Surveys carried out by the Information System Authority (RIA) and Statistics Estonia show that SMEs train their employees on cyber threats much less frequently than larger companies. In addition, they often only start planning major investments in cyber security when something actually happens.
‘However, preventing risks is always cheaper than dealing with the consequences. Only a few weeks ago, a company informed us that they had prevented an invoice fraud of more than a million euros,’ said Märt Hiietamm, Head of RIA’s Analysis and Prevention Department.
‘Research shows that many businesses know very little about the threats in cyberspace. There is also a lack of understanding of the potential damage of cyber attacks and the likelihood of them happening,’ Hiietamm explained. ‘Smaller businesses themselves think that they are not attractive enough targets for criminals, but in fact, they are often targeted because they have a lower average level of security.’
That is why, during Cyber Security Month in October, RIA’s awareness campaign will focus on SMEs. ‘Cyber security is not just an IT expense. In the worst case, a cyber attack could end in the company going bankrupt and leaving a large number of people out of work,’ stressed Hiietamm. Speaking of one of the most serious recent incidents, he mentioned a ransomware attack on two industrial companies in Harju County at the beginning of the year, which severely disrupted the work of hundreds of employees for several weeks.
‘In our work, we often see that a cyber attack can cause damage not only to the company itself, but also to its customers and business partners. Direct economic damage is often accompanied by reputational damage,’ said Hiietamm.
These risks are exemplified by the attacks against the service provider, or supply chain attacks, which have become common in recent years. In the case of such attacks, the network of the IT service provider is penetrated, for example, and the information systems of its customers are compromised. ‘We often see that the responsibilities and risks involved in the supply chain for providing an IT service or any other service are not fixed in the contract at all. In the worst case, there is not even a contact person to write to or call if a problem arises,’ explained Hiietamm.
The underestimation of cyber risks is well illustrated by a case last year where the Incident Response Team of RIA (CERT-EE) discovered more than 300 online shops using outdated software, making them vulnerable to one particular security flaw. Despite repeated reminders, almost a hundred e-shops still had not updated their software this summer.
If criminals manage to hack into an e-shop, they can install malware or create a phishing page to steal customer data – including bank card details. The careless handling of personal data can also lead to hefty fines of up to €20 million or 4% of a company’s turnover in the previous financial year, according to the General Data Protection Regulation of the EU.
On the positive side, Hiietamm pointed out that companies are increasingly aware of the most common scams. He also encouraged them to report incidents to RIA on the website report.cert.ee or [email protected] to further protect Estonian cyberspace.
‘Lead IT-securely!’, RIA’s information campaign starting today, will provide companies with information about cyber threats and how to prevent them, and a quick guide of cyber security (available in English) has also been created. You will also find lots of useful tips from RIA’s advice for institutions and businesses (in Estonian). In addition, businesses can apply for up to €60,000 in support to assess and improve their cyber security.
How to protect your business from cyber threats?
- Know what hardware and software you’re using – to map your company’s protection needs, you need a clear overview of your systems and what is happening on your internal networks.
- Protect your assets – manage updates, patch vulnerabilities, use firewalls/virus protection, etc.
- Protect your employees – create a secure password policy, use multi-factor authentication.
- Learn to spot attacks – raise awareness among your staff, train your people, and regularly test their knowledge.
- Learn how to recover – create a recovery plan, ensure that the back-up works, and do test recoveries.
- Protect your brand – be aware of threats, protect (social media) accounts, email server security protocols, etc.