Executive Summary:
In the United States, too many small and medium sized businesses (SMBs) are vulnerable to cyberattacks because they are misinformed about the threat. They do not perceive a real threat, and they are unprepared to deter a cyber-attack or deal with the aftermath of one. How can the Small Business Administration help SMBs reduce the number of clients affected by cyberattacks?
We provide four alternatives: cyber-security education and outreach, loan guarantees, tax credits, and a two-year cybersecurity pilot program. The first option of education and outreach provides the best outcome by addressing the root cause of the vulnerability problem.
The root cause of the problem is a sense of overconfidence in the SMB community in their ability to withstand a cyberattack. In a survey of 1,015 SMBs, 90 percent do not have an internal Information Technology (IT) manager and 66 percent of owners manage their own cyber-security (National Cyber Security Alliance, 2012). At the same time, while SMBs concede they do not have an in-house expert on staff, 76 percent believe they are safe from a cyber-security breach (National Cyber Security Alliance, 2012).
How do our alternatives stack up against this pervasive knowledge gap problem? The first option would institute mandatory cyber training for two SBA programs: loan guarantees and government contracting. It would also expand outreach campaigns in coordination with other agencies. The second option would provide loan guarantees for SMBs to purchase the protection they need. The third option would provide tax credits to businesses that design solutions for SMBs rather than large corporations, thereby increasing the availability of affordable and easy to understand solutions. Finally, the fourth option would be a two-year pilot program to help one hundred SMBs identify their vulnerabilities and build a plan to protect their assets. The program would include the development of a call center to help SMBs deal with imminent threats.
We evaluated these alternatives based on three criteria: efficacy, acceptability, and simplicity/adaptability. Efficacy addresses the reduction in uninformed SMBs and a reduction in cyber-attacks. Acceptability deals with the extent to which the alternative would be acceptable to the community. The criteria of simplicity/adaptability will focus on the extent to which alternatives are easy to implement and adjust.
We determined that based on all three criteria, the education and outreach program would be the most effective in mitigating a key problem in the cybersecurity issue. It would be the easiest to implement and adjust. It would have the greatest support among the different stakeholders due to the low marginal costs it engenders. Ultimately, with limited resources, the education and outreach program produces the greatest return on investment.
Problem:
Small and medium sized businesses (SMB) are too susceptible to data theft by hackers. In a constantly changing cyber-threat environment, many SMBs do not appreciate the scale of the threat and are ill equipped to handle it.
Evidence:
A starting point for any conversation about cybersecurity is to define the threat. The threat to SMBs comes in the form of crimeware, cyber espionage, denial of service, insider misuse, and web app attacks (Verizon, 2015). The 2015 Data Breach Investigations Report published by Verizon describes these in the following manner:
| Crimeware: | A catch-all term that represents malware infections within organizations that are not associated with more specialized classification patterns. |
| Cyber Espionage | Usually involves theft of information and two-thirds of incidents do not generally have attacker-attribution information whatsoever. Mostly affects manufacturing, public, and professional industries. |
| Denial of Service | An attempt to deny user access to a web site or web application. The severity of the attack is based on bandwidth, velocity and duration. Mostly affects public, retail, and financial services. |
| Insider Misuse: | When a person with access to sensitive and valuable data abuses the access they have been entrusted with. Mostly affects public, healthcare, and financial services. |
| Web App Attacks: | Generally used by organized crime syndicates to target customer credentials in order to abuse a web application tied to a bank/bitcoin account. Mostly affects information, financial services, and public industries. |
These sophisticated cyber-attacks threaten the viability of large multi-national corporations and small businesses alike—often with smaller companies acting as vectors for attacks aimed at larger businesses. In the United States, there are over 28 million small businesses, which comprise two-thirds of new net jobs annually, and 54 percent of U.S. sales (FireEye, 2015). Of the 50 percent of SMBs that have suffered a cyber-attack, 60 percent have gone out of business (LeClair, 2015). Although it is not clear that business failure is necessarily tied directly to cyberattacks, however the data suggests there is a strong correlation. For a small business, a cyber-attack can be an existential threat that they are disproportionately vulnerable to.
