Educating your shareholders on cyber attacks

Technology Pointers

For small business owners, it may seem your daily energy is caught up with just keeping the doors open and revenues coming in. However, unless you were very fortunate when you started up, you have a board of directors; most likely initial investors whose focus is on the long- term success of the company and on strategies for future growth. Part of their concern will be threats and risks to the present business. A particular concern may be the risks to the business in the case of a cyber attack. Small businesses are just as vulnerable to cyber attacks as large companies. However, they are far less likely to have the resources to recover. Let’s talk about the areas at risk when a cyber attack occurs.

Downtime

This is the most obvious and immediate consequence of a cyber attack. Your business becomes partially or fully shutdown. Given our reliance on technology, almost every aspect of a business, even a small service business is, in some way, reliant on technology. For example, a medical office can’t function if its reservation system is attacked. Staff may lose the basic ability to know which patients are scheduled for the day. A smaller retailer can’t ring sales if the point of sale goes down. If your website is attacked and compromised, that’s akin to shutting down the doors of a brick-and-mortar operation.

Data loss

Unless their goal is pure mischief, most cyber thieves are seeking data that can be monetized in some fashion. Customer data is a rich trove of data, providing thieves with the information to steal identities or hack bank accounts and credit cards. Only, they don’t just want your customer’s data. Your business has its own proprietary and financial information. You have company credit cards and bank accounts.

Legal

Should you suffer a significant loss of customer data, you may be subject to legal regulations. At the very least, you are likely required to notify the victims and the state or legal entity that regulates data loss in your jurisdiction or industry sector. For example, HIPAA has reporting requirements. Beyond reporting requirements, there may be financial penalties that can be imposed for significant data loss, especially if it could have been avoided via stricter internal controls. Again, HIPAA is an excellent example. California now has data regulations and the European Union (EU) imposes severe penalties for data loss that impacts any resident of the EU, even if the violator is not located within its geographic boundaries.

Brand damage and reputational loss

If your company is the victim of a cyberattack, you will need to inform any customer whose data may have been compromised. This will definitely not endear you to your clients. If word gets out, this can damage your ability to attract and convert new prospects into customers. This issue of brand damage could likely be the most severe, long-term risk to the success of the business. Adding to this is the competitive disadvantage in which it places you. Competing firms may use an event like this to highlight their own improved ability to protect customer data.

It isn’t just you — supply chains issues

One last area that you will need to advise your board about is your vulnerability to your supplier’s risks. Just as you can be attacked, so can every business and agent along the entire supply chain that feeds your business. As the pandemic has shown, supply chain issues can be serious and an internal disruption. U.S. vehicle production has been severely inhibited due to the unavailability of computer chips. If a major U.S. automaker such as Ford can be hurt, what about a small business like yours? Every business should address the plans of its suppliers to handle a cyber attack and have plans in place for alternative sources of inventory.

In summary, it is important that you outline to your board their areas of vulnerability. Without this information, you and they cannot make the strategic and tactical plans to protect the business in the case of a cyber attack. Keep your business booming this summer and enjoy some fireworks, too.

About Peter Johns 11 Articles
Peter Johns is a licensed insurance agent and risk advisor with Sparkman Insurance 7 Financial Services. He was formerly with Empower Information Systems, Inc.