White Paper | The Top Cyber Attacks Targeting Small Businesses

White Paper | The Top Cyber Attacks Targeting Small Businesses

This white paper explores the growing cyber threats targeting small and medium-sized businesses (SMBs), including phishing, ransomware, and IoT-related attacks. It offers valuable insights and practical cybersecurity measures to help SMB owners protect their businesses from evolving threats. Download the white paper to fortify your defense against cyberattacks.

White Paper | The Top Cyber Attacks Targeting Small Businesses

THE TOP CYBER ATTACKS TARGETING SMALL BUSINESSES

Y O U D E S E R V E T H E B E S T S E C U R I T Y

Quantum SparkTM

Cyber Threats Are On The Rise As more large businesses and corporations

invest heavily in cybersecurity tools, hackers are

increasingly targeting small and medium-sized

businesses (SMBs), FBI Supervisory Special Agent

Michael Sohn said at CNBC’s Small Business

Playbook event. In 2021, the FBI’s Internet

Crime Complaint Center received nearly 850,000

complaints regarding cyberattacks and malicious

cyber activity with nearly $7 billion in losses; up 64%

from the previous year. What's frightening, is that a

majority of these attacks were targeted at SMBs.

64% increase in

cyberattack losses year over year

$7B in potential losses from cyberattacks

What It Means to an SMB Owner As SMBs have modified their business model to consume more cloud services and web-based tools, attackers have adapted to skim what value they can from their targets. SMB organizations are still a good target for cybercriminals.

There is sufficiently valuable information to make it worth an attacker’s time and the organization’s protection level is typically weaker than that of a larger enterprise. Stolen credentials is the data compromised most and threat actors mainly achieve this using phishing techniques.

In this paper we discuss the top cyber security concerns small business owners face; phishing, password loss, malware, ransomware, supply chain an IoT-related attacks, and cybersecurity measures to prevent these types of attacks.

2THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

3THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

Anatomy of a Phish Put simply, phishing is a deliberate attempt to obtain sensitive information like login credentials or credit card numbers by masquerading as someone trustworthy. Phishing, and malware, will continue to be a massive threat for SMBs. In the first half of 2022 alone, there were over 2.8B malware attacks globally and over 236M ransomware attacks. And for phishing attacks, 255M have been reported since the end of October 2022. Phishing attacks may come in the form of an email that links to a malicious website or has a malicious attachment. Other avenues include‘vishing’ (voice phishing) and ‘smishing’ (SMS Phishing).

Some attempts, “spear phishing”, are targeted and some are not, “bulk phishing.” Spear phishing targets an individual or an organization and may be difficult to detect by appearing to be from a trusted source and having some knowledge familiar to the target. By contrast, bulk phishing casts a wider net, attempting to capture as many pieces of information from different individuals as possible.

In 2021, a large amount of organizations experienced at least one successful email-based phishing attack than the previous year. A close relative of the phish is the highly targeted attack called a business email compromise (BEC), a scam that can cost companies millions of dollars. This type of attack involves the phisher compromising the account of a high-level executive within a company and instructing their employees to transfer money to an account controlled by the attacker. Even Facebook and Google have taken the bait. See The Top 5 Phishing Scams of All Time.

https://www.techrepublic.com/article/top-cybersecurity-threats/ https://www.techrepublic.com/article/top-cybersecurity-threats/ https://www.cnbc.com/2023/01/07/phishing-attacks-are-increasing-and-getting-more-sophisticated.html#:~:text=An%20October%202022%20study%20by,more%20than%20255%20million%20attacks https://www.cnbc.com/2023/01/07/phishing-attacks-are-increasing-and-getting-more-sophisticated.html#:~:text=An%20October%202022%20study%20by,more%20than%20255%20million%20attacks https://www.checkpoint.com/cyber-hub/threat-prevention/what-is-phishing/the-top-5-phishing-scams-of-all-times/

4THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

Who Has Your Password? Having someone’s password is akin to having the keys to their car. Like a car theft, with someone’s network password, it is easy to log into systems as that person and move around the network, infecting other systems, elevating their privilege, installing other tools as desired and gathering data as they go. Threat actors can essentially impersonate that user.

If only one factor like username and password is needed to login, then they have what they need. There’s no need to find a sophisticated zero-day Remote Code Execution bug and a vulnerable system to exploit. This is likely why phishing attacks top the list of attack techniques.