Scope of Threat:
As the digital domain becomes the sphere where business is done, there is no sign of the cyber-threat abating anytime soon, instead becoming more pronounced. In 2014, 79,790 security incidents resulted in a financial loss of $400 million worldwide (Verizon, 2015). Any business which relies on the Internet to conduct their business is potentially at risk. In a cyber-attack, the attacker holds the advantage and can easily overwhelm an ill-prepared target. Even the best-prepared targets are at risk because “savvy attackers are using increased levels of deception, and in some cases, hijacking company’s own infrastructure and turning it against them” (Symantec, 2015). For example, a company may have a regularly scheduled software update, routinely done by IT, that is hijacked by an attacker and turned into a Trojan horse to affect victims from within. A small business, while not the target itself, can serve as a vector to help an attacker infiltrate a larger target. In fact, for the 70 percent of attacks for which there is a known motive, there is a secondary victim (Verizon, 2015). In these cases, an attacker can penetrate the email of a more vulnerable target through a phishing attack and then use stolen email credentials to attack better secured targets that the vulnerable business engages with. In 2009, China allegedly gained access to the blueprints for the F-35 Joint Strike Fighter, worth more than $1 trillion, by penetrating Lockheed Martin’s firewalls through a smaller sub-contractor company (Smith, 2013). Understanding the scale of the problem is essential to any business exposed to this risk in cyberspace.
SMB Perception of Threat:
There is a gap between the perception of the problem facing SMBs and the actual scale of the threat. SMBs are easier targets because they are less prepared to deter an attack. While cyber-attacks on large companies make headline news, the fact is that SMBs were the target of 60 percent of the attacks in 2013 (Aguilar, 2015). This percentage continues to grow. In a survey of 1,015 SMBs, 90 percent do not have an internal IT manager and 66 percent of owners manage their own cyber-security (National Cyber Security Alliance, 2012). At the same time, while SMBs concede they do not have an in-house expert on staff, 76 percent believe they are safe from a cyber-security breach (National Cyber Security Alliance, 2012). This illustrates the sense of overconfidence and under appreciation of the cyber-threat on the part of SMBs. There are two types of businesses that underestimate the scale the cyber threat: businesses that think they do not have anything worth stealing, and those that are simply unaware of the scale and sophistication of attacks today (FireEye, 2015). While many SMBs are not prepared for a cyber-attack, even fewer would be able to survive the financial cost of one.
Cost of Threat:
Only a minority of SMBs could potentially withstand the financial costs associated with a large cyber-attack. On average, a breach of 1,000 records can impose a cost between $52,000 and $87,000 per attack (Verizon, 2015). This figure entails the cost of legal actions, customer notification, provision of credit monitoring to customers, in addition to cost of lost business. Often, the damage is much worse. Across the entire range of detected cyber-attacks, the financial toll averages out to $3.79 million per breach (Ponemon Institute LLC, 2015). In 2012, a New York mannequin maker lost $1.2 million within a span of a few hours after “cyber criminals breached the 100-employee firm and retrieved its online banking credentials (FireEye, 2015).” Paired with other non-financial costs this can set off a chain reaction that can lead to business failure. These costs have only increased over the past several years. According to the Securities and Exchange Commission, with 75 percent of all spear-phishing scams being directed at SMBs, the costs have “increased from $525 million in 2012 to $800 million [in 2013], an increase of more than 50 percent” (Aguilar, 2015). Even if a SMB is able to bounce back from an attack and stay in business, it is more likely to suffer another attack (Aguilar, 2015). Beyond the financial cost, a company can lose the trust of its consumers and its reputation can be tarnished if it is perceived that the breach occurred because of negligence.
Alternatives:
For an organization like the Small Business Administration (SBA), the cyber-threat is a major barrier to ensuring the viability of its clients. The cyber-threat is not likely to go away anytime soon, but the SBA is in a position to help small businesses meet this challenge. There are four options to address this problem: cyber-security education and outreach, loan guarantees, tax credits, and two-year cybersecurity pilot program.
Option 1: Cyber-Security Education and Outreach
There is a substantial knowledge gap about cyber-threats that can be addressed through better education. The existing programs the SBA manages can be supplemented with a component that focuses on cyber-security. The entry point for many small businesses into SBA is when they seek financial assistance programs or when they seek to do business with the government. In the best case scenario, the SBA can become the go-to place for learning how to secure a business from cyber-threats. At the very least, cyber-awareness can become a prerequisite for doing business with the SBA. One way to do this is to make cyber-security awareness training a requirement for seeking a SBA loan guarantee or to register for government contracting. The SBA already makes clear to its clients that its requirements and practices are subject to change and so this would not be out of the realm of the SBA mandate. By doing this, the SBA would elevate cyber-security to be on par with raising capital for a business and a necessary requirement to doing business with the government.
