman pushes Obama to issue cybersecurity executive order
Daily Caller
Lieberman was the lead co-sponsor of the failed Cybersecurity Act of 2012, a controversial bill that sought to give the federal government regulatory control over the cybersecurity standards of water, power and utility companies.

White House said to plan EO on cybersecurity
ABS CBN News
SAN FRANCISCO – The White House is preparing to direct federal agencies to develop voluntary cybersecurity guidelines for owners of power, water and other critical infrastructure facilities, according to people who said they had seen recent drafts.

Northrop Buys M5 Network Security – Analyst Blog
NASDAQ
Northrop Grumman Corporation ( NOC ) has closed the acquisition of M5 Network Security Pty Ltd. for an undisclosed amount. Canberra, Australia-based, M5 Network Security Pty Ltd. provides cyber security and secure mobile communications products and …

Official Reaffirms US DOD Commitment to Cybersecurity
defpro
The U.S. Defense Department remains vigilant and committed to cybersecurity, especially since its cyber operations present a target for hackers, a senior Pentagon official said here Sept.

World Information, Data & Cyber Security News & Legal Roundup

German cybersecurity agency prods users to ditch IE

Computerworld – Germany’s cybersecurity agency on Monday urged users to drop Internet Explorer (IE) and switch to a rival, like Chrome or Firefox, until Microsoft patches a new critical bug in its browser.

Democratic senators call for ‘cybersecurity’ executive order
CNET

Senators call for ‘cybersecurity’ executive order. This summer’s partisan sparring that derailed a federal cybersecurity law has resumed, with Democrats proposing an executive order and Republicans saying it would levy “more mandates.”

Cybersecurity scholarships to be offered
UPI.com

“The nation is in dire need of people who are capable of handling the cybersecurity challenges we face,” professor of computing and information sciences Xinming “Simon” Ou said. “We are lagging behind in the number of experts we have versus the threats.

Cybersecurity: Kay Bailey Hutchison condemns Obama’s ‘heavy handed …
Houston Chronicle (blog)

Amid escalating partisan rhetoric over the bipartisan goal of protecting U.S. computer systems from terrorist attacks, Texas Kay Bailey Hutchison criticized President Obama for a “heavy handed, regulatory regime” that would be created.

National Cyber Security Alliance Announces Theme for Data Privacy Day
The Herald | HeraldOnline.com

18, 2012 /PRNewswire-USNewswire/ — The National Cyber Security Alliance (NCSA), a non-profit public-private partnership focused on helping all digital citizens stay safer and more secure online and official coordinator of Data Privacy Day (DPD), today …

When it comes to cybersecurity law, where do we draw the line?
ZDNet

Over the past few years, the Obama administration and Congress have taken a variety of legislative runs at creating comprehensive cybersecurity law. See Also: How cybersecurity is like Star Trek’s transporter.

Cyber security biggest challenge for universal credit, says David Freud
ComputerWeekly.com

Cyber security is the biggest challenge for the government’s universal credit roll-out, welfare reform minister David Freud has told a select committee. Speaking to a select committee, pensions minister Ian Duncan Smith said government had consulted …

NetLib teams with CIS to fight cyber security
Mass High Tech

Neil Weicher wants to win the battle in cyber security. NetLib, a Stamford, Conn.-based provider of encryption software founded by Weicher, has partnered with the Center for Internet Security, a non-profit focused on cyber security readiness.

UK spy agency tests Britons’ cyber skills
Reuters

The Government Communications Headquarters (GCHQ) said those aged 16 or over and not already working in cyber security could apply to test their ability to guard a computer network but only 150 contestants at most would be eventually allowed.

Former FBI Cybersecurity Official Steven Chabinsky Thinks FBI is Doing Great …
ticklethewire.com

The FBI’s former top attorney for cybersecurity, Steven Chabinsky, who stepped down this month, thinks the FBI is doing a great job battling the problem, but told the Washington Post that the “federal government” has taken a “failed approach”.

Rep. Markey introduces Mobile Device Privacy Act (H.R. 6377)

Representative Markey is no stranger to mobile privacy issues. Last year, Rep. Markey asked the FTC to investigate the practices of the Carrier IQ software company as a possible unfair or deceptive act or practice.

On September 12, 2012, Rep. Markey, co-Chair of the Bi-Partisan Congressional Privacy Caucus, released H.R. 6377, “The Mobile Device Privacy Act.” The legislation would require companies to disclose to consumers the capability to monitor telephone usage, as well as require express consent of the consumer prior to monitoring.

“Just because a mobile device is hand held doesn’t mean it should hand over personal information to third parties without permission,” said Markey in a released statement.

FTC Publishes Guide to Help Mobile App Developers Observe Truth-in-Advertising, Privacy Principles

Sept. 5 2012:

From the FTc web site:

The Federal Trade Commission has published a guide to help mobile application developers observe truth-in-advertising and basic privacy principles when marketing new mobile apps. The FTC’s new publication, “Marketing Your Mobile App: Get It Right from the Start,” notes that there are general guidelines that all app developers should consider. They include:

Tell the Truth About What Your App Can Do. – “Whether it’s what you say on a website, in an app store, or within the app itself, you have to tell the truth,” the publication advises;

Disclose Key Information Clearly and Conspicuously. – “If you need to disclose information to make what you say accurate, your disclosures have to be clear and conspicuous.”

