Cybersecurity Measures for Small Businesses

Explore top LinkedIn content from expert professionals.

  • View profile for Chris Cooper

    Exit-Ready Cyber for UK PE-Backed CEOs | Don’t let an 18-month-old IT flag chip your MOIC at Month 11 | VDR opening in the next 12 months? DM “CYBER” | Founder @ Rougemont Security

    20,107 followers

    This UK bank spent £5M/year on cyber security. They were convinced that it was bulletproof. So, we sent in a man wearing a £4 high-vis jacket… and he tore it all down. Here's the full story: A few years ago, I worked with a mid-tier investment bank that wanted to prove their security was 'impenetrable.' They had a big security budget. A large internal team. And they were confident they’d pass with flying colours. So we started with the technical side: → Penetration testing (getting access to systems) → External perimeter testing → Trying every trick in the book They held strong for many months. Their technical controls were really solid. But good security doesn’t stop at the firewall. Next came the physical stage. We sent a trained agent through the front door, aiming to get access to their offices. Reception did what they were supposed to do: → Check the visitor list → Refuse when they weren’t on it Fair play — their process worked. So we went back a week later and increased the pressure. Our agent walked in during a busy time of day – queues forming, phones ringing, staff everywhere – and wore a high-vis jacket with a fake ID clipped to the front. Using social engineering, he raised the tension and made reception feel that they needed to let him through NOW. It worked. The receptionist waved him through. He • walked in • found a loose network cable • connected it to his own device • quietly hoovered up internal data until morning No alarms. No alerts. No one noticed. TAKEAWAY: The bank's firewall was sound, but their people were the biggest vulnerability. When we’re overwhelmed, we tend to default to the simplest decision: "Just let them through so I can get back to this.” You can have great policies. You can have top-tier tech. You can even test them both. But if you don’t simulate pressure, stress, and uncertainty, you're testing an ideal world and not the real one. Even the most advanced security systems can be undone by human error. Equip your team to recognise social engineering. It's your first line of defence.

  • View profile for Joe Levy

    CEO at Sophos

    16,022 followers

    This week, several Sophos employees received WhatsApp messages and emails claiming to be from me. Thankfully, their training and instincts kicked in, and they reported them. In response, I emailed everyone on the Sophos team to raise their awareness of the recent impersonation attempts and remind them how to complement technological controls in defending against social engineering attacks like these. CEO fraud isn't new. But it's getting more convincing. This comes at a time when threat groups like Scattered Spider and Shiny Hunters (tracked by CTU as GOLD HARVEST: https://lnkd.in/g82Bs4Su) are becoming increasingly adept at using AI and other novel social engineering attacks to gain access to otherwise well-defended organizations. The tactic is usually the same: reach someone outside of corporate IT systems, create urgency, impersonate a senior executive, IT, or other variants of authority, and push for action (e.g. “I need gift cards now for this partner event”). A few reminders we shared with our team, useful for the broader public: 1️⃣ Be skeptical of unexpected messages from colleagues via WhatsApp, Signal, SMS, LinkedIn, etc. 2️⃣ Always redirect to a verified internal channel: Teams, Outlook, Slack, etc.  3️⃣ Don’t engage. Report it through proper internal channels And for leaders, no matter the size of your organization: ✔️ Raise awareness of these tactics across your teams so they know when - and when not - to trust messages from their leaders and colleagues ✔️ Make it easy for them to report or verify those attempts ✔️ Establish formal and robust financial processes for fund transfers ✔️ Avoid corporate behaviors that enable this type of fraud (e.g. pressuring employees to conduct any business outside of clearly approved tools and processes) Stay safe!

  • View profile for Wendi Whitmore

    Chief Security Intelligence Officer @ Palo Alto Networks | Cyber Risk Translator | AI Security & National Security Leader | Former CrowdStrike & Mandiant | Congressional Witness | USAF Veteran | Keynote Speaker