The SBA can also partner with the Federal Bureau of Investigation and Department of Homeland Security to run cybersecurity workshops across the country. Attending one of these workshops can be a fulfillment of the newly implemented cyber-awareness requirement. This would increase attention and attendance for the workshops. For those unable to attend a workshop, the SBA can develop an online training console that requires a passing score in order to fulfill the cyber-security requirement. This training can be developed in other languages besides English to make it accessible to a greater proportion of the SBA client community. Currently, of the 59 online training modules the SBA maintains on its website, only one deals with cybersecurity. The SBA can develop more online training that deal with more than just the rudimentary basics covered in its one training module.
Option 2: Loan Guarantees
Another option is for the SBA to provide loan guarantees geared towards the implementation of cyber-security plans. Currently, the SBA has four types of loan programs: General Small Business Loans: 7(a), Microloan Program, Real Estate & Equipment Loans, and Disaster Loans. In addition to these loan programs, the SBA can implement a loan program geared to improve the cyber resiliency of its clients. The SBA would need to identify the proper use of these funds and provide guidance on available resources that would help a business address the cyber risk.
Option 3: Tax Credits
Tax credits can be provided to businesses that are interested in developing cyber-security solutions. In the current environment, adequate cybersecurity protection can be expensive and inaccessible to many SMBs. This, itself, may be a deterrent to safeguarding their IT infrastructure. The goal of these tax credits would be to create economies of scale in the cybersecurity solutions field. The incentive would be for companies that are developing solutions that are easy to understand, easy to implement, and sustainable. The combination of education, loan guarantees, and tax credits can serve as a staging point for a more robust program.
Option 4: Two-year Cyber-Security Pilot Program
A fourth option is to develop a two-year pilot program with 100 SMBs that would serve as a springboard for a more robust cybersecurity arm of the SBA. A two-year pilot program can mitigate risk and can serve as a testing ground for business leaders to interact with cyber-security experts to develop a cyber-security plan. The program begins with an audit, done by an outside contractor, to determine the vulnerability of 100 businesses that employ less than 250 people. Experts agree that any cyber-security plan must begin with the identification of the most vulnerable assets. Once vulnerabilities are identified, the next step would be to develop a plan to improve the protection of those critical vulnerabilities. Participation in the program would give a small business access to a support center designed to provide guidance on urgent matters and direct the client to the appropriate resources specific to their concerns. In sum, this program would audit a participating company, develop a cybersecurity plan to address vulnerabilities, and provide support through a call center for businesses with scant IT resources.
Criteria:
The three criteria that will be used to evaluate the viability of the above alternatives are efficacy, acceptability, and simplicity and adaptability. For efficacy, reduction in the number of cyber-attacks against SMBs per year will be the measure of success of a given alternative. For political acceptability, there needs to be “buy-in” from the SMB community and the appropriate defense and security agencies for each given alternative. For simplicity and adaptability, the baseline policy solution needs to be thorough, easy to implement and adaptable.
The audit will narrow the scope of what critical vulnerabilities need to be protected for each individual SMB. Once these vulnerabilities are identified, monetary resources can be targeted to address these problems and remedy them. A metric for determining the success of the program will be a documented reduction in the overall average of cyber-attacks against SMBs in a given time period. Observable reduction in attack rates can be seen as a sign of success for the aforementioned alternatives. Additionally, measuring the number of SMBs who utilize the tax credits to develop cyber-security solutions will also be an efficiency metric. If nobody uses the program, then the program does not work.
Due to the fact that these solutions require the cooperation of numerous federal agencies, it needs to be palatable to the various nuances and “fiefdoms” of each individual agency. Especially for an agency like the Department of Commerce, which typically does not interact with the Departments of Justice and Homeland Security, these interactions will have to be centered on an accepted common goal with mutual benefits. Additionally, SMBs will need to be encouraged to believe that, despite a perception of government interference, the individuals conducting the audits are knowledgeable on the subject material and serve in an advisory role only.
The program’s robustness and improvability will need to be measured by qualitative measures, rather than quantitative. The full scope of the problem needs to be addressed by each alternative; to include readily identified vulnerabilities, simplicity of strategy, and efficacy of tools developed to prevent cyber-attacks. Furthermore, many of the SMB owners are not experts in cyber-security. Therefore, the education program needs to be as simple and easy to use as possible in order to ensure the greatest percentage of involvement from SMBs. Finally, the program needs to be able to change with the rapidly advancing cyber-threats. Active preventative systems and updated cyber-security protocols will make the difference between an SMB being protected or being vulnerable to attack.