Build Privacy Considerations in From the Start. – Incorporate privacy protections into your practices, limit the information you collect, securely store what you hold on to, and safely dispose of what you no longer need. “For any collection or sharing of information that’s not apparent, get users’ express agreement. That way your customers aren’t unwittingly disclosing information they didn’t mean to share.”

Offer Choices that are Easy to Find and Easy to Use. – “Make it easy for people to find the tools you offer, design them so they’re simple to use, and follow through by honoring the choices users have made.”

Honor Your Privacy Promises. – “Chances are you make assurances to users about the security standards you apply or what you do with their personal information. App developers – like all other marketers – have to live up to those promises.”

Protect Kids’ Privacy. – “If your app is designed for children or if you know that you are collecting personal information from kids, you may have additional requirements under the Children’s Online Privacy Protection Act.”

Collect Sensitive Information Only with Consent. – Even when you’re not dealing with kids’ information, it’s important to get users’ affirmative OK before you collect any sensitive data from them, like medical, financial, or precise geolocation information.

Keep User Data Secure. – Statutes like the Graham-Leach-Bliley Act, the Fair Credit Reporting Act, and the Federal Trade Commission Act may require you to provide reasonable security for sensitive information.

Cybersecurity, information & Privacy News Roundup

Cybersecurity, and insecurity, vexes nations
Minneapolis Star Tribune

Cybersecurity, the subject of this month’s Minnesota International Center’s “Great Decisions” dialogue, is a hot topic in the Beltway, Silicon Valley and on Wall Street. It’s also an important subject in Foggy Bottom and Turtle Bay.

CIO Magazine Cybersecurity News Roundup: MyAgent Trojan; Virus Infects Saudi Oil Giant

Cybersecurity News Roundup: MyAgent Trojan; Virus Infects Saudi Oil Giant; and Pro-Censorship Hackers. This week’s IT security news roundup features stories on the newly discovered MyAgent Trojan; malware that forced a Saudi Oil Giant to shut down.

What you should know about cybersecurity
Minneapolis Star Tribune

Congress is now in recess. But before its members left town, back on Friday, Aug. 3, they rejected a bipartisan bill that would have established optional “cybersecurity” standards for the computer systems that operate the country’s power grids, dams.

A Cybersecurity Dream Act Alternative
BankInfoSecurity.com (blog)

Will Obama use the Dream Act model of bypassing Congress to advance his cybersecurity agenda? Obama’s counterterrorism adviser John Brennan hints that such an order could come [see Cat Out of Bag on Infosec Regulation?].

Cyber security and disaster planning go hand in hand
Colorado Springs Business Journal

When the Waldo Canyon fire roared closer to Colorado Springs on June 26, Jeff Beauprez, president and CEO of Colorado Networks, started getting frantic phone calls from businesses along the Garden of the Gods Road corridor.

The Battelle CyberAuto Challenge encourages students to pursue cybersecurity.
LiveScience.com

Today’s cars have grown vulnerable to the threat of computer viruses or hackers — security researchers have even shown how to remotely unlock a vehicle or start a car’s engine using simple text messages. But a group of U.S. students who attended the …

Obama may bypass lawmakers with cybersecurity executive order
Leader and Times

Senate Republicans recently blocked cybersecurity legislation, but the issue might be revived by the White House, a federal law enforcement official told the Law Enforcement Examiner on Monday.

Cyber security boot camp to educate potential cyber spooks
ComputerWeekly.com

Stephanie Daman, CEO at the Cyber Security Challenge UK, said the cyber camp concept is something completely new for this year’s Challenge: “It represents a great opportunity for our expert sponsors to work closely with a group of young talent.”

Baltimore-area colleges win $4.7M in cyber security grants
Bizjournals.com

Harford Community College will receive $74000 to put toward its work with the Regional Cybersecurity Education Initiative. HCC, University of Delaware and Delaware Technical and Community College formed the education initiative with industry partners …

Blank Rome Lobbying for Motorola Solutions on Cybersecurity, Tax Reform
The BLT: Blog of Legal Times (blog)

The lobby shop is advocating for the Schaumburg, Ill.-based telecommunications company on “[i]ssues related to public safety/D block spectrum; issues related to cybersecurity; issues related to tax reform legislation,”

Collaborative Cybersecurity: Why the private sector is essential.
By Paul Nicholas – TwC

The official Microsoft Security Blog provides in-depth discussion of security, cybersecurity and technology trends affecting trust in computing, as well as timely security news, trends, and practical security guidance.

The Cybersecurity Blame Game Continues
The stalling, bickering, almost-breakthrough, and eventual demise of cybersecurity legislation in the United States Senate was a sad thing to watch.