Does Everyone Have Your Password? Often overlooked, some Internet of Things (IoT) devices like smart cameras and routers come with default usernames and passwords which can easily be found on the Internet. If the vendor doesn’t require this be changed when set up, then everyone may have your password. Default and hard coded passwords have been used in botnet campaigns like Mirai and its variants to control hundreds of thousands of IoT devices without their owner’s knowledge. Change those default passwords using strong passwords that are hard to guess using brute force techniques.

https://datarecovery.com/rd/default-passwords/ https://www.beyondtrust.com/resources/glossary/hardcoded-embedded-passwords#:~:text=Hardcoded%20passwords%20are%20particularly%20dangerous,)%2C%20systems%2C%20and%20software.&text=Hardcoding%20presents%20a%20risk%20for,%2C%20firmware%2C%20application%2C%20etc. https://www.beyondtrust.com/resources/glossary/hardcoded-embedded-passwords#:~:text=Hardcoded%20passwords%20are%20particularly%20dangerous,)%2C%20systems%2C%20and%20software.&text=Hardcoding%20presents%20a%20risk%20for,%2C%20firmware%2C%20application%2C%20etc. https://support.google.com/accounts/answer/32040?hl=en

5THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

Held Ransom This leads us to ransomware. 85% of Managed Service Providers (MSP) report that ransomware is their biggest threat to SMBs. As we've mentioned above, the amount of reported ransomware attacks continues to grow drastically – over 623M ransomware attacks globally!

Unfortunately if a small business relies on their computers, and many do for order entry, then a ransomware infection is a show stopper. At a minimum, there is the threat of losing access to any work or personal files that are not backed up. How does a ransomware infection happen?

Step 1: Gain Access – We’ve seen a few ways this happens. Another notable method is to target vulnerable systems with known exploits.

Consumer-grade equipment like routers and IoT devices have vulnerabilities that are well-known so it’s best to do your research before purchasing and installing these. Look for vendors without vulnerabilities and for those who do, see how quickly they patched the device. Unfortunately in some cases where a patch wasn’t supplied, the recommended solution is to throw away the device.

Step 2: Data Encryption – After a threat actor has gained access to a system, they can begin encrypting. Since encryption functionality is built into an operating system, this simply involves accessing files, encrypting them with an attacker-controlled key, and replacing the originals with the encrypted versions. Some ransomware will also take steps to delete backup and shadow copies of files to make recovery without the decryption key more difficult.

Step 3: Ransom Demand – Different ransomware variants issue ransom demands in different ways, but it is not uncommon to have a display background changed to a ransom note or text files placed in each encrypted directory containing the ransom note. Typically, these notes demand a set amount of cryptocurrency in exchange for access to the victim’s files. If the ransom is paid, the ransomware operator will either provide a copy of the private key used to protect the symmetric encryption key or a copy of the symmetric encryption key itself. This information can be entered into a decryption program (also provided by the cybercriminal) that can use it to reverse the encryption and restore access to the user’s files, hopefully.

While these three core steps exist in all ransomware variants, different ransomware can include different implementations or additional steps. For example, ransomware variants like Maze perform files scanning, registry information, and data theft before data encryption, and the WannaCry ransomware scans for other vulnerable devices to infect and encrypt.

https://www.infosecurity-magazine.com/news/over-620-million-ransomware/

6THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

Getting In Through The Supply Chain As an SMB, you should actively invest in strategies and tools that can prevent supply chain attacks. This type of attack is increasing in frequency as attackers have the ability compromise a large amount of sensitive data from multiple organizations by just targeting a single vendor. You can think of it as a fisherman using an extremely wide net to catch fish, versus a fisherman using a single fishing pole to catch one fish.

Traditionally the focus of security has primarily been on ensuring the perimeter, on-prem systems, and other network connected products are secure. And historically, this has been enough. But we live in a day in age where technology advances every day, and consequently, so does cyber crime. It has been estimated that supply chain attacks grew by more than 300% from 2020 to 2021.

Supply chain attacks occur when an attacker attempts to infiltrate an organization through vulnerabilities in the services or programs the organization uses from a third-party. This can include project management tools, financial institutions/programs, and more. An example of a well-covered supply chain attack was when hackers used ExPetr (aka NotPetya) to exploit the automated update system of accounting software called M.E.Doc. This delivered a ransomware attack to all customers, causing millions in losses for both large enterprises and SMBs.

IoT Attacks On The Rise A growing number of cyber criminals are also targeting Internet connected IoT devices at branch offices and remote locations which are often far less secure and more vulnerable than the company headquarters. Any lack of visibility into network-connected devices at an organization’s main location is often compounded by a factor of N for every additional remote branch office. Not only are the remote locations not staffed by the same IT or security experts at headquarters, but they are also maintained and operated by different employees and third-party vendors.

