Many businesses in the United States have been putting resources—including people, technology, and budgets—into protecting themselves from information security and cybersecurity threats. As a result, they have become a more difficult target for malicious attacks from hackers and cyber criminals. Consequently, hackers and cyber criminals are now successfully focusing more of their unwanted attention on less secure businesses. As the use of Internet and networked computers grows, and new technologies such as cloud computing enable even greater technological advances, the occurrence of cybercrime is expected to grow as cybercriminals seek to exploit online and networked vulnerabilities in business networks. “Fifty percent of small to medium-sized businesses have been the victims of cyber attack and over 60% of those attacked go out of business. Despite the rise in cybercrime among small businesses, many small businesses remain susceptible to cyber attacks due to lack of resources and surprisingly, a lack of knowledge of the threat. The NSBA found that despite the increasing threats posed by cyberattacks, The activity of identifying what information requires what level of protection, and then implementing and monitoring that protection, is called “risk management” This process will likely require the input and collaboration of a broad array of personnel within the business to be successful. You should bring together those personnel in your business that
can help make informed decisions, for example project managers, executives, legal, and IT personnel. You should review and update your risk management plan at least annually and whenever you may be considering any changes to the business. It is clear that small businesses need
to be better informed on the impact cyberattacks can have on their businesses and be better prepared to meet the increasing cyberthreat.