How Can SMBs Reduce MSP and Cybersecurity Risks?

565 views
•
January 21, 2022
by
RSAC Cybersecurity
YouTube video player
How Can SMBs Reduce MSP and Cybersecurity Risks?

TL;DR

Small and midsized businesses should reduce security complexity, improve visibility, and verify that threats are fully remediated instead of assuming they are too small to attract attackers. Because criminals automate campaigns and may exploit trusted MSP relationships, SMBs need correctly configured protection, appropriate expertise, and careful oversight of every dependency that can access their systems or data.

Transcript

Good morning, good afternoon, or good evening from my side. So my name is Candid Wuest. I'm the vice president of cyber protection research at Acronis, and I'm delighted to talk about the risks and all those kind of other things that you as a small, mid-sized business should actually think of. 'Cause yeah, there's a lot of trust in the, um, in ther... Read More

Key Insights

  • Small businesses are active cyberattack targets, even when they cannot pay large ransoms or do not store customer credit card details. Attackers pursue organizations of every size, so the absence of prominent news coverage does not indicate that an SMB has avoided attack attempts.
  • Limited security visibility can create false confidence about whether attacks occurred. Twenty percent of surveyed companies said they had not been targeted, while 14.2 percent did not know whether they received phishing emails, raising questions about their ability to recognize credential theft and other compromises.
  • Cyberattacks are increasingly automated, allowing criminals to target many organizations efficiently. The transcript cites approximately 350,000 new malware samples detected each day by AV-Test and says attackers use automation, machine learning, and artificial intelligence to generate malware and personalized phishing campaigns.
  • Security expertise is scarce among small and midsized businesses. A cited ConnectWise survey found that only 57 percent of SMBs had security personnel on staff, leaving many organizations poorly equipped to manage increasingly complex infrastructure, cloud services, threat detection, and incident response.
  • Cloud adoption increases operational flexibility but also introduces complexity and visibility challenges. The presentation reports that 78 percent of companies struggle to obtain a common view across their infrastructure, making it harder to understand who accesses cloud data and what actions occur across separate systems.
  • Incomplete remediation allows security incidents to recur after the immediate damage is contained. The presentation says 55 percent of companies do not remediate threats correctly, potentially leaving systems unpatched or passwords unchanged even after ransomware, unauthorized access, or data leakage has been discovered.
  • Too many overlapping security products can increase cost and configuration risk. About 21 percent of surveyed organizations used more than ten security solutions simultaneously, including 7.2 percent using more than fifteen, creating complexity that can contribute to mistakes and weaken overall resilience.
  • Trusted MSP relationships can become supply-chain risks for SMB customers. The description states that criminals increasingly target MSPs because economies of scale and pre-installed automation tools can provide access to multiple customers, making oversight of trusted dependencies an important part of SMB security planning.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why do cybercriminals target small and midsized businesses?

Cybercriminals target small and midsized businesses because automated attacks can be launched efficiently against organizations of every size. An SMB does not need to hold customer credit card data or possess enough money for a multimillion-dollar ransom to become a target. The presentation warns that many smaller companies have probably already faced attacks, even if they lacked the visibility needed to recognize them.

Q: How can an SMB tell whether it lacks security visibility?

An SMB may lack visibility if it cannot say whether phishing messages reached employees, whether unauthorized users accessed cloud data, or how often its systems were targeted. In the cited survey, 14.2 percent did not know whether they received phishing emails, and 20 percent said they had never been targeted. The presenter suggests that some of these organizations may simply have failed to detect attempted attacks.

Q: How frequently are SMBs experiencing cyberattacks and phishing?

The cited survey found that 21 percent of companies noticed at least one attack per day, while 9.3 percent noticed at least one attack per hour. For phishing, about one-third reported receiving one to five phishing messages per month, and approximately 20 percent reported more than twenty. Some messages may also be filtered by services before administrators or employees see them.

Q: Why is automation important in modern cyberattacks?

Automation allows attackers to produce and distribute threats at a scale that would be impractical through manual work. The presentation cites approximately 350,000 new malware samples detected every day by AV-Test. It also says criminals use machine learning and artificial intelligence to generate attacks and personalize phishing messages with information from data leaks, increasing pressure on businesses that lack comparable defensive capabilities.

Q: What cybersecurity staffing challenges do SMBs face?

SMBs often struggle to hire and retain people with the expertise required to protect their infrastructure. The presentation cites a survey showing that only 57 percent of small and midsized companies have security personnel on staff. Smaller organizations may also be unable to match the salaries offered by large global companies, even as cloud adoption and evolving threats create additional requirements for specialized knowledge.

Q: Why does using many security tools create risk for SMBs?

Using many tools can produce overlapping functions, unnecessary costs, fragmented visibility, and configuration mistakes. About 21 percent of surveyed organizations used more than ten security solutions in parallel, while 7.2 percent used more than fifteen. The presenter argues that reducing complexity improves resilience because staff have fewer products to configure, monitor, and coordinate, especially when internal security expertise is limited.

Q: How should an SMB respond after detecting a security incident?

An SMB should go beyond stopping the immediate damage and address the underlying conditions that enabled the incident. The presentation says 55 percent of companies do not remediate threats correctly. Proper follow-through can include patching affected systems and changing passwords that attackers may have obtained. Without those actions, ransomware, data leakage, or another compromise may recur weeks later.

Q: Why are managed service providers a cybersecurity risk for SMBs?

Managed service providers can become attractive targets because they occupy trusted positions within their customers' supply chains. According to the description, economies of scale and numerous pre-installed automation tools make MSPs appealing to attackers seeking access to SMB customers. A compromise of that trusted dependency can therefore expose multiple organizations, so SMBs should consider provider-related access and risk within their security planning.

Summary & Key Takeaways

  • Small and midsized businesses are targets even when they lack valuable payment data or cannot afford multimillion-dollar ransoms. Automated campaigns let criminals attack organizations at scale. Survey respondents frequently reported daily attacks and recurring phishing, while some businesses reported no incidents or did not know whether phishing had reached them, suggesting limited visibility.

  • Limited staffing and increasingly complex infrastructure weaken SMB defenses. Only 57 percent of surveyed SMBs had security personnel, while cloud adoption created new expertise and monitoring requirements. Seventy-eight percent struggled to establish a common view across infrastructure, and 55 percent did not remediate threats correctly, allowing unresolved weaknesses or compromised credentials to remain.

  • Security tools alone do not guarantee protection. Twenty-three percent of surveyed small businesses used no endpoint security, while some relied on free or consumer-grade products. Other organizations created excessive complexity by running numerous overlapping solutions. SMBs should simplify their security environments, configure protections correctly, and scrutinize MSPs and other trusted dependencies that attackers may exploit.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