The News: According to recent intelligence from CrowdStrike, a staggering 43% of all cyberattacks now target small-to-medium businesses. While we often hear about the Fortune 500 in the news, hackers are increasingly focusing on the “middle market” because these companies often have enough data to be valuable but lack the enterprise-grade defenses to stop a sophisticated breach. The report highlights that no industry is exempt, but those handling high volumes of sensitive data—like healthcare, finance, and retail—are at the top of the list.
The Expert Take: CrowdStrike’s data reinforces a core principle of the NIST Cybersecurity Framework 2.0: Asset Management (ID.AM). You cannot protect what you don’t know you have.
For an SMB, your “attack surface” is larger than you think. It isn’t just your office computer; it’s your employee’s home Wi-Fi, your cloud-based accounting software, and even your digital point-of-sale system. Hackers don’t always want your company’s “trade secrets”—often, they just want a “pivot point” into your larger partners or a quick payday through ransomware.
The 3 Most Targeted Small Business Profiles:
- The Data Rich: If you store Social Security numbers, medical records, or credit card info (Healthcare/Law/Accounting), you are a “Tier 1” target.
- The Supply Chain Link: If you provide services to larger corporations, hackers may attack you to get to them. You are the “backdoor” into the enterprise.
- The “Always On” Retailer: E-commerce and retail shops are targeted because downtime equals immediate lost revenue, making you more likely to pay a ransom quickly.
How to Shield Your Business:
- Map Your Data: Identify exactly where your “Crown Jewels” (customer and financial data) are stored. Is it on a local drive? In the cloud? On a laptop?
- Implement an EDR: CrowdStrike’s specialty is Endpoint Detection and Response. For an SMB, this is like having a digital security guard that watches every laptop and server for suspicious behavior 24/7.
- Patch Religiously: Most “successful” attacks on small businesses exploit old software bugs that were fixed months ago. If your system asks to update, do it immediately.
Original reporting via: CrowdStrike Cybersecurity 101
