Featured Product
This Week in Quality Digest Live
Management Features
Jason Chester
Exploring essentials to manufacturers’ present and future success
Harish Jose
A quest for ultimate efficiency
Chuck Olinger
Many requirements for quality management can be met through advanced ERP software
Suneel Kumar
Leveraging the strengths of your team members
Knowledge at Wharton
10 rules help you approach conflicts with a methodical strategy for resolving problems

More Features

Management News
Morse has a long history with the center, both as a faculty researcher and for serving as the center's deputy director since 2010
Siemens introduces PCBflow, a secure, cloud-based solution for accelerating design-to-manufacturing handoff for printed circuit boards
Includes global overview and new additive manufacturing section
Tech aggravation can lead to issues with employee engagement, customer experience, and business results
Harnessing the forces that drive your organizations success
Free education source for global medical device community
New standard for safe generator use created by the industry’s own PGMA with the assistance of industry experts
Provides synchronization, compliance, traceability, and transparency within processes
Galileo’s Telescope describes how to measure success at the top of the organization, translate down to every level of supervision

More News

NIST

Management

NIST Guide Helps Small Businesses Improve Cybersecurity

Explains basic steps businesses can take to better protect their information systems

Published: Wednesday, November 30, 2016 - 18:45

(NIST: Gaithersburg, MD) -- Small-business owners may think that they are too small to be victims of cyber-hackers, but Pat Toth knows otherwise. Toth leads outreach efforts to small businesses on cybersecurity at the National Institute of Standards and Technology (NIST) and understands the challenges these businesses face in protecting their data and systems.

“Businesses of all sizes face potential risks when operating online and therefore need to consider their cybersecurity,” she says. “Small businesses may even be seen as easy targets to get into bigger businesses through the supply chain or payment portals.”

Toth is the lead author of NIST’s Small Business Information Security: The Fundamentals. The guide is written for small-business owners not experienced in cybersecurity and explains basic steps they can take to better protect their information systems.

“Many small businesses think that cybersecurity is too expensive or difficult; Small Business Information Security is designed for them,” says Toth. “In fact, they may have more to lose than a larger organization because cybersecurity events can be costly and threaten their survival.” The National Cyber Security Alliance found that 60 percent of small companies close down within the six months following a cyber attack.

The new NIST publication walks users through a simple risk assessment to understand their vulnerabilities. Worksheets help them to identify the information they store and use, determine its value, and evaluate the risk to the business and customers if its confidentiality, integrity, or availability were compromised.

The guide is based on NIST’s Framework for Improving Critical Infrastructure Cybersecurity, which was issued in 2014 as part of efforts to protect the nation’s critical infrastructure. The framework’s processes and tools provide key standards and best practices developed over decades by the federal government and industry. Its simple language allows organizations to better communicate, and its overall design helps them identify, assess, and manage cybersecurity risks.

For example, the new guide describes how to:
• Limit employee access to data and information
• Train employees about information security
• Create policy and procedures for information security
• Encrypt data
• Install web and email filters
• Patch, or update, operating systems and applications

Other recommendations may require new equipment, and the guide can help businesses perform cost/benefit analyses. “We recommend backing up data through a cloud-service provider or a removable hard drive and keeping the backup away from your office, so if there is a fire, your data will be safe,” says Toth. And a backup can be used to restore data in case a computer breaks or malware infects a system.

The guide also suggests:
• Installing surge protectors and uninterruptible power supplies to allow employees to continue to work through power outages and to save data
• Considering the purchase of cybersecurity insurance
• Ways to find reputable cybersecurity contractors

NIST has been in the business of helping small businesses with information security since 2001, when it joined forces with the U.S. Small Business Administration and the Federal Bureau of Investigation’s InfraGard program to provide introductory cybersecurity workshops to small businesses. 

Discuss

About The Author

NIST’s picture

NIST

Founded in 1901, The National Institute of Standards and Technology (NIST) is a nonregulatory federal agency within the U.S. Department of Commerce. Headquartered in Gaithersburg, Maryland, NIST’s mission is to promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and improve our quality of life.