Outcomes:
Given that the cyber-threat is constantly evolving, it is difficult to predict the future outcomes of any initiative that is implemented by the SBA. Ultimately, in our analysis of potential outcomes we will determine if each option we propose is sufficiently likely to produce results that outweigh the costs associated with implementation. To do this, we will determine the relative costs and weigh those against potential benefits. Additionally, the outcomes will be measured by the criteria set forth in the previous section: efficacy, acceptability, and simplicity and adaptability.
Option 1: Cyber-Security Education and Outreach
The outcome of cybersecurity education and outreach will be a reduction in the knowledge gap of the SMB community about the cybersecurity threat. The plan would make cybersecurity training a requirement for seeking a SBA loan guarantee and to register for government contracting. Beyond this, it would expand training events across the country in tandem with other government agencies. There is no other way to increase cyber awareness than to increase the availability of accurate and reliable information and training.
Making cyber awareness training a requirement for loan guarantees and to register for government contracting will reduce the number of SMBs that are not well-informed about cyber-threats. The benefits of making this a requirement outweighs the costs of enforcement. In terms of risk, this option is the least risk-averse of the options outlined. The SBA makes $10 billion in loan guarantees each year to thousands of SMBs. This requirement would be a catch-all effort that would help ensure that these guarantees are safeguarded against the business risk that comes with being vulnerable to cyber-attacks. We expect this training requirement to close the knowledge gap among all businesses seeking new loan guarantees and government contracts.
In terms of simplicity and adaptability, we predict this program will be both accessible to the relevant population and adaptable to the ever-changing threat landscape. There is no current program comparable to the one we are proposing and the likelihood of reducing the knowledge gap without additional training and education is low. It is not likely that this new requirement will be seen as an insurmountable burden that would drive small businesses away from the SBA.
One assumption we have made in our analysis of outcomes for education and outreach is that increased availability of information will lead to a reduction in ignorance of the problem. Another assumption we have made is that cyberattacks will be reduced because better informed SMBs will take action to protect their assets. If neither of these assumptions turns out to be accurate, then the outlined outcomes will be reduced or negated. However, it is not likely that even if those two assumptions are incorrect that the problem will get worse by implementing this program.
Option 2: Loan Guarantees
The intent of new loan guarantees for cyber protection is to help SMBs afford the cyber protection they will need for their business. Whereas the education and outreach program addresses the knowledge gap, this program addresses the action that SMBs need to take to protect their assets. The outcome of this program will be the reduction in SBA-affiliated businesses that are vulnerable to cyber-attacks. This program could be targeted towards SMBs that understand the scope of the threat but are ill-prepared to put up the money to protect their business.
Our outcome is based on the assumption that businesses do not implement effective cyber security protection because they cannot afford it. If there are other reasons SMBs do not protect their assets, this program would not be as effective as we project. This program would only cover the businesses that seek these loan guarantees on a voluntary basis; the assumption is that businesses that are well-informed but under-resourced will seek these loans.
Option 3: Tax Credits to Boost Cyber-Security Solutions
Tax credits will provide an incentive for companies that are developing new cyber solutions geared towards small businesses. The outcome will be an increase in the availability of cybersecurity solutions that are affordable for SMBs to implement. There is currently a deficit of scalable solutions and the focus of many cybersecurity firms is the development of solutions for the government and large corporations. We do not anticipate a scenario where the introduction of these tax credits will lead to a reduction in the availability of cyber solutions for SMBs. Another outcome would be more competition in a market that is dominated by big firms. The ultimate goal is that SMBs will seek these solutions and that will lead to increased protection not just among SBA-affiliated SMBs but among all SMBs in the country.
Option 4: Two-year Cyber-Security Pilot Program
The outcome of the two-year pilot program will be an increase in the cyber resiliency of the 100 SMBs that volunteer for the program. Beyond this, another outcome will be development of best practices that could be useful for SMBs that do not participate in the program. The pilot program could help determine the viability of expanding aspects of this program, such as the cyber problems call center, beyond the two-year period. Of the four options, this program will impose the most costs and will be the most difficult to implement. However, it is the option with the highest potential returns on investment in the long-term if it serves as a framework for an increased role for SBA in the cybersecurity domain. Developing a call center for cybersecurity concerns will help SMBs without in-house IT expertise to deal with potential data theft operations—potentially beyond the trial period.
