Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!

The Small and Medium Business’ False Sense of Cybersecurity

By Brian Berger
smb-cyber
October 5, 2017

I have been meeting with many small and medium business owners over the past few weeks and months discussing cybersecurity, and have noticed a few common themes or objections in their responses. The first objection to a proper cybersecurity program is typically the cost – most small and medium organizations have not budgeted for or considered cyber as part of their business continuity plan. Yes, it will cost some money to start and to remediate the cyber gaps in an organization, but these costs are lower than the average cost of one cyber incident.

A second common response to cyber incidents is, “It has not happened to me, and we are not even a target.” As a security professional, this one compels me to want to help even more. The small and medium business market is unprepared and woefully understaffed for proper cybersecurity measures.

The fact that a cyber incident can cost an organization more than $200,000 on average should be enough to compel immediate action, but this is not the case. There is either a misunderstanding about the magnitude of impact on the budget, the impact on ongoing operations or the plausibility that every business is a target. I can say with certainty that the business owners who I have met who have realized that it’s time to act are the ones who have had a cyber event in their business. They are the lucky ones whose businesses have survived the event, while the ones who have been attacked who I have not met may be among the 60% of businesses who do not survive a cyberattack. 

As a call to action for our hundreds of thousands of small and medium businesses who have not proactively started to address cyber preparedness, please do! Your livelihood, your employees’ jobs and the services you provide to our economy depend on your diligence addressing cybersecurity. Cybersecurity is a well-prepared journey, and it’s not a single product purchase, but rather a combination of knowledge, facts, awareness, training, planning, implementation and preparedness. 

There are a lot of discussions about assessments and assessors. Assessments are needed and are the first step in the process; however, they come in all shapes, sizes and costs. Additionally, they identify a point-in-time context using the provider’s assessment technique. Is the technique a question and answer process, a test and verify process or a combination using both tools and technology?  This is an area to really ask questions of your assessment provider. At the end of the process, a high-quality set of deliverables that identify your cyber posture from a physical, logical and digital perspective with actionable insights is critical for the business. Since cyber posture is fluid, due to networking, social engineering, insider threats, outsider threats and platform integrity, a plan for real-time situational awareness would be a valuable part of the assessment as part of cyber risk management.

Here are a few suggested deliverables for a high quality cyber assessment:

  • Measured cyber posture: physical, logical and digital.
    • Understand your cyber posture from the time someone enters the building until data transmits to and from digital assets.
  • Identified cyber gaps with clearly defined steps to remediate.
    • During the assessment process, a clearly defined set of organizational “cyber” gaps should be documented.  In addition to identification of gaps a clear set of steps necessary to “remediate” the gaps need to be put into a step by step plan.
  • Ranked vulnerabilities by criticality.
    • Organizational vulnerabilities are typically digital assets and their posture.  Within the asset analysis a set of criteria should be examined to rank the asset vulnerabilities in a minimum of four categories: Critical, High, Medium and Low.
  • Plan of action, improvement plan, policies and training materials.
    • The plan of action should be a prescriptive document that identifies, Gaps and Vulnerabilities in a actionable plan.  Issues need to be identified with both the risk level and solution to bring each item into a proper cyber posture.  In addition to the plan of action, the availability of policies and internal training materials for the company are critical to maintaining cyber posture and actionable policies and training when a cyber event occurs.
  • Baseline and continuous improvement through real-time situational awareness.
    • Once an organization has been assessed, a baseline is created.  From this baseline tools and technology should be deployed to monitor behavioral changes to the network and assets.  Real-time situational awareness is critical to understand when an organization is under attack from both internal and external bad actors.
KEYWORDS: cyber security awareness cybersecurity assessment security budget security education Small to Medium Business (SMB) security

Share This Story

Brian Berger is the executive vice president of commercial cybersecurity for Cytellix, a turnkey cyber managed service for small to medium sized businesses.

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Hand reaching up out of the ocean

What I Learned About Burnout the Hard Way (and How to Actually Fix it)

Broken wet floor sign

Why Response Time Is Becoming the Missing Metric in Workplace Safety and Security

Paparazzi

When Private Events Become Public Infrastructure: What Celebrity OSINT Teaches Security Leaders

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

People watching fireworks

Security Guard Assaulted at Firework Show

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

August 27, 2026

Leveraging AI & Mobility to Advance Your Security Domain

LIVE: August 27, 2026 at 2 PM EDT Explore how AI-driven cloud security solutions can elevate your security domain enhancing threat detection, streamlining operations, and delivering the resilience modern organizations demand.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing