Recent cyberattacks on key government agencies in Barbados bring into sharp reality the fact that the fight is persistent in building a resilient cybersecure infrastructure within the public and private sectors. Indeed, the conversation and sensitisation must go beyond the month of October, commemorated annually as cybersecurity awareness month. A whole of country approach is needed to mobilise resources, adopt the right regulatory regime, and train employees and citizens alike about the existential threat of cyberattacks.
It is against this backdrop that the Small Business Association of Barbados recently partnered with C & W Business to host a webinar on Mounting a Defense against Cyberattacks, with a focus on helping micro and small businesses to build resilience in their operations to mitigate the risks of attacks.
Participants during the webinar were given a broad perspective of the issues and the solutions to be employed to safeguard their businesses.
Cybersecurity was presented as a combination of technology, people and processes to create strategies, aimed at protecting sensitive data, ensuring business continuity and safeguarding against financial losses. It is built on three pillars, people, processes and technology. These pillars help a business to create a good cybersecurity posture.
Once a business has established a digital presence, it is a target due to its population, and/or acquisition of data. DATA was described as ‘GOLD’, in this hyper-digital connected world.
Participants were informed that there were over 300 billion phishing attacks annually. An attack may cause possible financial loss, loss of reputation and even identity theft. Information over the last three years indicates a plethora of incidents in both the private sector and state agencies where valuable data was breached.
Examples include Massy’s cyberattack in April 2022 in Trinidad & Tobago and October 2022 in Jamaica. The breach resulted in 17 GB of data being leaked, which included personal information such as the names, addresses, taxpayer registration numbers, signatures, videos and pictures of Massy Jamaica employees and contractors. Attacks were recorded in Bermuda, whose Government IT department and communication system experienced a breakdown, Martinique, British Virgin Islands, St Kitts & Nevis, and St Lucia, to name a few. Right here in Barbados, several banks, credit unions, and government departments have all fallen prey to the attackers. The Caribbean is definitely seen as a hot spot for cyber criminals.
The attacks have been so pervasive that the government of Costa Rica in 2022 declared a State of Emergency after a month of crippling ransomware attacks. This was the first time in history that a State of Emergency has been declared on a non-physical event and on a cybersecurity event.
The Gartner Report September 2021 estimated that there was going to be a 12.4% increase in Cyber spend valued at $150 billion in 2021. By 2024, the spend is $215 billion globally according to the September 2023 report, an increase of 14.6%.
The C & W Business team recalled an example which demonstrated the high cost of cyberattacks on firms. The experience of a ransomware attack on an organisation revealed the following statistics:
- The organisation paid over USD$100k in incident response and recovery
- It lost 23 days of business to restore 80% of operations and did not get 100% recovery
- The attack was undetected in their systems for 12 months
- The firm paid USD$3k monthly to have the EDR, significantly less than the $100k for recovery.
The webinar also explored solutions that firms could employ in this fight. Two initial areas are EDR (Endpoint Detection & Response) and user security awareness training. EDR is an AI-driven security solution that autonomously monitors, detects, and responds to threats in real time, offering proactive protection and automated mitigation for endpoint devices. User Security Awareness Training will help to educate users to understand, identify and avoid cyber threats. The goal is to prevent or mitigate harm – to both the organisation and its stakeholders – and reduce human cyber risk.
In mounting a defense, the small business must carry out a few steps:
- KYE (Know Your Environment)
The business must know its environment – identify potential threats, critical systems, legal implications and develop response and mitigation strategies for cyber resilience. Barbadian firms should know the legal regulations that govern cybersecurity and data within a business, which are governed by the Data Protection Act 2019.
- Culture
It is important for business owners to create a cyber culture within the organisation. Creating such a culture starts from the leadership. In order to do this, business persons must communicate value, drive leadership, establish governance, implement awareness programmess, and define Key Performance Indicators for transparent reporting.
“Cybersecurity is the responsibility of every single person within an organisation,”
- Partner
The presenter posited that no one entity can do cyber security by themselves. There is a USD$3.6 million gap in cyber security skills and competences globally, and therefore, it is almost impossible to manage cybersecurity alone. Firms should partner wisely – outsource securely, stay vigilant, enhance response, augment expertise and ensure compliance.
With the digital revolution in play globally and the increased use of technology in everyday activity, the vulnerability of the firm is heightened. It is therefore incumbent on all business owners and individuals to mount their own defense and work assiduously to build resilience. Additional techniques include:
- Adopt AI Driven technologies
- Back-up of files; regularly tested
- Conduct vulnerability scans
Use two factor authentication.