It may not prove to be the most cost-effective option or the option that helps the most SMBs in the short-term. One assumption we are making is that SMBs will want to participate in this program because they understand the risks associated with not having an adequate cybersecurity plan. Another assumption is that the SBA is ready to take on a more robust cybersecurity program beyond providing loans, tax credits, and education. Ultimately, developing such a program is not likely to make the problem of cybersecurity worse for SMBs even if the benefits are not as pronounced as we anticipate.
Trade-offs:
| Policy Option | Efficacy | Acceptability | Simplicity + Adaptability |
| Option 1: Education and Outreach | Will impact all SMBs who seek SBA loan guarantees + gov’t contracting | It imposes a new barrier to entry for SMBs into SBA | Training is easy to implement + adaptable to new problems |
| Option 2: Loan Guarantees | Will impact all SMBs who seek SBA loan guarantees for cyber | It will cost the SBA money to enact loan program | Moderately difficult to implement + not easily adaptable |
| Options 3: Tax Credits | Will impact all SMBs in the country | Will need to get through congress | Difficult to implement + not flexible |
| Option 4: 2yr Pilot Program | Will impact 100 participant SMBs | Adds a layer of bureaucracy | Difficult to implement+ adaptable |
We will examine the trade-offs across the outcomes produced by each alternative and not the alternatives themselves. To define the outcomes: Option one would reduce the knowledge gap about cybersecurity among SBA-affiliated SMBs. Option two would increase the number of businesses protected against cyber threats. Option three would make cyber solutions more widely available and more affordable. Option four would develop the SBA infrastructure to deal with cyber issues and would protect the 100 participant SMBs from data theft.
The outcomes cannot be examined without first detailing the potential magnitude of the outcomes across the different options. There are 28 million SMBs in the country— defining an SMB as a business employing less than 500 people. Yet, not all of those SMBs will necessarily ever come in contact with the SBA or seek SBA loan guarantees and/or government contracts. Clearly, the SBA would want to reach the greatest number of businesses possible with their initiatives, but the impact of each option on the SMB population varies from option to option. The option with the potential for greatest impact is the tax credit option because its outcome would not be tied to involvement with the SBA. The option that would address the least number of SMBs is the 2 year pilot program because it would only directly affect 100 SMBs from the onset. The education and outreach option along with the loan guarantee option will affect SMBs that choose to interact with the SBA through these or other programs. The tradeoff in numbers affected by each number is easily quantifiable and at first glance the tax credit may appear to be the best option. However, there as other considerations that need to be addressed before a decision is made based on the metric of efficacy.
The SBA will need to determine which leg of the problem it will seek to address with its limited resources. The first problem is the issue of misinformation or lack of understanding that SMBs have about the cyber threat; we refer to this as the knowledge gap. The second problem is the vulnerability of small businesses to hackers because they do not have appropriate or effective protection. One assumption we have made in this proposal is that reducing the knowledge gap will lead to businesses taking more initiative to protect their assets, thereby reducing their vulnerability to cyber-attacks. To this end, the option that best addresses the problem of the knowledge gap is the education and outreach program but it comes at the expense of addressing the lack of protection problem. Likewise, the option that best addresses the lack of protection problem is the loan guarantee program but it comes at the expense of educating a greater number of SMBs about the threats in cyberspace.
In terms of lowest marginal costs, the education and outreach campaign is the least expensive option. There is a fixed cost to developing the training modules and education materials, but once these modules are developed the cost of educating each extra business unit is low. By contrast, the two-year pilot program would have the highest marginal cost in the protection of each extra business unit from 1 to 100. In short-term versus long-term projections, the first option provides the greatest return on investment in the short term and the fourth option could provide the greatest return on investment in the long-term. The tax credit option would also provide its greatest returns in the long-term rather than short-term because it is necessarily a market solution whose success depends on a variety of factors.
If we consider the status-quo as a baseline option, then all four options are likely to improve the problem of cybersecurity. At the very least, none of the options would potentially make the situation worse. The determination that ultimately needs to be made is what part of the problem the SBA should aim to mitigate or resolve. The SBA is best structured to implement options one and two without it having a detrimental effect on its budget or other fundamental responsibilities. Coincidentally, options one and two aim to mitigate the problem posed at the beginning: the knowledge gap and unpreparedness of SMBs to deal with the threat. Option three seeks an outcome that is related to the central problem but does not confront it head-on. Option four aims to be a holistic approach but would come up short in having the greatest effect among a greater number of businesses when compared to other options.