Before any IoT devices (e.g., printers, cameras and other Smart systems) at these remote offices can be secured, they must first be identified and assessed for risk. Furthermore, significant efforts and resources are then needed to build effective security policies that can protect against the risk these IoT devices create across the various branch locations. This requires allowing normal operational connections for managing, monitoring, and updating the devices while preventing other connections to or from the devices.

Geographically distributed organizations also are in need of an IoT security solution that can automate the discovery and visibility of any connected IoT device; having the ability to automatically apply immediate protection for the device and network.

7THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

Prevention Is Key Small businesses need enterprise level protection without the complexity, cost and expertise. This means they need security that consolidates the functions to achieve a high level of protection, security that doesn’t require a large staff or deep expertise and security that just works, right out of the box. But how does that work?

Above all else preventing the next cyberattack is key. Solutions that detect an infection has occurred are helpful, but they’re a bit like hearing “Fire” in a crowded movie theater. When you see or hear the alert, then you know you have to take action, i.e. move quickly to the nearest exit or disconnect the infected system from the network. An alert that the fire is out or the attack was prevented means you can continue doing what you were doing.

Securing The Network Check Point security gateways are enterprise-grade, meaning they’ve been tested, approved and deployed by thousands of enterprises worldwide. The Check Point Quantum Spark™ Series security gateways are an all-in-one solution for securing small to medium size businesses.

Protection from every threat

Easy to deploy and manage

“All-in-One” solution

https://www.checkpoint.com/products/small-business-security/

8THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

Quantum Spark Highlights • Easy setup – Plug it in, follow a simple set-up wizard and your network is secure

• Out of the box protection – security policies are included that deliver protection immediately, and adjustments can be made to tailor policies for your business.

• Low price – The Quantum Spark family delivers protection with a modest investment. Check Point Quantum Spark security gateways could also be offered by your local Internet service provider as a monthly subscription. Asked for your service provider for Check Point.

• Easy management – Ongoing management and upkeep is simple with a mobile app to monitor and mitigate any security issues while on the go.

• Network and security package in one – Models are available with the latest and greatest internet connectivity options, including 5G Cellular, Wi-Fi 6, and more. These gateways can support multiple internet service providers and monitor them for quality of service, so you can get the best bandwidth for each application.

Enterprise Capabilities in a Small Package The security functions of the Quantum Spark Next Generation Firewall family enable you to control who accesses your network, prevents attacks and threats, and secures communications with your business from remote employees or additional business locations. Having the tools is important. Knowing how to use them simply and effectively is critical.

Just like enterprises, small businesses need to ensure that only authorized traffic and users are allowed to access the network. They must also ensure that only appropriate websites are accessed by users. Policies span various capabilities that are used to protect the network.

• Next-Gen Firewall – Ensures only the traffic that should be allowed on the network traverses the network. Prohibited traffic is blocked before it ever enters the network.

• Application Control and URL Filtering – these capabilities work together to ensure that only allowed applications are used on the network and that only allowed websites can be visited.

https://www.checkpoint.com/products/next-generation-firewall/ http://www.checkpoint.com/products/application-control-software-blade/

9THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

• User Awareness – Allows an organization to have polices in place that will allow or prohibit what specific people can do, based on their identity or role in the business.

• QoS – Quality of Service allows you to give priority to your most important traffic.

Prevent Attacks and Threats Large enterprises use high levels of protection to defend the business from threats. Small businesses now can leverage these threat prevention technologies to defend their business.

• IPS – Intrusion Prevention Systems search traffic for attacks targeting business co mputers and devices. Computers and devices that do not have the latest patches are protected by the IPS.

• Anti-Virus – Malware such as viruses and worms are prevalent and can cause major damage. Anti- Virus blocks malware before it can get into the network.

• Anti-Spam – unwanted email is an issue for any business. Anti-Spam blocks SPAM email messages that can also often deliver malware or lead users to malicious sites.

• Anti-Bot – Bots collect information to send to their command and control center for further malicious activity. Anti-Bot will detect and block that communication.

• Sandboxing – prevents infections from undiscovered exploits, zero-day and targeted attacks by launching suspicious files in a virtual sandbox, discovering malicious behavior and then preventing malware from entering the network.

Protect Business Data When computers communicate with other computers or remote users, the information can be captured by attackers if it is not encrypted. Virtual Private Networks (VPN) encrypts data traversing the network, allowing only the intended receivers to read the information.

• Remote Access – Encrypts traffic from PC’s and user devices to the network, whether they are in the office or on the road.

• Site-to-Site VPN – If a business has multiple offices, this VPN encrypts all communications between multiple office locations.

https://www.checkpoint.com/products/identity-awareness-software-blade/index.html http://www.checkpoint.com/products/ips-software-blade/ http://www.checkpoint.com/products/antivirus-software-blade/ http://www.checkpoint.com/products/anti-spam-email-security-software-blade/

10THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

Cloud Managed Option Outsourced security services are one of the fastest growing segments in the security market. Check Point cloud security management introduces a central management and service provisioning platform that answers the needs of a Managed Security Provider (MSP) offering protections for SMBs and vertical markets. It features an intuitive web-based user interface and uses robust architecture to support the management of thousands of Check Point 1500, 1600, and 1800 Appliances.

Web Browser and Mobile App for Management On-the-Go SMBs have a variety of easy to use choices for managing Quantum Spark security gateways including a web portal and mobile app. Check Point’s WatchTower iOS and Android mobile application enables staff to monitor their security status and quickly mitigate any threats directly from the mobile device.

Securing the Endpoint If you don’t have a backup plan in place to help you restore systems from a ransomware attack, then consider Check Point's Harmony Endpoint security solution.

Ransomware Protection When an anomaly or malicious behavior is detected, our endpoint security blocks and remediates the full attack chain without leaving malicious traces. Harmony Endpoint uses a unique vaulted space locally on the machine that is only accessible to Check Point signed processes – in case the malware attempts to perform a shadow copy deletion, the machine will not lose any data.

11THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

Phishing Protection Prevent credential theft with Zero-Phishing® technology that identifies and blocks the use of phishing sites in real-time. Sites are inspected and if found malicious, the user is blocked from entering credentials. Zero-phishing® even protects against previously unknown phishing sites and corporate credential re-use.

Securing Mobile Devices Harmony Mobile is the market-leading Mobile Threat Defense solution. It keeps your business data safe by securing employees’ mobile devices across all attack vectors: apps, network and Operating System. Deployment is easy and it protects devices without impacting user experience or privacy.

Securing Cloud Applications Harmony Email & Collaboration is a prevent-first security solution for the protection of cloud email and office applications such as Office 365 and G Suite, Teams, OneDrive, and SharePoint. Connecting to cloud application using native APIs it is invisible to attackers and does not require any network changes.

Once deployed, Harmony Email & Collaboration scans cloud mailboxes and applications for exiting threats. When a user receives an email, file, or message through an Office 365 or G Suite application, it examines the email for malicious content, and determines if it needs to be quarantined, cleaned, removed, etc. APIs analyze data in transit and at rest to make sure no malicious content penetrates or propagates within the organization, all from a single, user-friendly management platform and a single license for email, office, and enterprise applications.

Business Email Compromise (BEC) Protection The solution inspects the communication’s metadata, attachments, links and language, as well as all historical communications, in order to determine prior trust relations between the sender and receiver, increasing the likelihood of identifying user impersonation or fraudulent messages.

Prevent Account Takeover Prevent unauthorized users and compromised devices from accessing your cloud email or productivity suite applications. Transparent to users, Harmony Email & Collaboration provides additional data into the identity provider’s authentication process, so suspicious logins (e.g.: seen in two different locations, bad IP reputation) are immediately denied and blocked.

12THE TOP CYBER ATTACKSTARGETING SMALL BUSINESSES

Help Is Available Nearly two-thirds of small to medium businesses say they lack the in-house skills to deal with cyber- security issues – so it’s no surprise that SMBs are urgently looking for solutions to prevent cyber- threats from damaging their business.

Help is available from Managed Security Providers (MSP) who sell security services specifically designed for the growing SMB market. To put the size of that opportunity in perspective, it’s forecast that SMBs’ spend on security worldwide will almost double between now and 2024 (from around $50 billion currently). And a 2020 survey found that SMBs are willing to pay 25% more to a MSP offering security services, and 91% of SMBs would consider moving to a new IT service provider if it offered the right security solutions.

Why Check Point? The Fortune 100 relies on Check Point for security. Other providers don’t bring the level of expertise and experience delivering high levels of protection. Only Check Point delivers enterprise-grade security in a compact, easy to manage package, designed to meet the needs of a small business.

What Are You Waiting For? Security for a small business is too important to ignore. With Check Point, small businesses can feel confident that they have the best security available, in a package that doesn’t require extensive expertise or time to get high levels of protection.

Contact a Check Point Authorized Reseller today to get started with enterprise-level security that protects the small business.

Visit https://www.checkpoint.com/products/small-business-security for more information.

https://www.checkpoint.com/products/small-business-security


Item Type: pdf