PHOTO
From 2020 being dubbed ‘the year of the side hustle’ to small businesses grappling to maintain continuity and profitability, despite these unprecedented times there has been a significant uprising in entrepreneurial activity the world over. Startups tend to be created by people who burn with an idea and want to put it into action as soon as possible. Money is usually tight, and expenses run high, what with product development, promotion, and all the rest of it. When managing priorities, emerging businesspeople often neglect matters related to information security.
Many startups try to save on security, confident that a small company with limited resources holds no interest for cybercriminals. The truth is, anyone can fall victim to cybercrime. Firstly, because many cyber threats are massive in scale, their originators aim wide, trying to hit as many as they can in the hopes that at least some will generate a return. Secondly, commonly being weakly protected startups present attractive targets for cybercriminals. Whereas corporations sometimes spend months to recover from a cyberattack, a small company may simply not survive one. To properly safeguard your startup, given a limited budget, you might want to build a threat model before you go ahead with the launch — to figure out which risks are relevant for your business. Kaspersky helps startups by covering the typical mistakes of many first-time entrepreneurs.
Weak protection of cloud resources
Many startups rely on public cloud services, such as Amazon AWS or Google Cloud, but not all of them use proper security settings for such storage spaces. In many cases, containers with client data or Web app code end up protected by nothing but weak passwords — and internal corporate documents can be accessed with direct links and are visible to search engines. As a result, anyone can get hold of critical data. Sometimes, in their quest to keep things simple, startups leave important documents available to anyone in Google Docs for good — simply because they forget to restrict access to them.
Poor employee awareness
People are often the weak link in any given business. Attackers know it full well and use social engineering tricks to penetrate the corporate network or fish out confidential information.
Poor awareness is doubly dangerous for companies employing freelancers, as it may prove quite a challenge to control what devices and what networks they use for work. Therefore, it is very important to motivate and steer all workers toward a security-focused attitude.
To avoid exposing yourselves to cybercriminals and stay in business, give proper consideration to cybersecurity when mapping out your business plan:
- Figure out which resources need protection first and what security tools you can afford at the earliest stages. In fact, many safeguards will not involve much expense.
- Use robust passwords to protect your work devices and accounts. Our Kaspersky Small Office Security solution includes the Kaspersky Password Manager utility built to generate robust passwords and store them inside encrypted containers. Do not neglect two-factor authentication — you will find it almost everywhere these days, and it really works.
- Thoroughly review the data-storage laws of the countries in which you plan to operate, and make sure your company’s personal information storage and processing workflow is compatible with those laws. If possible, consult lawyers about the traps and pitfalls of each market in question.
- Keep a close eye on the security of third-party services and software. How well-protected is the collaborative development system you use? Is your hosting provider safe? Are there any known vulnerabilities in the open-source libraries you use? These questions should interest you at least as much as the consumer properties of the end product.
- Raise your employees’ cybersecurity awareness and encourage them to dig into the subject on their own. If your company has no cybersecurity professionals on board (typical for a startup), find someone with at least some interest in the matter who can start by following our blog.
- Do not forget about computer infrastructure protection. Kaspersky have a solution for budding companies with limited budgets. It will help automate security oversight over your workstations and servers and make secure payments online. No administration skills are required.
About Kaspersky
Kaspersky is a global cybersecurity company founded in 1997. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky technologies and we help 250,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.
For further information, please contact:
Sweta Fernandes, Account Executive, Golin, KasperskyTeam@golin.ae
© Press Release 2021
Disclaimer: The contents of this press release was provided from an external third party provider. This website is not responsible for, and does not control, such external content. This content is provided on an “as is” and “as available” basis and has not been edited in any way. Neither this website nor our affiliates guarantee the accuracy of or endorse the views or opinions expressed in this press release.
The press release is provided for informational purposes only. The content does not provide tax, legal or investment advice or opinion regarding the suitability, value or profitability of any particular security, portfolio or investment strategy. Neither this website nor our affiliates shall be liable for any errors or inaccuracies in the content, or for any actions taken by you in reliance thereon. You expressly agree that your use of the information within this article is at your sole risk.
To the fullest extent permitted by applicable law, this website, its parent company, its subsidiaries, its affiliates and the respective shareholders, directors, officers, employees, agents, advertisers, content providers and licensors will not be liable (jointly or severally) to you for any direct, indirect, consequential, special, incidental, punitive or exemplary damages, including without limitation, lost profits, lost savings and lost revenues, whether in negligence, tort, contract or any other theory of liability, even if the parties have been advised of the possibility or could have foreseen any such damages.