Category: Shared Links

  • How Much Does a Data Breach Cost a Small Business?

    By J. Mesa

    A cybersecurity breach is expensive, and the cost lasts long after the systems are back on. For a small business, one incident can decide whether the company survives the year.

    This post breaks down what a breach costs, where the money goes, and what lowers the bill.

    How much does a data breach cost a small business?

    Estimates vary with the study and the size of the company.

    • The Hiscox Cyber Readiness Report 2019 put the mean cost of a firm’s largest single cyber incident at just under $200,000, across businesses of all sizes. That figure counts recovery, lost revenue, and lost customers.
    • IBM’s yearly Cost of a Data Breach Report covers organizations of all sizes. It measured a global average of $4.24 million in 2021 and $4.35 million in 2022, and the 2024 report put it at $4.88 million.

    Your number depends on what data you hold, how long you are down, and how prepared you are. A small breach caught early may cost a few thousand dollars. A ransomware attack with no usable backup can cost far more than $200,000.

    What are the direct costs of a breach?

    • Incident response. Forensic investigators and IT specialists to find and remove the attacker
    • System recovery. Rebuilding computers, restoring data, replacing equipment
    • Legal advice. An attorney to guide notification and liability
    • Notification. Letters, a call center, and credit monitoring for the people affected
    • Regulatory fines. Penalties under rules such as HIPAA, the FTC Safeguards Rule, or state privacy laws
    • Card brand penalties. Assessments under PCI-DSS if payment card data was involved
    • Ransom. If you choose to pay, with no guarantee of results

    What are the hidden costs?

    • Downtime. Every hour your systems are down is an hour you can’t sell, bill, or serve customers.
    • Lost customers. People leave a business that loses their data, and they tell others.
    • Damaged reputation. Winning new clients gets harder.
    • Higher insurance premiums. Your cyber policy costs more after a claim.
    • Staff time. Your team spends weeks on recovery in place of their jobs.
    • Lost contracts. Larger clients may drop a vendor after an incident.

    For many small businesses, the downtime and the lost customers cost more than the technical cleanup.

    What makes a breach more expensive?

    • Sensitive data. Stolen card numbers, health records, and Social Security numbers bring notification duties and fines. A breach that touches only internal systems costs less.
    • Slow detection. The longer an attacker stays inside, the more they take.
    • No backups. Without a clean backup you rebuild from nothing or face the ransom.
    • No plan. Decisions made in a panic cost time and money.
    • Compliance gaps. Regulators penalize a business that skipped required safeguards.

    What makes a breach less expensive?

    Studies of breach costs point to the same factors each year.

    • An incident response plan that the team has practiced
    • Employee training, which reduces successful phishing
    • Multi-factor authentication and limited access
    • Encryption of sensitive data
    • Tested backups, kept offline or offsite
    • Fast detection through monitoring and alerts

    Each one shortens the incident or shrinks the amount of data exposed.

    Can a small business survive a breach?

    Many do. The ones that recover have backups, a plan, insurance, and cash reserves to cover the gap. You may have heard a claim that 60 percent of small businesses close within six months of an attack. That number circulates widely, and nobody has produced a study that supports it. The honest answer is that survival depends on preparation.

    Does cyber insurance cover the cost?

    A cyber insurance policy can pay for investigation, legal help, notification, business interruption, and sometimes extortion payments. Before you rely on one, know three things:

    • Insurers require controls such as multi-factor authentication and backups, and they can deny a claim if your application was inaccurate.
    • Policies have limits, deductibles, and exclusions. Read them.
    • Insurance pays bills. It does not restore lost customers.

    How do I estimate my own risk?

    1. List the data you hold and how many people it covers.
    2. Estimate what one day of downtime costs in lost sales and wages.
    3. Ask how long a full restore from backup would take.
    4. Check which laws and contracts apply to your data.
    5. Add the cost of outside help: IT, legal, and notification.

    That rough total shows how much prevention is worth to you.

    How much should a small business spend on cybersecurity?

    No single figure fits every company. Match your spending to your risk. Start with the low-cost basics that prevent the most common attacks, then add assessment and monitoring as your data and your contracts demand.

    Compare the cost of each measure with your estimate above. A password manager and multi-factor authentication cost a few dollars per user per month. A day of downtime costs far more.

    What steps prevent or reduce the cost of a breach?

    1. Use strong, unique passwords with a password manager.
    2. Turn on multi-factor authentication for email, banking, and remote access.
    3. Update software and security systems on a schedule.
    4. Train employees on cybersecurity best practices, and repeat the training.
    5. Back up your data and test the restore.
    6. Encrypt laptops and phones.
    7. Write an incident response plan and keep a printed copy.
    8. Limit the data you keep.
    9. Review your vendors’ security.

    What should I do in the first 24 hours of a breach?

    1. Disconnect affected systems from the network.
    2. Call your IT provider or incident response firm.
    3. Notify your cyber insurer. Many policies require prompt notice.
    4. Call your attorney.
    5. Preserve evidence. Don’t wipe systems before they are examined.
    6. Change passwords from a clean device.
    7. Document every action and the time you took it.

    Fast, orderly action in the first day lowers the final cost more than anything you do afterward.

    Your next step

    The cost of a breach is significant, and most of it is avoidable. Investing in strong cybersecurity measures protects your business from financial and reputational damage. Cerberus Cybersecurity helps small businesses find their gaps with risk and compliance assessments, write practical policies, and train their teams. Contact us to find out where you stand.

