Think Your Business Is Too Small for Cybercrime? Think Again

Businessman using smartphone and laptop with shield and padlock icons.

Many small business owners assume cybercriminals are looking for much bigger targets — companies with thousands of employees, large IT departments and massive amounts of customer data.

Unfortunately, size doesn’t necessarily make a business less attractive.

Smaller companies can be appealing targets because they may have fewer IT resources, less formal employee training and fewer safeguards around payments and sensitive information. According to the UK cyber security company, StationX, small to medium-sized businesses (SMBs) are 3x more likely to be targeted than larger firms, accounting for 50% of all attacks despite representing a fraction of economic output.

And cybercriminals don’t always need to break through sophisticated security systems to cause damage. Sometimes, they simply need to convince one person to trust the wrong email, phone call or payment request.

That’s where social engineering comes in.

How Cybercriminals Target People, Not Just Technology

When we think about cyber-attacks, it’s easy to picture hackers breaking through firewalls, exploiting software or launching sophisticated ransomware attacks.

But many cybercriminals take a much simpler route: they convince someone to let them in.

  • An employee receives an urgent email that appears to come from the owner.
  • A supplier sends “updated” banking information.
  • Someone claiming to be from the bank calls about suspicious activity and asks for a password or verification code.
  • A familiar-looking Microsoft login page asks an employee to sign in again.

These are examples of social engineering — attacks designed to manipulate people into providing information, transferring money or giving criminals access to systems.

And they work.

According to CFC, a leading cyber insurance provider, approximately three in four of its cyber claims are driven by human error. Theft-of-funds claims commonly involve criminals impersonating suppliers or senior employees to convince someone to authorize a fraudulent payment.

Social Engineering Is Getting Harder to Spot

At one time, many phishing attempts were easier to spot. Poor spelling, awkward wording, unfamiliar email addresses and suspicious-looking links were often warning signs.

Things have changed.

Artificial intelligence is helping cybercriminals research their targets, create more convincing phishing messages and carry out attacks faster and on a larger scale. Deepfake voice and video technology can also make impersonation scams increasingly believable.

That means an email may sound exactly like your boss. A phone call may appear to come from a trusted organization. A payment request may contain enough real information about your company, suppliers or employees to seem legitimate.

The most effective defence may be surprisingly simple: slow down and verify.

Build Verification Into Your Everyday Processes

One of the best ways to defeat social engineering is a team that knows what to look for and what to do next. Take the time to train your employees to:

  • Pause before acting on urgent requests. Messages demanding immediate payment, confidential information or password changes should raise a red flag.
  • Verify unusual requests through a second channel. If banking information changes or a senior employee asks for a transfer, confirm it by phone or in person using contact information you already trust.
  • Check the sender carefully. Look closely at email addresses, domain names and links. Small differences can be easy to miss.
  • Be cautious with unexpected login prompts. Instead of clicking a link in an email or text, go directly to the website or application you normally use.
  • Report suspicious messages quickly. Employees should know exactly who to contact when something doesn’t seem right.
  • Make verification part of the process. Establish procedures for payments, banking changes and requests for sensitive information so employees aren’t forced to make judgement calls under pressure.

The goal isn’t to make employees suspicious of every email or phone call. It’s to develop the habit of stopping for a few seconds and asking: Does this make sense, and can I verify it another way?

Technology and Risk Mitigation Still Matter

Multi-factor authentication, strong passwords, software updates, secure backups, firewalls and system monitoring remain essential parts of good cyber security. These technical safeguards should work alongside employee awareness and good internal processes.

But no security measure can make a business completely immune from cybercrime. CFC notes that even businesses investing in IT security can remain vulnerable when criminals bypass technical safeguards by exploiting human error.

Modern cyber insurance adds another layer of protection. Depending on the insurer and policy, coverage can include financial protection, incident response and proactive services such as threat intelligence and vulnerability scanning designed to identify threats before they become claims.

Why Work with a Local Independent Broker for Cyber Insurance?

Cyber insurance can be complex, and coverage can differ significantly between insurers.

As your neighbours in the insurance business, McLean & Dickey can help you understand your cyber exposures, compare coverage options from the insurers we work with and find protection suited to the way your business actually operates. If a cyber incident occurs, we’re here to help you navigate the claims process and connect you with the support available through your policy.

Don’t assume your business is too small to be targeted. Contact McLean & Dickey today to talk about cyber insurance and the steps you can take to protect your business, your finances and the trust you’ve built with your customers.

Read Our Blog
Like this post? Share it with your friends.
Skip to content