    23,208 followers

    What if your biggest cyber risk isn’t malware but a highly trained “employee” you never hired? We’re watching a shift in how attacks happen. Social engineering is no longer sloppy or easy to spot. It’s polished, patient, and increasingly powered by AI. Why? Because attackers are evolving into well-run businesses. They have playbooks. They train their teams. They measure outcomes. And now AI is helping them refine tone, language, and credibility at scale, often faster than internal teams can respond. A recent Palo Alto Networks Unit 42 case involving Muddled Libra, also known as Scattered Spider, makes this very real. 🔶 They didn’t deploy malware. They didn’t dump credentials. 🔶 They called a help desk. Within 39 seconds, they leveraged existing OAuth tokens and connected APIs to extract 3 TB of data from trusted applications already inside the environment. That’s the reality. Attackers are exploiting trust, not just technology. So what can organizations do? 🔶 Re-evaluate help desk authentication and move beyond knowledge-based verification 🔶 Require stronger identity validation for password resets and privilege escalation 🔶 Apply least privilege and tighter controls to tokens, sessions, and API access 🔶 Monitor identity behavior, not just endpoints 🔶 Train teams to recognize well-crafted, professional social engineering This is where identity security becomes critical. Not just who has access, but how access is granted, validated, and monitored every step of the way. The question isn’t whether attackers will keep improving. They will. The real question is whether we are evolving our defenses at the same pace.

  • View profile for Tomislav Vazdar

    Principal Consultant | Cybersecurity & AI (Governance, Risk & Compliance) | CEO @ Riskoria | Media Commentator on Cybercrime & Digital Fraud | Creator of HeartOSINT

    10,224 followers

    During a recent panel discussion organized by the Voice of Entrepreneus association ( Glas PODUZETNIKA ), I had the opportunity to delve into some of the most pressing cybersecurity challenges and trends shaping the landscape for 2025 and beyond. One topic that particularly resonated was ransomware - a threat that continues to evolve in sophistication and impact. 🚨 The Ransomware Playbook: Cybercriminals today are far more strategic. They meticulously analyze a company’s financial standing, industry, and data value to determine the ransom amount. This calculated approach ensures their demands hit where it hurts the most, making it difficult for organizations to negotiate or refuse payment. 🔍 Emerging Trends to Watch: 1️⃣ The rise of double-extortion tactics, where attackers threaten to leak stolen data in addition to encrypting it. 2️⃣ Increasing use of AI-powered phishing campaigns, creating highly personalized and believable traps for employees. 3️⃣ Targeting of critical supply chain links, where vulnerabilities in smaller vendors compromise entire ecosystems. 🛡️ How Do We Respond? It’s clear that businesses of all sizes must adopt a proactive, rather than reactive, approach to cybersecurity. This means: ☑️ Regularly assessing risks and ensuring robust incident response plans. ☑️ Implementing stronger authentication mechanisms like multifactor authentication (MFA). ☑️ Educating employees to recognize and avoid sophisticated phishing attempts. Cybersecurity is no longer a cost center - it’s a critical investment in protecting your organization’s reputation and operations. As threats like ransomware grow more complex, our strategies must become equally agile and innovative. What trends in cybersecurity are you most concerned about for 2025? Let’s discuss in the comments! 👇 #Cybersecurity #Ransomware #DigitalRisk #ProactiveDefense Tomislav Gosarić Tomislav Vuk Tino Herljević Marijan Bračić Vedran Antoljak

  • View profile for Dor Eisner

    Co-founder & CEO @Guardz | Powering MSPs Growth with Agentic Workspace Security

    7,923 followers

    Most MSPs still think of cyber threats as isolated incidents, while data show a different reality: compromise is already part of the baseline in SMB environments. 89% of monitored SMBs have at least one user with a confirmed credential compromise at any given time, and roughly 31% of users use compromised passwords every single month. That’s reality! It’s getting worse fast. We are seeing dozens of thousands of unique spray IPs every month, session-hijacking activity increasing by more than 20% in a matter of months, and OAuth abuse accelerating as attackers move higher in the application layer, where traditional controls are weaker. Ransomware detections surged by 190%, and RMM abuse has become the number one endpoint threat vector.  Business email compromise continues to operate at scale with real incidents costing millions of dollars. Attackers aren’t breaking systems anymore. They’re moving through them. That’s why adding more tools or reacting faster to alerts isn’t solving the problem. The issue isn’t volume, it’s the model itself.  Security is still being operated in silos, while the attack surface is fully connected. What’s needed now is a fundamental shift in how we operate security. Moving from fragmented controls to a unified data fabric, powered by agentic detection and response that can actually understand context and act across the entire environment with automated remediation. We captured these patterns along with the drivers behind them in the 2026 State of MSP Threat Report. https://lnkd.in/eewsqvtd

  • View profile for Paakhhi G.

