Nothing keeps executives awake at night more than the threat of cyberattacks. There’s a good reason for that. Cybercrime is an omnipresent threat that’s growing in sophistication and reach. That’s because, for criminals, cybercrime is a high-growth industry, ballooning from $3 trillion in 2015 to $10.5 trillion by 2025, according to Cybersecurity Ventures. Potential costs of data breaches and other cyberattacks include:
- Financial loss from lost revenue, operational downtime, recovery costs, legal exposure and increased cyber insurance costs
- Regulatory penalties if authorities find a company was complacent or not in compliance with data protection standards when a breach occurred
- Reputation damage and loss of trustwith customers and vendors
Against this backdrop, strengthening your cybersecurity measures isn’t optional. Since every business is a target, you must safeguard your business and customer data regardless of your company’s age, industry or size.
Fortunately, you’re not alone and have options based on expert cybersecurity advice. In this blog, we’ll review the cyberthreats you should know and how to prevent them from damaging your business.
What is a cyberattack?
Before we dig into cybersecurity best practices, let’s look at the most common attacks and breaches facing companies today. It’s particularly important for small and medium business (SMB) managers, who may recognize these examples from headline-making high-profile breaches, to understand that cybercriminals also target their companies. In fact, the more limited financial and technical resources available to SMBs make them the preferred target of many criminal organizations. This, in turn, has made SMB cybersecurity awareness and defensive measures as important as enterprise IT security best practices.
Common examples of cyberattacks and data breaches
Cyberattacks are constantly evolving and come in many forms. The most common attacks exploit your machines and, even more frequently, your people. And they’re often interrelated or work in tandem. For example, a human may be compromised in one form of attack to facilitate a separate attack on systems or data. Here’s a quick rundown on four categories of tactics and breaches that comprise, either together or separately, most successful cyberattacks.
Social engineering attacks
Social engineering attacks exploit humans instead of machines. These attacks trick your employees into providing confidential information by posing as trusted colleagues or IT support specialists. Tactics include baiting, pretexting and impersonation. Urgency and fear are sometimes used to get the victim to respond quickly without thinking. These attacks are effective because they bypass traditional system defenses.
Malware and ransomware
The term “malware,” derived from “malicious software,” refers to any program or code that infiltrates or damages computer systems. Its objectives include:
- Stealing your data
- Disrupting your operations
- Gaining control of your networks
Ransomware, a fast-growing and highly-feared subset of malware, locks your employees out of their systems or encrypts files, allowing attackers to demand payment (a “ransom”) in exchange for a decryption key. The emergence of Ransomware-as-a-Service (RaaS), which enables non-technical criminals to execute ransomware attacks, has vastly spread ransomware attack reach and frequency.
Data breaches
Data breaches occur when criminals access your company’s confidential, sensitive or protected information, often through the attack methods we just discussed. They can involve theft of:
- Personally identifiable information (PII)
- Intellectual property
- Financial records
- Trade secrets
Data breaches can have severe consequences, as identified earlier, on your company’s financial, regulatory or brand status. With increasingly stringent regulations like the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), your business is required to pursue proactive measures (e.g., encryption, regular security audits, etc.) to minimize both the risk of breaches and damages when they occur.
State-sponsored attacks
State-sponsored attacks are funded and directed by nation-states to achieve geopolitical goals. They typically target critical infrastructure (public utilities, financial systems, government agencies, etc.) to cause disruption and chaos and/or to steal classified information. Strategic objectives may include:
- Election influence or disruption
- Economic disruption
- Espionage
State-sponsored attacks often have considerable sophistication and resources and leverage vulnerabilities like zero-day exploits and advanced persistent threats (APTs) to evade detection over extended periods. Defensive measures against state-sponsored attacks involve traditional cybersecurity measures and intelligence collection, sharing and collaboration between governments and private companies.
10 Cybersecurity tips to prevent cyberattacks
Despite rising threats, there’s good news, too. There are steps you can take and affordable cybersecurity solutions you can deploy to tilt the odds in your favor and protect your business. Here are 10 cybersecurity best practices you can leverage to maximize your protection.
1. Implement strong authentication
Develop and enforce robust password policies and enable multifactor authentication (MFA) wherever possible. “Wherever possible” is key here—even if you think an application is low-risk, it may integrate (one day, if it hasn’t already) with an application that accesses sensitive systems and data. Make MFA-enablement central to your company’s cybersecurity policy. And consider a strong password management system for managers and employees who need to access multiple systems.
