Businesses have come a long way in regard to technology. The digital era has changed the modern workplace and with those changes come new concerns for security. High quality, fireproof filing cabinets and locked doors no longer provide sufficient protection for company data. Businesses now must consider the real threat of cybercriminals and the impact that breached data could have on a company’s livelihood. And while cybercriminals are often considered to be shady characters in hoodies who live in basements and pose minimal threat to small and medium sized businesses, the reality is that no one is immune to becoming a target.
“The biggest issue I have when speaking with clients or prospects is denial,” said Greg Pike, sales executive at LP Insurance. “Everybody that is using the internet needs to understand that [cyber] criminals are way more sophisticated than we are as business owners.”
Nevada Business Magazine recently hosted a Business First panel with experts qualified to address cybersecurity. Showcasing a range of expertise, from complex IT systems, managing common digital vulnerabilities and cybersecurity insurance, these experts sat down in early-November at Proprietor’s Reserve to offer their thoughts regarding cybersecurity. Business First breakfasts are designed to educate and inform readers while allowing them the opportunity to network and hear from experts in person. After covering a variety of cybersecurity topics, panelists took audience questions and stayed after to meet with attendees, one-on-one.
The Business First cybersecurity panel was moderated by Shannon Scholten-Adams, vice president of Nevada Business Magazine. In addition to Adams, four experts offered their insights including Christopher Berdan, director of information technology at Clark County Credit Union, Sean Connery, founder of Orbis Solutions, Kyle Hendrickson, director of cybersecurity at Eide Bailly and Greg Pike with LP Insurance. Each panelist brought a unique perspective to this complex issue and provided insight for business owners and executives on building a cyber safe world.
Recognizing the Importance
The idea that cyber threats only exist for large corporations is a dangerous misconception. Whether it is due to a niche industry, a small workforce or simply a more old-fashioned way of conducting business, many small and medium sized businesses overlook the need for cybersecurity.
“These hackers aren’t always going after the big guys,” said Berdan. “The big guys can afford to have those [IT] departments. They can afford to have the top tier talent. Smaller companies typically will have smaller IT departments and will have smaller investments in software and platforms that can deter those attacks. The biggest and worst thing that a company can do is think that it will not happen to them. Because eventually, somewhere down the road, it will happen to you.”
Taking the threat of cyber-attacks seriously is paramount for survival in today’s business world. And while every company may not be able to afford a large team of IT specialists, there are certain steps that can be taken to manage common cyber vulnerabilities.
“Having an IT department is something that most businesses look at as just a giant money waste because they are not generating any revenue for your company,” said Berdan. “But it is one of the most important departments that any business can have. And if you are a smaller company and you can’t really afford that top-tier talent, getting some sort of an MSP (Managed Service Provider) to make sure you cover all your bases is something that you need to do. Having a robust IT department or a robust service provider that has your back is one of the biggest, best and most important things you can do as a company.”
Big Business
Unbeknownst to many businesses, hacking is a multibillion-dollar industry. Although Hollywood has spun a narrative that hackers are rebellious teenagers or college dropouts who sleep on their best friend’s couch, the reality is that hacking is big business on both a national and international level. “Internationally, a lot of the hacking groups are in Russia, and it is a business,” said Connery. “This isn’t a guy in a hoodie in his basement that’s disheveled, it is a [real] business. They have cubicles. They have medical, they have doctors and nurses. This is a real business, and they are making billions of dollars.”
In many countries, hacking derives so much revenue and offers so many benefits, that it it is perceived as adventitious rather than criminal. “[Hackers] have the same advantages of being able to work from home,” said Hendrickson. “[Hacking may be] state sponsored, or state ignored, because it may not be with the full blessing of a government, if you live in a country and someone is taking action against someone that you are competitive against, you might still encourage it, but not necessarily come out and sponsor it.”
Managing Vulnerabilities
Every internet user is vulnerable to the threat of a cyberattack and with so many smart devices in both the personal and professional sphere, managing that vulnerability is essential. For businesses, educating the workforce about potential hacking attempts is a practical tool for preventing cyber-attacks. “IT talent is important to be certain, but cybersecurity is not purely an IT problem,” said Connery “93% of [cybercriminal] tech is going to be coming in through email, so you are going to have business email compromised. [When] people receive an email, they act on it. [There are] phishing attacks [where an email] looks like Office 365 and it asks you to change your passwords. You enter what you have and now the bad guy has all your information. It really is not purely an IT thing. We require everyone in the organization to help protect themselves, their business, their family, and friends. It really is an everybody thing.”
In today’s digital world, cyber threats are not limited to email. With nearly every household and business device running off WIFI or the internet, cyber criminals have become experts in penetrating even the most ordinary of digital devices. Having a knowledgeable IT department to protect these devices from threats aids in managing vulnerability. “Why are we putting thermostats and televisions on corporate network with your servers and your workstations? Why aren’t they on a guest network or on a whole completely separate network?” asked Connery. “There actually was a hotel casino that had a smart thermometer in their lobby and the bad guys were able to access it and then access the gaming data all through a thermostat that they put on the same network as a server.”
Implementing permissions for certain employees and devices is also a tool for cybersecurity. While employees must be able to complete their jobs, much data can be protected by simply not allowing it to be available to unnecessary personnel. Similarly, limiting the use of personal email and social media on work devices can also reduce potential threats. With social engineering on the rise, where deception is used to manipulate someone else to divulge confidential information for the sake of fraud, maintaining separate devices for personal and work is simply good business. “If you are allowing your employees to use Facebook or any sort of social media on your network, stop it today,” said Pike. “Put out a notice right now and put it in your system so you can’t even log onto the systems.”