    Helping Professionals Break into Data Privacy & Startups Get DPDP Compliant

    13,613 followers

    Ever received a suspicious email that made you raise an eyebrow? You're not alone! Let's decode the art of cyber manipulation. 🤔💻 #StayVigilant" Cybersecurity isn't just about firewalls and antivirus software. It's also about protecting yourself against a more subtle threat: social engineering attacks. These tactics prey on our human nature, but we're here to empower you to recognize and outsmart them. Unmasking Social Engineering Attacks: They don't need to crack codes; they manipulate minds. Think phishing emails, pretexting, baiting, and tailgating—all designed to trick us into giving up sensitive information. Identifying the Telltale Signs: 1. Sense of Urgency or Fear: When it feels like a crisis, pause and verify. 2. Unusual Requests: Unexpected demands for info or access? Proceed with caution. 3. Inconsistencies: Typos, strange email addresses, or unprofessional language can be tip-offs. 4. Too Good to Be True Offers: If it sounds too good, it might be part of a scam. 5. Unsolicited Contacts: Be wary of unsolicited messages or calls seeking personal or financial data. Defending Against Social Engineering: 1. Stay Informed: Keep yourself updated on the latest social engineering tactics and red flags. 2. Verify Requests: Always confirm the identity of anyone requesting sensitive information. 3. Two-Factor Authentication: Boost security with two-factor authentication wherever possible. 4. Utilize Filters: Use phishing filters and email scanners to spot malicious content. 5. Policy Enforcement: Implement and reinforce strong security policies within your organization. 6. Encourage Reporting: Foster a culture where reporting suspicious activity is encouraged and rewarded. Stay vigilant, stay informed, and together, we can build a safer digital world. #cybersecurity #socialengineering #securityawareness 🔒💼🌐

  • View profile for Martin Astley

    CISO & MSSP Founder | Helping organisations strengthen cyber resilience, Zero Trust & AI governance | Keynote Speaker | Mental Health in Cyber Advocate

    23,882 followers

    This is getting clever… and dangerous. ⚠️ At first glance, this looks like a standard Cloudflare “verify you’re human” page. But look closer 👇 It’s instructing the user to open PowerShell as an administrator and paste a “verification code”. That is not verification. That’s execution. This is a phishing attack designed to bypass traditional security controls by turning the user into the vulnerability. No exploit needed. No malware download prompt. Just social engineering done well. If a user follows these steps, they are effectively handing over control of their machine. A few takeaways worth sharing with your teams: - No legitimate website will ever ask you to run commands in PowerShell to “verify” anything - Anything involving admin access should immediately raise suspicion 🚩 - Attackers are shifting from technical exploits to human manipulation - Security awareness is no longer optional, it’s critical This is exactly the kind of attack that slips through if your defence strategy is purely technical. Train your people. Test your people. Protect your business. Curious to know - would your users spot this? 🤔 #CyberSecurity #Phishing #SocialEngineering #Cloudflare #SecurityAwareness #CISO #Infosec

  • View profile for Jason Makevich, CISSP

    Helping MSPs & SMBs Secure & Innovate | Keynote Speaker on Cybersecurity | Inc. 5000 Entrepreneur | Founder & CEO of PORT1 & Greenlight Cyber

    9,863 followers

    Someone starts a new job on Monday. They post about it. By Wednesday there's a text from the owner. Quick favor. Grab some gift cards for the team. Keep it quiet, it's a surprise. They buy the cards. They scratch off the codes. They send the photos. The message came from an attacker. This is a timing attack, and the timing is public. Job changes get announced. Owners and managers sit a click away. Everything an attacker needs is already published, including the fact that a specific person at a specific company is three days into a role where they're still learning how the boss talks. That gap is measurable. Keepnet's 2025 study of 237 companies found new hires are 44% more likely to fall for phishing than longer-tenured employees in their first 90 days, and 45% more likely when the message impersonates the CEO. In that same window, 71% clicked at least one phishing email. Two things make the first week harder than those numbers suggest. Often the message arrives by text. In Verizon's 2026 DBIR, 41% of social engineering breaches involved social vectors beyond email, with roughly a quarter coming through social media or phones. Smaller organizations saw a median of 12 SMS phishing campaigns a year. Every filter you bought is looking somewhere else. And a new hire who senses something is off has to weigh being right against looking difficult in week one. Most people take the safer social bet. So remove the decision from the employee and put it in the process. Brief them before day one. Write down how leadership actually communicates. Require second-channel verification for any money or credential request, so checking counts as following policy. And have the owner say it plainly on day one. "I will never text you asking to buy anything, and you will never be in trouble for checking." Keep announcing new hires. Celebrating people is good. Just brief them before you do. Onboarding sits between HR and IT, which is why ownership tends to fall through. The best MSPs already catch this, folding it into the onboarding runbook and revisiting it at QBRs, because they've seen what the first week costs. The window runs 90 days. Week one is where it peaks.