2. Provide cybersecurity training
Educate employees on cybersecurity risks and best practices. Since cybercriminals are better at exploiting people than machines, training your staff to recognize phishing attempts (and other social engineering tactics) and other common cyberthreats is vital. Cyberaware employees reduce your company’s exposure and become much savvier about cyberthreats in their personal lives as well.
UPSTACK RECOMMENDS: The United States Cybersecurity and Infrastructure Agency (CISA) provides free educational resources you may find helpful. The Federal Communications Commission also publishes cybersecurity resources for small businesses.
3. Keep systems updated
Consistently update and patch all systems, software, and devices. Unpatched systems are a common attack vector for cybercriminals. They also present a strong argument for managed services that routinely keep your systems updated.
4. Use robust security software
When it comes to security, an ounce of prevention is worth a pound of cure. Installing and maintaining reputable antivirus, anti-malware, and firewall solutions is essential to achieving and maintaining protection. Here again, managed services can pay for themselves many times over. Services like unified threat management (UTM) can free your IT teams to focus on strategic matters and eliminate the risks associated with expired patches and definitions.
5. Secure networks
Protect Wi-Fi networks with strong encryption (WPA2 or WPA3), change default router passwords and secure your data networks with firewalls, virtual private networks (VPNs) or other network security solutions, depending on your company’s needs. If you’re not sure what you need, have a security audit performed.
UPSTACK RECOMMENDS: Don’t overlook endpoint security—especially if your company has remote or mobile employees.
6. Encrypt sensitive data
Implement encryption for both data at rest and data in transit. Be sure to encrypt your data backups – they’re often overlooked, which makes them a favorite target of cybercriminals.
7. Implement access controls
Regularly review and update access permissions, especially for privileged accounts. Implement strong access management policies, such as:
- Role-based access control (RBAC), which connects access rights to user roles, privileges to roles (rather than users) and automated tools that add, change and delete privileges through employee lifecycles
- The principle of least privilege, which limits exposure by granting access only to data and systems necessary for any job function
- Multifactor authentication, as discussed earlier, to prevent unauthorized access
- Secure administrative access for accounts with special access and privileges
- Access control layers that secure data and applications with firewalls, network segmentation and attribute-based controls in conjunction with user identification
- Monitoring and management procedures that ensure users have not accessed unauthorized systems
8. Backup data regularly
Perform frequent backups of critical data and systems and test backup restoration processes regularly. Store backups securely, preferably including copies offsite, in the cloud, or both. Consider a protocol like 3-2-1, which calls for three copies of backups—two on-site on different media and one offsite. Be sure to encrypt your data during transit and storage.
UPSTACK RECOMMENDS: Backup-as-a-Service (BaaS) can automate your backups and finely tune them to your Recovery Point Objectives (RPOs) and Recovery Time Objectives (RTOs).
9. Monitor for suspicious activity
Implement robust monitoring and logging systems or services and regularly review logs and alerts for signs of unauthorized access or unusual behavior. Encourage employees to report suspicious activities or software behaviors promptly and consider AI-powered solutions like managed detection and response (MDR) that can identify anomalous behavior and eliminate or quarantine threats before they spread through your infrastructure.
10. Develop an Incident Response Plan (IRP)
Create and maintain a comprehensive incident response plan with clear containment, eradication and recovery procedures. Your plan should include:
- Who: Roles and key contacts from your internal response team, security supplier(s), IT team, appropriate members of senior management, your legal advisor(s), your human resources (HR) teams, your public relations (PR) team and your insurance companies (e.g., cyberinsurer). Have at least one backup contact available for each department.
- What: Escalation criteria and processes/flowcharts to help you categorize the scope and severity of an attack, determine the appropriate response and the parties responsible for communication, tracking and remediation. Checklists and playbooks developed in advance can deliver clarity amid chaos and speed remediation. Have a procedure in place to make decisions in situations not covered by your playbooks. Establish rules for handling system cleaning and restoration while capturing vital evidence.
- Where: Establish a conference bridge in advance (keeping in mind that, with systems down, your team may need to communicate via telephone only).
- When: Establish rules for when to engage legal, HR, PR and forensics assistance.
Regularly test and update your plan to ensure an effective response to a potential cyberattack.
Strengthen your Cybersecurity with UPSTACK
As a full-service technology advisory firm, we have experience helping customers choose cyber resilience and managed security solutions ranging from risk management to network, endpoint, cloud security and much more under a unified security umbrella that’s right-sized for your needs—and your budget.



