The Identity Theft Resource Center (ITRC), a U.S. non-profit organization, recently released a report with some disturbing findings for small businesses. It found that cyberattacks targeting small businesses have hit a new record, with 73 percent of small business owners polled reporting either a data breach, a cyberattack, or both. This is the highest number in the three-year history of the report.*
The report is based on survey responses from 551 small business owners, leaders, and employees. The goal of the survey was to explore the impacts of cybercrimes on small businesses.
Who is initiating these attacks? The top four causes cited were External Threat Actors (30 percent), Malicious Insiders (30 percent), Third Party Vendor Was Attacked (24 percent), and Remote Workers (21 percent). Phishing schemes, business email compromise, and scams or fraud also caused breaches.
Employee and consumer data continue to be the most impacted categories of information affected by data breaches, the report found. Although the financial impacts of breaches were lower than previous years, with more businesses reporting losses under $250,000 and fewer reporting larger losses, more businesses saw other increased impacts. For example, 32 percent cited loss of customer trust. Some businesses (13 percent) also resorted to headcount reductions as a direct result of data breach costs.
Other problems faced after a cyberattack included difficulty understanding what happened, problems responding to customer concerns, and difficulty finding affordable solutions to help prevent future attacks.
Cyber insurance was cited as the primary single source of recovery funding, at 33 percent. However, many companies had to pay costs out of pocket (cash reserves 29 percent) or rely on financing (existing lines of credit 27 percent, and new loans or lines of credit 23 percent).
"The trends identified in the 2023 Business Impact Report follow the same patterns the ITRC has seen in our other reports around consumer impacts and data breaches," said Eva Velasquez, ITRC President and CEO. "We saw a spike in attacks in 2021 before a reduction last year due to the Russian invasion of Ukraine and disruption in the cryptocurrency markets. Identity crime markets have rebounded this year, leading to record levels of breaches and business attacks."
How Are Businesses Responding?
On the more positive side, 85 percent of survey respondents said they were ready to respond to a cyber event. That's up significantly from 70 percent last year.
Despite their optimism, however, the report found that most small businesses have not been taking advantage of multi-factor authentication for employee or customer use. They have also not been making strong passwords mandatory or using role-based access for employee access to sensitive data. The number of businesses who reported using these various precautions ranged from just 20 percent to 34 percent. This is a major issue when cyberattacks targeting small businesses are hitting such significant numbers.
The report states that practices and policies for the protection of information and privacy are also lacking, with adoption rates for consumer data collection, use, and storage practices ranging from 21 to 37 percent.
"The good news is that small business leaders are focused on data security and privacy protection," said Velasquez. "However, we still have a lot of work to do. We must accelerate the transition to newer protections and continue to develop new resources to assist victims based on solid research and unmistakable evidence."
While businesses seem to have more positive attitudes about their ability to defend themselves against cybercrime, at the same time many seem to be dismissing standard best practices. As the number of cyberattacks targeting small businesses continues to climb, businesses must become increasingly vigilant in order to reduce their chances of being victimized.
* https://www.idtheftcenter.org/publication/itrc-2023-business-impact-report/