  • View profile for Vivek P.

    Director & Head - Cyber Intelligence | CISM | IAM | PAM | SSO | SAML | OAUTH | MFA | EPM | EDR | SIEM | DLP | GRC | Oracle | Sailpoint | Delinea | BeyondTrust | Cyberark | Ping | Forgerock

    12,644 followers

    Most social engineering attacks don’t happen in the dark with some hacker in a hoodie. They happen at 2:15 PM on a Tuesday… “Hi, I’m Rahul from Finance. I’m locked out. Can you reset my password real quick?” And just like that, access granted. No red flags. No alerts. No second thought. Why? Because companies train support teams to be helpful, not suspicious. To solve problems fast, not question authority. Here’s the cheat code nobody’s giving them: 🔒 Always verify identity through a second channel. (Even if the person sounds urgent or important.) 🧠 Assume every password reset request could be fake. (It’s not rude. It’s secure.) 👀 Look for pressure tactics: “I need this NOW,” “My boss will freak,” “We’re losing money.” (Classic hacker playbook.) 📞 Never trust caller ID or email alone. (Hackers spoof both in seconds.) 📚 Roleplay attacks monthly. Not just one-time training. (Real learning happens through repetition.) 🎯 Give support teams the power to say no. If they feel unsure, they should pause, not panic. Social engineering isn’t some advanced tech issue. It’s a people issue. And if companies don’t teach the frontline how to spot it, they’re just funding the next breach. Train your support team like your business depends on it. Because one day, it actually might. Tag your IT lead or support head here. Let’s start fixing this where it actually matters.👇 📌 P.S. As a trusted cybersecurity specialist, I can help you assess your cybersecurity risks and recommend the right solutions for your business. Please feel free to contact me if you have any questions or need assistance. #cybersecurity

  • View profile for Dev Mitra

    Forbes Business Council I Helping HNI Entrepreneurs Build & Scale Startups in Canada | IP & Technology Lawyer | Managing Partner @ Matrix Venture Studio™

    20,355 followers

    The $2.8 billion mistake most small businesses make is thinking they're too small for hackers to notice. Your business is the perfect target for hackers, and it has nothing to do with your data. I've noticed a consistent pattern in hundreds of breaches, where the hackers aren't just targeting you for your data, but they're using you as a stepping stone. Small businesses have become the perfect entry point in our connected economy. When you're part of a supply chain or have access to larger client systems, you become valuable real estate for attackers. Some data on this big problem: ↳ Small businesses faced over 700,000 attacks in 2020 alone ↳ These attacks resulted in $2.8 billion in damages ↳ Only 14% of small businesses have any security plan at all When small companies become the weak link, the consequences get massive: 📌 The 2013 Target breach, exposing 40 million customer credit cards, began when hackers compromised credentials from a small HVAC vendor. 📌 In 2021, attackers targeting Colonial Pipeline caused gas shortages across the East Coast. They didn't breach Colonial directly; they entered through smaller vendors with weaker security. Most small business owners I talk to are ignoring security because they’re overwhelmed with competing priorities and limited resources. But effective security doesn't always mean expensive security. Here are four practical steps that have helped my clients significantly reduce their risk: 1. Implement multi-factor authentication This single step blocks most automated attacks and costs almost nothing to deploy. 2. Train your team to spot phishing attempts With 95% of breaches starting with human error, a simple training program creates massive returns. 3. Keep good backups When ransomware strikes, the difference between paying thousands and recovering quickly often comes down to having current backups. 4. Have a response plan ready Know exactly who to call and what to do if something happens. The first 24 hours are critical. What I've learned is that the businesses that survive are the ones that build basic security practices into their daily operations. 📌 Have you ever received a phishing email? #cybersecurity #smallbusiness #startups #security

Explore categories