{"id":705,"date":"2021-10-19T14:56:17","date_gmt":"2021-10-19T19:56:17","guid":{"rendered":"https:\/\/cmitsolutions.com\/boston-ma-1089\/?p=705"},"modified":"2023-03-23T23:25:53","modified_gmt":"2023-03-24T04:25:53","slug":"where-to-start-the-cybersecurity-risk-assessment-2","status":"publish","type":"post","link":"https:\/\/cmitsolutions.com\/boston-ma-1089\/blog\/where-to-start-the-cybersecurity-risk-assessment-2\/","title":{"rendered":"Where To Start &#8211; The Cybersecurity Risk Assessment"},"content":{"rendered":"<h2><\/h2>\n<h1><strong>Where To Start &#8211; The Cybersecurity Risk Assessment<\/strong><\/h1>\n<p>Is your business safe? Our clients ask themselves this question every day. In the last year alone, we\u2019ve seen a major increase in cybersecurity questions. Everyone wants a quick way to find out. Many put off worrying until there is a real problem. While October is <a href=\"https:\/\/staysafeonline.org\/cybersecurity-awareness-month\/\"><span style=\"color: #000080;\">Cybersecurity Awareness Month<\/span><\/a> and we\u2019re pushing as much education awareness as possible, business owners are still confused about whether or not cyber attacks are a real threat.<\/p>\n<p>An estimated 71% of all cyber-attacks are against small businesses and after an attack, 60% of them will be out of business in six months. In addition to this, there was a 424% increase in attacks in 2021. Why is this important? Smaller businesses are easier targets for cyber criminals.<\/p>\n<p>For <span style=\"color: #000080;\"><a style=\"color: #000080;\" title=\"Why SMBs Should Invest In Cyber Security\" href=\"https:\/\/cmitsolutions.com\/boston-ma-1089\/why-smbs-should-invest-in-cyber-security-2\/\">businesses just starting out with cybersecurity<\/a><\/span>, we recommend taking a risk assessment that takes into consideration: 1) the size and complexity of your business and 2) whether or not your business is subject to regulatory constraints. There is an art to right-sizing security assessments for SMBs and we understand that delicate balance.<\/p>\n<h3><strong>Why Are Risk Assessments Important?<\/strong><\/h3>\n<p>Cyber threats are a serious issue for businesses today \u2013 no matter the size. Many smaller companies do not have the appropriate safeguards or policies and procedures in place.\u00a0Other businesses may feel they have implemented the proper standards when in reality they are still at risk.\u00a0A Cybersecurity Risk Assessment will help identify the areas that your company needs to improve and recommend the proper security actions to implement. Simply started, we find your security holes and plug them.<\/p>\n<h3><strong>The Risk Assessment Process<\/strong><\/h3>\n<p>To begin the process, our cybersecurity experts will schedule a 30-minute consultation to complete an initial cybersecurity questionnaire about your business. The answers to this questionnaire generates a matrix highlighting your security needs into four quadrants: Administrative Safeguards, Physical Safeguards, Technical Safeguards and Organizational Requirements.<\/p>\n<p>If the business is in a non-regulated industry, the generated matrix will be reviewed in concurrence with running the Full Network Detective Security Diagnostic. If the business is in a regulated industry, the generated matrix will be reviewed in conjunction with running the Full Network Detective Security Diagnostic. In addition, HIPAA, PCI DSS, FINRA and NIST diagnostic modules will be added for the relating industries.<\/p>\n<p>Our matrix identifies the following four areas where your business may need to improve security:<\/p>\n<p><span style=\"color: #ff0000;\"><strong><img decoding=\"async\" class=\"size-full wp-image-706 alignleft\" src=\"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-content\/uploads\/sites\/100\/2023\/03\/virus.png\" alt=\"\" width=\"150\" height=\"150\" \/>ADMINISTRATIVE SAFEGUARDS<\/strong><\/span>\u00a0 |\u00a0 This identifies potential threats, risks, and vulnerabilities with your data. It also ensures that you protect the confidentiality, integrity, and availability of the data you create, receive, maintain, or transmit. In addition, it outlines how you manage user access to data and train workforce members to protect confidential data. Lastly, it clarifies what policies and procedures are used to monitor login attempts.