What Should You Do If Your Business Is Hit By A Cyber Attack?

Cyber-attacks aren’t letting up, with corporate giants such as Facebook, British Airways and Marriott International all hitting the headlines in the last 12 months. Yet, despite publicity around these high-profile cases, for small businesses, it’s still tempting to think that cyber-attacks aren’t something that you really need to worry about.

Unfortunately, this couldn’t be further from the truth, with research showing that 42% of small businesses were hit by a cyber-attack in the last 12 months.

Smaller Businesses Soft Target for Hackers
By their very nature, small business owners are constantly spinning plates, so it’s no wonder that preparing for cyber incidents isn’t top of the to-do list. Yet, hackers have become wise to this, often seeing SMEs as a soft target, without the funds, time or knowledge to defend themselves.

Research shows that the majority of small businesses still aren’t taking the threat seriously. More than a third (37%) don’t have a cybersecurity plan in place and 40% per cent wouldn’t know who to contact if a crime was committed. With the average annual cost of a cyber breach standing at around £25,700, it is time to sit up and take notice.

Even if you have all the right technology and processes in place, sometimes you’re powerless to stop a breach. This is why an effective response plan is essential, enabling you to control the situation as quickly as possible, with minimum impact to you and your customers.

How to respond to a Cyber Attack
Want to make sure you’re prepared? Then, your cyber-attack response plan should include the following:

Arm Yourself with Knowledge
Speed is of the essence following a cyber-attack. You need to know what caused the breach, with a view to rectifying the problem quickly and ensuring it doesn’t happen again. As a small business, chances are you don’t have this expertise in house, so you should line up IT forensics experts for if and when you need them.

Your Legal Response
There are numerous legal issues to consider, particularly since the introduction of the GDPR last year. These include informing the Information Commissioner’s Office (ICO) of the breach, defending your business against any claims of malpractice, as well as managing your approach to customers and the media. For this, you’ll need a good lawyer, ready to support you from the moment you’re aware of the problem.

Handling Media queries
You could be the focus of media attention following a breach, so be ready to handle all external communications about what happened and how you’re responding. Again, time is of the essence, so you’ll need to have statements ready to go asap. If you don’t have your own PR expertise internally, make sure you have external support – whether an agency or experienced consultant, on speed-dial.

Informing Customers
Depending on your customer-base and the scale of the breach, you could have a lot of unpleasant phone calls to make! You’ll need to be ready with a way to handle this communication efficiently across numerous channels, including at least email and telephone. As a small business, this communication should be as personal as possible, but your lawyer will be able to advise on what you should and shouldn’t be saying.

Make Sure You’re Covered
If the worst does happen and you’re facing the repercussions, your final line of defence is a watertight and specialist cyber insurance policy. Bear in mind that policies can vary significantly, so be sure to seek specialist advice regarding the best option for your needs and how these might change over time. Some insurance policies will also offer an immediate response plan and external expertise as part of your cover, giving you one less thing to worry about. 

Finally, it is worth highlighting that the GDPR imposes the same responsibility on all businesses that handle personal data, irrespective of size. The potential impacts of a breach are great, with fines as much as €20m. So make sure you’re on top of cyber security, before it’s too late.

Training Your Employees and Yourself
Last, but certainly not least, you should first train your staff and management about Cyber protection and comprehension of cyber security. 
This can be done at low cost by taking focused on-line cyber security lessons for a few minutes every day for a few weeks and keeping everyone up to speed every few months by a few daily lessons on cyber security protection. 
The results reduce your cyber security risks significantly. 

Contact us at Cyber Security Intelligence for more information.

ByteStart:

You Might Also Read:

How To Develop Secure Cybersecurity Practices:


 

 

« Over 90% Of Security Pros Fear Insider Threats
Combining AI’s Power With Self-Centered Human Nature Could Be Dangerous »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Veridify Security

Veridify Security

Veridify Security (formerly SecureRF), develops and licenses quantum-resistant, public-key security tools for the low-resource processors powering the Internet of Things.

Software Engineering Institute (SEI)

Software Engineering Institute (SEI)

At the CERT Division of SEI we study and solve cybersecurity problems, research security vulnerabilities in software, and develop information and training to help improve cybersecurity.

NLnet Labs

NLnet Labs

NLnet Labs is a not-for-profit foundation with a long heritage in research and development, Internet architecture and governance, as well as security in the area of DNS and inter-domain routing.

Eskive

Eskive

Eskive is a Brazilian cyber security awareness and education platform that empowers users and strengthens their company in the face of cyber threats.

NinjaJobs

NinjaJobs

NinjaJobs is a community-run job platform developed by information security professionals. We focusing strictly on cybersecurity positions.

Level39 (L39)

Level39 (L39)

Level39 is the world's most connected tech community, with over 200 tech startups and scaleups based onsite.

Founder Shield

Founder Shield

Founder Shield is a data driven insurance brokerage focused excusively on rapidly evolving high-growth companies.

HancomWITH

HancomWITH

Hancomwith is an information security company. We provide optimized blockchain solutions in areas including next-generation authentication, security and digital asset transaction.

Partners in Regulatory Compliance (PIRC)

Partners in Regulatory Compliance (PIRC)

Partners in Regulatory Compliance provides an array of cybersecurity services including cybersecurity policy management, risk assessments and regulatory compliance consulting.

3Lines Venture Capital

3Lines Venture Capital

3Lines Venture Capital invests in exceptional founders and startups working on broad disruptive themes of Future of Work, AI enabled enterprises, and Industry 4.0.

E2E Technologies

E2E Technologies

E2E Technologies are a proactive, SLA-beating, managed service provider that busts the common stereotypes surrounding IT.

West Midlands Cyber Resilience Centre (WMCRC)

West Midlands Cyber Resilience Centre (WMCRC)

The East Midlands Cyber Resilience Centre supports and helps protect SMEs and supply chain businesses and third sector organisations in the region against cyber crime.

Information Systems Security Association (ISSA)

Information Systems Security Association (ISSA)

ISSA is the community of choice for international cybersecurity professionals dedicated to advancing individual growth, managing technology risk and protecting critical information and infrastructure.

Helix Security Services

Helix Security Services

Helix Security provides IT & information security consultancy to government and businesses across New Zealand.

HWG

HWG

HWG is a company specialized in providing cyber security solutions and consulting services.

Mediatech

Mediatech

Mediatech, specialized in managed Cybersecurity and Cloud services, a single point of contact for your company's IT and infrastructure.