Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« IRS Struggles with Security Issues | Main | Digital Device Malware »

How SMBs Can Improve Security

Last week I commented on a survey by GFI Software on SMB security and this week I had a chance to dig into more details with David Kelleher a research analyst at GFI. One of the things that struck me about the survey results was an apparent disconnect between the high number of respondents who said their budget was sufficient and the low number who felt their networks were secure. If the network aren't secure, shouldn't they be looking for more money to lock them down? Not necessarily.

Those responsible for security in SMBs may think they have enough with anti-virus and anti-spam filters. There isn't enough awareness about other security measures, like content filters and IPS.

The second reason is that a big problem for SMB security is user awareness. These businesses don't need more software or appliances, they need to get their staff trained on basic security awareness and company policies. (That is if they have formal policies).

David Kelleher noted that SMBs that may not have dedicated IT staffs could take advantage of resellers and channel partners. They build their business around the needs of small companies and the desire of big companies to move product. Sure there are some risks, a channel partner is going to have a built in bias toward products they resell. Comparative reviews from trade journals like NetworkWorld can help SMBs avoid the really poor products. More importantly the resellers can help SMBs understand the bigger security picture that too many seem to be missing.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/591

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net