Fail-Safe
Cybersecurity not only involves preventing potential threats but preparing for them. One essential way for businesses to do that is through investing in cyber insurance. “By 2026, ransomware is going to be a $10 trillion industry globally,” said Berdan. “To put that in perspective, if you don’t have cyber insurance, get it today, because it’s going to save your butt someday. It is not an ‘if,’ it is a ‘when’ you get hit.” Unfortunately, investing in quality cyber insurance is not always a clear process. “When you begin to look at the billions and billions of dollars that ransomware has taken from our industry, you’ll begin to understand the underwriting aspect has become more and more difficult,” said Pike. “Three years ago, the application was seven questions. They wanted to know what industry you were in, your revenue, and how many employees you had. Today, the average application runs about 15 pages, and the application dives very deep; 90 percent of the time I tell my clients to not even bother filling it out. [I tell them to] give it to their IT person, because it’s language that you and I don’t really talk about every day.”
Regardless of its complexities, cyber insurance is a must for businesses. “The best fail-safe would be to find the right insurance carrier that has the right type of coverage,” said Pike. “Most cyber liability that you are seeing inside an insurance policy that the carriers are giving away is not enough. It doesn’t respond to every crisis that you are going to have. Most standard cycle liability policies have seven separate ensuring agreements and there is a trend now that they have redefined the crisis response or the breach in the crisis management and are now providing sublimits. Unfortunately, that is the largest portion and they tie so many different causes of loss into the sublimit, that it is not enough to cover the exposure. With the average business being down for 21 days, is a quarter of a million dollars enough to support your business? The answer for most of us is going to be no. Finding the critical carrier that understands the cyber risk, the right insurance broker that understands how to read the policy and understand the terms and conditions and then can express that to the business owner [is essential].”
Changing the Landscape
COVID-19 had a significant impact on business. And while it changed the landscape of many company operations with work from home protocols, it also ushered in new opportunities for cyber-attacks, a greater need for knowledgeable IT departments and an educated workforce. “From a management perspective and having a lot of your workforce work from home now, it is harder to keep an eye on people,” said Berdan. “I don’t mean like Big Brother, standing over their shoulder making sure that [employees] are doing their work, I mean their network. Making sure you have a robust VPN to access your company data is a huge factor in that and also training. Ronald Reagan had a great saying – ‘Trust but verify’ and when it comes to basically all ransomware attacks and vulnerabilities, you should turn it on its head and it should be verified within trust. With having a workforce that is so remote now, it’s harder to do that.”
Although more businesses have returned back to traditional office settings, many businesses continue to operate remotely or offer employees flexible work schedules. This flexibility demands higher cybersecurity. “You have to assume that [employees working remotely are working on a] compromised system,” said Connery. “I assume every workstation is compromised, but definitely home machines that don’t have all the tools to detect [threats] and do all that stuff we need to do. If you are working at a coffee shop or somewhere else, [cyber security has] really changed. We used to sit at an office behind a firewall and be sort of protected, but now it is very different. You are on your cell phone, you’re at a coffee shop, you’re home on your own computer, where your kids are playing games and downloading those. [There are] so many different technologies.” These different technologies and locations for conducting business have IT departments looking for innovative ways to offer cyber security to employees. “[The question is], ‘How do we reduce the attack surface in new and creative ways for all of us while being able to work independently from coffee shops and from home on any device?’” said Hendrickson. “It is a different way of thinking of security. When I think of reducing the attack surface, I want to focus on protecting less stuff, but being able to watch that stuff better and increase the level of security for what I protected.”
Planning Ahead
Being the target of a cyber-attack is not a matter of ‘if,’ but ‘when’ for businesses. And regardless if the attack is being conducted 30 minutes or 30,000 miles away, the consequences of neglecting cybersecurity could prove devastating for businesses. In order to protect themselves, it is essential that companies stay informed of new technology and the opportunities they provide for cybercriminals. “Incident response plans are living documents,” said Berdan. “[Just as our] security policies are living documents, your knowledge should also be essentially a mental living document. Ransomware, malware, vulnerabilities are changing hourly, not daily, but hourly. Do the best you can to stay as up to date as you can on threat actors, threats, vulnerabilities, breaches, etc.”
Being aware of the existing cyber threats is a first step for businesses, but creating a thorough response plan prepares them in the event of an attack. “A plan isn’t a plan until you’ve tested it,” said Hendrickson. “It’s just a good idea until you’ve gone through and identified the gaps. And it can’t be just a technical plan, it needs to be a business plan because it needs to support the processes that you use to serve your clients. We need to test it, we need to involve the business leaders and it needs to be comprehensive [so that] we understand what to do in a disaster.”
Cybersecurity is a multi-faceted and ever changing industry. And while many businesses have the luxury of entire IT departments, other businesses don’t know where to begin when it comes to protecting their business from cybercriminals. “Getting started for most companies is a hard thing,” said Hendrickson. “And while I think there’s a lot of value in external resources, starting internally to get that shell of the plan and walking through it a few times internally [is a start]. [It’s important to ask], ‘What happens if this key system goes away? How do we do this?’ The average outage of a business is 21 days in regard to ransomware, but most people get paid every two weeks or twice a month. What happens if your payroll suddenly goes away? People tend to stop showing up if you stop paying them. What are your plans around simple things like that? Start [there] and then broaden that.”










