IT Security

Cybersecurity for Small and Medium-Sized Businesses

Accurately assessing and analyzing cyber security risks – we’ll show you what options are available.

When we talk aboutcybersecurity risks, most people first think of large-scale, targeted hacker attacks on major corporations and governments. We hear aboutadvanced persistent threats (APTs),zero-day vulnerabilities,spear-phishing, andCEO fraud.

In fact,cybersecuritysimply means that the risk is not limited to IT, but affects the entire company and originates in the cyber domain—primarily the internet. Thus, every small and medium-sized enterprise (SME) is exposed to a significantcybersecurity riskon a daily basis, simply because it owns systems and employs staff who interact with the internet. The greatest risk for these companies, however, is not targeted attacks (motivated by national interests) exploiting unknown vulnerabilities, but rather global malware, phishing, and ransomware campaigns carried out by profit-driven cybercriminals. These criminals use simple scams and known vulnerabilities to cause rapid, widespread damage and extort money.

The consequences can be devastating. The damage caused by a malware or ransomware attack often threatens the very survival of small and medium-sized businesses alike. It is therefore essential for every business leader to understand the risks to which their employees and resources are exposed and to know what options are available to effectively mitigate those risks.

Assess cyber security risks quickly and effectively

The first and most important step is to analyze the threats and challenges to cybersecurity. Security frameworks can facilitate a systematic assessment, but they are often—such as the BSI’s IT-Grundschutz in Germany—too extensive for small and medium-sized enterprises (SMEs) to manage. With theCIS Controls, the Center for Information Security (CIS)  provides a framework that can be scaled to suit the needs of small and medium-sized enterprises.

The 20 critical control points

The 20 critical control points of the CIS Controls Framework are divided into three categories:

  • TheBasiccategoryincludesessential control points for managing hardware and software, as well as for access control, configuration, and vulnerability management.

  • TheFoundationalcategorycoverskey security measures for data, software, firewalls, routers, switches, and both mobile and stationary devices.

  • The "Organizational" categorycoversorganizational measures such as awareness training, incident response, and the conduct of penetration tests.

GIS Controls
Source: CIS, License: CC-BY-SA 4.0.

Source: CIS, License: CC-BY-SA 4.0.

There is no “one-size-fits-all” solution for adequate security. The CIS recognizes this as well and divides the measures for assessing and addressing risks into threeimplementation groups.

IG1

The first group,IG1, includessolutions for companies with limited resources and little experience in cybersecurity. The goal here is to establish an appropriate baseline level of controls upon which further controls and measures can be built.

IG2

IG2includes controls for medium-sized companies and those that have already taken steps and gained experience in the area of cybersecurity. Among other things, this involves efficient and pragmatic protection against malware, phishing, and ransomware.

IG3

IG3is ultimately intended for companies that have sufficient expertise and resources to protect themselves against theAPTs andzero-day hacksmentioned earlier.

GIS Implementation Groups
Source: CIS, License: CC-BY-SA 4.0

In practice, this works as follows: Toensure, in accordance with Control Number 6 (Maintenance, Monitoring, and Analysis of Audit Logs), that the necessary log files are available for a post-mortem analysis following an IT incident,IG1requires that audit logs be enabled for all relevant systems. This typically involves a one-time effort. InIG2, a centralized log management system with analysis capabilitiesshouldbe implemented so that security personnel can quickly detect new threats, such as a malware infection or a DDoS attack, and track them retroactively. Finally, to protect large infrastructures and detect novel attacks exploiting zero-day vulnerabilities,IG3calls for consolidatinginformationin aSIEMand partially automating the response.

For organizations of all sizes, theImplementation Groupsalso provide a useful guide for prioritizing security measures. This ensures that core issues are addressed first, thereby minimizing cybersecurity risk from the outset. More information on the Implementation Groups is available in the accompanyingCIS white paper.

Take the quiz yourself now

For anyone who wants a quick overview of their current cybersecurity posture, the CISofferstheCIS Controls Self-Assessment Tool (CSAT). With this free tool, anyone who has a clear understanding of the measures currently in place can assess their cyber risk.

TheCIS Controlsprovide a quick and effective starting point for analyzing cybersecurity risks. However, anyone who runs the CSAT and takes a look at the sub-controls will notice that this is not an“out-of-the-box” checklist. For each control point, the generically formulated requirement must be adapted to the technological and organizational realities of the company’s IT infrastructure, and any unsuitable requirements must be revised or appropriately replaced.

Our Cybersecurity Assessment for Microsoft 365 Customers

In particular, companies that have made the switch to the Microsoft Cloud already have all the necessary technological prerequisites to implement the core controls ofImplementation Groups1 and 2. However, they often lack the expertise and guidelines needed to actually achieve the objectives of these controls.

For example, the sub-controls inIG1require ongoing inventory of all hardware and selective software approval; inIG2, they require trackingof the software actually installed; and inIG3, they require integrationthat consolidates this information.Allthree controls are technically addressed for endpoints through the use ofMicrosoft Intune. However, it must also be ensured operationally that all devices are registered and that a software blacklist or whitelist is maintained and enforced!

We therefore offer a cybersecurity assessment fully tailored to the Microsoft 365 cloud platform. Using our questionnaire on the implementation status and usage patterns of various Microsoft security tools—such asMicrosoft Intune,Microsoft Information Protection, orAzure AD Security Defaults—youcanclearly visualize your addressed and unaddressed risks and, in consultation with us, develop a concrete action plan for your company’s cybersecurity strategy.

Microsoft Dashboard for Security Analysis

Conclusion: Quickly identify risks and opportunities

CIS Controls also offer small and medium-sized businesses the opportunity to quickly assess their cybersecurity risk and identify opportunities for improvement through generic measures.

Our cybersecurity analysis also allows you to demonstrate the specific implementation status of technological measures in Microsoft 365 and clearly visualize the cybersecurity risks addressed by these measures.

Recent magazine articles on IT security

social engineering32
IT Security
What exactly is social engineering?
From a seemingly harmless text message to a sophisticated phishing campaign—how attackers exploit employees’ vulnerabilities and trust to achieve their goals.
Read more
VULNERABILITY ANALYSIS32
IT Security
Why should vulnerability analysis be a concern for small and medium-sized businesses as well?
More than half of all small and medium-sized enterprises in Germany have already fallen victim to a cyberattack; depending on the scale of the attack, the financial losses have run into the millions.
Read more
A security camera mounted on a wall
IT Security
What kind of penetration test do I need?
A penetration test must be conducted with the right objectives and scenarios in order to be effective.
Read more

Learn more about our phishing simulations and awareness training.

Discover how your business can benefit

csm nicolas roesener e35f74755d
Nikolas Rösener
Security Expert