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"color: #ff0000;\"><img decoding=\"async\" class=\"size-full wp-image-707 alignleft\" src=\"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-content\/uploads\/sites\/100\/2023\/03\/danger.png\" alt=\"\" width=\"150\" height=\"150\" \/>PHYSICAL SAFEGUARDS<\/span><\/strong>\u00a0 |\u00a0 This evaluates the disaster recovery procedures and emergency operations plans you currently have in place. It will also assist in identifying how you grant access to your office, your systems and your data, as well as how you inventory all systems with access to data. Assessing the maintenance and protection of passwords is also covered.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"color: #ff0000;\"><img decoding=\"async\" class=\"size-full wp-image-708 alignleft\" src=\"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-content\/uploads\/sites\/100\/2023\/03\/technical.png\" alt=\"\" width=\"150\" height=\"150\" \/>TECHNICAL SAFEGUARDS<\/span><\/strong>\u00a0 |\u00a0 This ensures correct technology policies and procedures are implemented. It will look at the current framework for how access is granted to hardware\/software systems and data. It also reviews the company password policies, details how inactive sessions are closed, and assess how data is protected from alteration or destruction.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"color: #ff0000;\"><img decoding=\"async\" class=\"size-full wp-image-709 alignleft\" src=\"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-content\/uploads\/sites\/100\/2023\/03\/contract.png\" alt=\"\" width=\"150\" height=\"150\" \/>ORGANIZATIONAL REQUIREMENTS<\/span><\/strong>\u00a0 |\u00a0 This evaluates how your business partners protect the privacy and security of confidential data and how data breaches are handled. Contractual provisions are reviewed to ensure business partners protect the privacy and security of data. It also ensures that records are kept to document adherences to contractual provisions.<\/p>\n<h3><\/h3>\n<h3><strong>Post Risk Assessment<\/strong><\/h3>\n<p>Once you pull back the curtain on cybersecurity and understand how your small business is vulnerable, you can take the necessary steps safeguard it. First and foremost, find and work with a dependable, competent Managed Service Provider (MSP). Ensure the provider delivers core security services, including Patch and Vulnerability Management, Identity Management and has a Deep Understanding of Network Security. Establish policies and processes for managing compliance areas applicable to your business and employ user on and off boarding at a minimum. Last but not least, train or hire staff knowledgeable in security and compliance disciplines. These cybersecurity best practices will go a long way to keeping your business protected. Don\u2019t forget that we\u2019re always here to help. Reach out to begin your cybersecurity assessment today.<\/p>\n<p>Stay tuned each week in October as we\u2019ll post a new blog for Cybersecurity Awareness Month.<\/p>\n<p>Written by: <a title=\"About\" href=\"https:\/\/cmitsolutions.com\/boston-ma-1089\/about\/\"><span style=\"color: #000080;\">Chris Zambuto<\/span><\/a> | Chief Information Security Officer <span style=\"color: #000080;\"><a style=\"color: #000080;\" href=\"https:\/\/www.facebook.com\/CMITBostonCambridge\/\">@<\/a><\/span><a href=\"https:\/\/www.facebook.com\/CMITBostonCambridge\/\"><span style=\"color: #000080;\">CMITBostonCambridge<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Where To Start &#8211; The Cybersecurity Risk Assessment Is your business safe?&#8230;<\/p>\n","protected":false},"author":259,"featured_media":635,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[],"class_list":["post-705","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blog"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/posts\/705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/users\/259"}],"replies":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/comments?post=705"}],"version-history":[{"count":0,"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/posts\/705\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/media\/635"}],"wp:attachment":[{"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/media?parent=705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/categories?post=705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1089\/wp-json\/wp\/v2\/tags?post=705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}