Cyber insurance may help defray certain breach-related costs, but that doesn’t stop attacks.
Controlling access to your systems, updating security patches and account security, limiting the amount of data you store, and practicing data backups and breach-response scenarios—all of these steps can help reduce both the likelihood of a data breach and the overall impact if one were to occur.
Here are some of the topics our editorial team touched on while researching the Canadian Centre for Cyber Security’s baseline controls for small and medium organizations, the Office of the Privacy Commissioner of Canada’s breach-prevention guide, the Privacy Commissioner’s PIPEDA breach-reporting guide, and the Insurance Bureau of Canada’s analysis of small-business cyber-attack costs.
How Can a Small Business Prevent a Data Breach?
- Identify and document all of your accounts, systems, data and third-party vendors.
- Implement multi-factor authentication for important accounts.
- Promptly apply security patches and updates.
- Remove unnecessary permissions on accounts and systems.
- Encrypt sensitive information.
- Maintain offline or isolated backups and ensure that you can restore them.
- Assign a program owner who’s responsible for driving these actions, and make sure everyone understands their roles and responsibilities in the event of an incident.
While implementing these actions won’t necessarily protect you from being breached, the Canadian Centre for Cyber Security encourages businesses to plan on the assumption that a cyber incident will occur. Have a plan to help you identify, respond and recover from a cyber incident.
Why Small Businesses Face Material Cyber Risk
Despite their size, many small businesses have sensitive information, such as payment, supplier, employee and customer data, that is of interest to attackers looking to conduct fraud or perform extortion. Business size is not a security control.
Practical security is about limiting the most obvious avenues for intrusion and limiting the level of access an attacker can achieve with a compromised account.
Preventing a Data Breach: What You Can Do Today
| Priority | Action | Evidence or test |
|---|---|---|
| 1. Know the environment | List all hardware, software, cloud services/platforms, accounts, sensitive information, and third-party providers/vendors. | Each item in the inventory has an owner. |
| 2. Protect accounts | Use multi-factor authentication, have different passwords, and separate accounts for admin tasks. | MFA report and list of privileged users |
| 3. Patch and configure | Enable updates. Get rid of unsupported software. Change the software’s default configuration. | Patch status and exceptions with deadlines |
| 4. Limit access | Give each person only the access needed and disable access promptly after a role change. | Access review/ offboarding log |
| 5. Protect data | Minimize data collection; define retention rules and apply them to data you keep; encrypt sensitive data stored on portable media. | Data map, deletion record and encryption status |
| 6. Back up and restore | Keep an isolated/offline backup copy, and backups should always be encrypted. | Restore test successfully restored a critical system. |
| 7. Secure vendors | Make sure there are contractual obligations for data security, access rights and procedures for notification of any security breach. | Vendor list, assurance documents and contact paths |
| 8. Train and rehearse | Include instructions about how to report an incident. Carry out response drills. Keep a hard-copied response plan available. | Attendance, exercise findings and closed actions |
Read More: Use the Business Cyber-Attack Protection Guide
Consider Cyber Insurance
Consider exclusions or sublimits that may apply, waiting periods, deductibles, notice requirements, mandatory security conditions and other coverage conditions.
Ask about first-party coverage for cyber-event response, including business interruption, data restoration, extortion, privacy liability, regulatory coverage and third-party coverage for a vendor incident.
Read More: Explore Cyber Liability Insurance
Potential Costs of a Data Breach
Direct Financial Costs
Possible costs include investigation, containment, system reconstruction, data recovery, customer service, notifications, credit monitoring, legal support and additional staff.
Costs will depend on the type of systems and data involved and the length of outage.
Legal and Regulatory Costs
Seek advice on applicable laws based on the specific facts. Depending on the situation, provincial privacy, workplace, health laws or contractual obligations may also apply.
If PIPEDA applies and the breach represents a real risk of significant harm, the Privacy Commissioner and affected people must be notified. Businesses subject to PIPEDA must also keep a record of all breaches.
Reputation and Customer Loss
It can be difficult to predict the repercussions for trust.
Do not make statements indicating stolen data has been destroyed or is being maintained securely unless you have evidence.
Operational Disruption
What are the bare minimum services your business needs to get by? Have plans in place to deal with losing access to any of the following:
- payment;
- scheduling;
- email;
- production; and
- customer information.
What to Do When You Discover a Possible Breach
- Use the response plan. Contact the named technical, privacy, legal and insurance resources.
- Contain affected accounts or systems without destroying logs, messages, devices or other evidence.
- Record what happened, when you found it, the systems and information involved, and every containment decision.
- Assess harm and reporting duties under the law that applies. Use the Privacy Commissioner’s risk-assessment tool if PIPEDA applies.
- Notify the insurer within the contract’s deadline and obtain consent before incurring costs if the policy requires it.
- Restore from known-good sources, monitor for recurrence and document the changes made after the incident.
Read More: Read About Growing Cyber Threats and Cyber Insurance