Decision:
The education and outreach program is the best option for the SBA to pursue. This option addresses a key part of the problem: lack of knowledge about cyber threats. Given that the mission of the SBA is to advise SMBs rather than solve their problems, this option addresses a key problem in a way that is within the scope of SBA’s mandate. In terms of numbers, the SBA would be able to maximize the impact on the greatest number of SMBs with this option. It would come at a cost of not dealing with the issue of ill-preparedness by SMBs. However, if we consider that SMBs are ill-prepared because they do not understand the scope of the threat, then a logical conclusion would be that SMBs would take steps to protect their business once they are educated about the threat. The SBA is not currently structured to do more than serve as an advisory body and loan guarantor for SMBs. Ultimately, this option will provide the greatest return on investment and requires a lower level of investment than other options.
Our Story:
Small businesses face a bigger threat to the security of their assets and customers’ data than they imagine. It is easy for the media to latch on to stories that will capture the most attention, such as the hacking of Sony or Target. We constantly hear about the cyber threat against the US government from state actors such as China, North Korea, and Russia. While those threats are important to address, such a focus on strategic threats leaves a bigger section of the economy vulnerable. The owner of a local coffee shop may not consider that they have anything worth stealing when compared to the likes of corporations like Best Buy or Northrop Grumman. But the fact of the matter is over 60 percent of the cyber threat is aimed at those small businesses least prepared for it. They are easier to penetrate and therefore more frequently targeted. This is a problem that will not go away and the status quo is not sustainable.
The SBA is in a position to help mitigate the risk posed to small businesses by hackers and cyber-thieves. Whereas big businesses have the capability to seek out the best cyber firms in the business to protect their assets and respond to threats, small businesses often have no idea where to even start. This is where the SBA can make a difference. The same way they advise SMBs on the basics of raising capital and getting government contracts, the SBA can also become a source for reliable information and training about the threat these cyber criminals pose. The interconnectivity of world markets will only increase and as the streamlining of new technologies gains momentum, it is time for the SBA to consider taking a leadership role in addressing a pervasive cyber threat.
What we propose is a simple solution to a big part of the problem, which we consider to be the misunderstanding and underestimation of the threat by small businesses. It is true that SBA cannot solve the problems of all of its clients, but it can help identify the tools required to better protect their assets. By increasing training, and making it a requirement for certain programs, the SBA will begin to narrow the gap in knowledge. If a training module can convince even one independent book store owner to protect their data, the program will have succeeded. People are more likely to act on information if they hear it first-hand from someone they know than if they hear it on some TV or internet ad. That is why outreach is also an important aspect of the program we proposed.
The SBA does not need to reinvent itself to help its clients meet this challenge. It can take something the SBA already does well—educating and identifying resources for its SMB clients—and integrate our proposed program into its already well-established functions. The organization may meet some resistance in trying to implement this program from curmudgeons who never agree on anything, but we anticipate it will be well received. The hope is that small business owners will take action on the information before it is too late.
Bibliography
Aguilar, L. (2015, August 19). The Need for Greater Focus on the Cybersecurity Challenges Facing Small and Midsize Businesses. Securities and Exchange Commision. Retrieved from http://search.proquest.com/docview/1726742415?accountid=14541
FireEye. (n.d.). Not Too Small to Matter: Five Reasons Why SMBs are a Prime Target for Cyber Attacks (pp. 1–11). Retrieved from https://www2.fireeye.com/WEB-WP-Not-Too-Small-To-Matter_LP.html
LeClair, J. Small Business, Big Threat: Protecting Small Businesses from Cyber Attacks., § House Small Business Committee (2015). U.S. House of Representatives: Federal Information & News Dispatch, Inc. Retrieved from http://smbiz.house.gov/UploadedFiles/4-22-2015__Dr.__LeClair__testimony.pdf
National Cyber Security Alliance. (2012). 2012 NCSA/Symantec National Small Business Study (pp. 1–18).
Ponemon Institute LLC. (2015). 2015 Cost of Data Breach Study: Global Analysis (pp. 1–31).
Smith, D. (2013, June 24). Cybercrooks target SMBs with new types of attacks; Ransomware, mobile malware and brute-force attacks aimed at small business are on the rise. Network World.
Symantec. (2015). ISTR 20 Internet Security Threat Report (No. 20).
Verizon. (n.d.). 2015 Data Breach Investigations Report (pp. 1–70). Retrieved from http://www.verizonenterprise.com/DBIR/2015/
Wiley, A. (n.d.). Cyber security conference helps protect. Times West Virginian. Fairmont. Retrieved from http://www.timeswv.com

Leave a comment