  • What Is a CVE? How to Prioritize Software Vulnerabilities

    What Is a CVE? How to Prioritize Software Vulnerabilities

    By J. Mesa

    In 2021, researchers recorded more software vulnerabilities than in any year before it. The record has been broken several times since. For a business, the lesson is practical: you can’t fix everything, so you need to know what to fix first.

    This post explains what a vulnerability is, how the industry tracks them, and how to set priorities.

    What is a software vulnerability?

    A vulnerability is a flaw in software or hardware that an attacker can use to do something the designer never intended, such as running their own code, reading private data, or crashing a system. Vendors fix vulnerabilities with updates, also called patches.

    What is a CVE?

    CVE stands for Common Vulnerabilities and Exposures. It is a public catalog that gives each known vulnerability a unique ID, such as CVE-2021-44228. The nonprofit MITRE runs the program with funding from the US government.

    A CVE ID gives everyone the same name for the same flaw. Vendors, researchers, and security tools all use it.

    What is the National Vulnerability Database?

    The National Vulnerability Database (NVD) is run by the National Institute of Standards and Technology. It takes each CVE and adds detail: a severity score, the affected products, and links to fixes.

    How many vulnerabilities were disclosed in 2021?

    A report by Risk Based Security and Flashpoint counted 28,695 vulnerabilities disclosed in 2021, the highest number on record at the time. Three findings stood out:

    • 28,695 vulnerabilities were disclosed during the year.
    • 29 percent had no CVE ID. Another 4 percent had an ID in “reserved” status, which meant the NVD held no usable information about them yet.
    • 4,108 were remotely exploitable and had both a documented public exploit and an available fix.

    That last group matters most. The report found that an organization could cut its risk and its immediate workload by nearly 86 percent by putting those vulnerabilities first.

    Why does the number keep rising?

    • More software exists, and more of it connects to the internet
    • More researchers look for flaws, and more vendors run reward programs
    • Software is built from shared components, so one flaw affects many products
    • Reporting has improved

    A rising count partly reflects better discovery. It still means more work for whoever maintains your systems.

    What does a severity score mean?

    Most vulnerabilities receive a score from the Common Vulnerability Scoring System (CVSS), on a scale of 0 to 10.

    • 9.0 to 10.0: critical
    • 7.0 to 8.9: high
    • 4.0 to 6.9: medium
    • 0.1 to 3.9: low

    The score measures how bad a flaw could be. It does not tell you whether attackers are using it, or whether your business is exposed.

    Do I need to patch every vulnerability?

    Over time, yes. Right away, no. Nobody can install every fix at once. What matters is the order.

    Which vulnerabilities should I patch first?

    1. Flaws attackers are using right now. CISA publishes the Known Exploited Vulnerabilities catalog, a list of flaws with confirmed attacks. Start there.
    2. Flaws in systems that face the internet. Firewalls, VPNs, email servers, and websites are reachable by anyone.
    3. Flaws that can be exploited remotely and have public exploit code.
    4. Critical and high scores on systems that hold sensitive data.
    5. Everything else, on a regular schedule.

    This is the same lesson the 2021 report drew. A small share of vulnerabilities carries most of the real risk.

    What is a zero-day?

    A zero-day is a vulnerability that attackers use before the vendor has released a fix. You can’t patch it, so other layers have to protect you: limited access, network controls, monitoring, and backups. When the fix arrives, install it at once.

    What is patch management?

    Patch management is the routine of finding, testing, and installing updates. A simple version for a small business:

    1. Keep a list of your devices and software.
    2. Turn on automatic updates wherever you can.
    3. Check once a month for updates that need manual installation, such as firewalls and business applications.
    4. Install urgent fixes for internet-facing systems within days.
    5. Replace products the vendor no longer supports.
    6. Record what you did.

    How fast should I patch?

    Many organizations aim to fix critical flaws on internet-facing systems within days and everything else within 30 days. Attackers often begin using a new flaw within days of its disclosure, so speed on the most exposed systems matters more than perfect coverage.

    How do I find out which vulnerabilities affect my business?

    • Turn on update notifications from your vendors
    • Subscribe to CISA alerts
    • Run a vulnerability scan, which checks your systems against the list of known flaws
    • Ask your IT provider for a report on what is out of date

    A scan gives you a list. A risk assessment tells you which items on the list matter.

    What if a system can’t be patched?

    Some older systems have no fix available. Reduce the risk another way:

    • Take the system off the internet
    • Put it on a separate network segment
    • Limit who and what can connect to it
    • Plan and budget for its replacement

    Why do so many vulnerabilities lack a CVE ID?

    The CVE program depends on vendors and researchers to request IDs, and the process takes time. Some flaws are published on a vendor’s site or a researcher’s blog and never enter the catalog. Tools that rely only on CVE data miss those. It is one more reason to follow your vendors’ own security notices.

    Does this apply to a small business?

    Yes. You use the same operating systems, browsers, routers, and business applications as large companies, and attackers scan for the same flaws. The good news is that you have fewer systems to keep track of.

    What should I do this month?

    1. List your devices and software.
    2. Turn on automatic updates.
    3. Check your firewall and router for updates.
    4. Look up CISA’s Known Exploited Vulnerabilities catalog and compare it with the products you use.
    5. Schedule a vulnerability scan.

    Your next step

    As the world changes, so does the threat landscape. Diligence and awareness build resistance, and a community that shares what it learns protects everyone in it. Get in touch with our team to learn how Cerberus Cybersecurity can find and rank your vulnerabilities with a risk and compliance assessment. Contact us today. At Cerberus Cybersecurity, our stance on cybersecurity is and will remain people first.