A primer to cyber security training for SMBs

A primer to cyber security training for SMBs

Empower your SMB team with effective cybersecurity training with this started guide and protect your business together as a team.

5 Mins

2nd April 2024

Article

SMB, Cyber security, Digitalisation, Business Launch & Operations

Key takeaways

To help protect SMBs against cyber attacks, it is critical to train employees and defend together as a team
Training should cover basic online security concepts, including strong passwords, safe browsing, and email security
Interactive sessions and real-world phishing scenarios can make the learning more effective
Ongoing education in cyber security is key for employees, and SMBs can access various courses to help them continue their learning

Cyber security is already a necessity for businesses, including and especially small and medium-sized businesses (SMBs). Not only is the frequency of attacks increasing at an alarming rate, but the level of sophistication of the attacks is also rising. Phishing attempts, malware threats and even online scams have caused serious damage to SMBs recently. According to the Cyber Security Agency of Singapore (CSA), there were 132 reported ransomware incidents in 2022, with SMBs most impacted by such attacks, particularly those in manufacturing and retail. Phishing attacks are also on the rise, with 8,500 reported incidents in 2022, compared to 3,100 in 2021.

 

Are you prepared to defend your business against this rising tide of cyber threats? According to a recent survey across the U.S., Germany, U.K., and Singapore, only 22 percent of SMBs surveyed felt adequately prepared for a cyberattack.

 

As such, it's crucial to educate your team on cyber security. Follow these steps to help train your employees so they can help defend your business against cyberthreats in the future. 

 

Start with the basics of online security

There are some foundational aspects that every employee should be aware of today. These form the backbone of good security practices and are not complicated to follow.

 

Use strong passwords: Emphasise the importance of creating and maintaining strong, unique passwords. Encourage the use of password management tools for added security.
Follow safe browsing practices: Educate employees on safe browsing habits, including the avoidance of suspicious websites and the use of secure connections (HTTPS). Highlight the risks associated with downloading files from untrusted sources.
Pay attention to email security: Train your team to recognise common email security threats, such as phishing attempts and suspicious attachments. Stress the importance of verifying the legitimacy of email senders before clicking on links or downloading attachments.

 

Make the training interactive

Passive learning may not be sufficient for the average employee to be able to take action during an actual cyber security incident in real life. This is where hands-on, interactive training sessions can help to reinforce their understanding and application of cyber security principles.

 

To provide interactive learning sessions, test your employees with situations that mimic real-life cyber threats. For example, you could simulate situations where employees must identify and respond to potential security risks, while in the midst of a major seasonal event that brings in a lot of traffic, such as Black Friday.

 

Interactive workshops can also help in this regard, where case studies, group discussions, and practical exercises can be used to deepen employees' understanding of cyber security concepts. To conduct these workshops, you could either invite a cyber security expert or engage an external agency to organise sessions on a recurring basis. Singtel’s Cyber-Readiness and Training Services, offers life-like drills to prepare IT teams for today’s cyber security threats and defence techniques. The services also equip management and board-level executives with the knowledge necessary for sound decision-making during crises. 

 

Simulate real phishing scenarios

With the rise in phishing-based attacks today, it is important to ensure that your team is able to spot these types of threats early. This is where simulated exercises can be helpful, offering immediate feedback and valuable learning opportunities.

 

For example, you could assign an employee to craft phishing emails that resemble common business communications, such as invoices, collaboration requests, or HR updates. This mirrors the tactics cybercriminals use, making the training more relevant. Monitor if any employees fall for these fake emails, and provide immediate feedback and explain how the phishing email could be identified and avoided in the future.

 

Here is a basic checklist you can follow when training employees to defend against phishing emails:

 

  1. Verify the sender: Double check the email sender's address to ensure it matches official company communication standards.
  2. Examine links: Hover over any links (but avoid clicking them!) to preview the URL and ensure it directs to a legitimate website.
  3. Inspect content: Analyse the email content for irregularities, such as unusual language, requests for sensitive information, or unexpected attachments.
  4. Confirm with sender: If in doubt, contact the supposed sender through a separate, known communication channel to verify the legitimacy of the email.
  5. Report to IT: If an email seems suspicious, report it to the IT department immediately to prevent potential security breaches.

 

Such simulations need not be a one-time thing either. Only by regularly conducting simulated exercises can you track improvements and identify areas that may require additional focus. Use the data gathered to enhance the effectiveness of future training sessions. You can start simple but slowly increase the complexity of simulated phishing exercises by making the phishing emails harder to detect.

 

Singtel offers various e-learning courses through the Security Awareness Education and Phishing Service to help employees raise their security consciousness. These courses include phishing simulations which mimic social engineering attacks to targeted users to heighten cyber awareness. Singtel also has a phishing game called "Catch the Phish", which can be played on mobile and desktop devices. The goal of the game is to test whether one is able to differentiate a phishing attempt from a legitimate scenario.

 

Establish standard procedures for incident reporting

In the unfortunate event of a security breach, having a well-defined incident reporting procedure is critical for a swift and coordinated response. To start with, encourage employees to report security incidents in real time, especially when they encounter a suspicious email. It could be a simple step such as forwarding suspicious emails to a dedicated IT email address. 

 

It's vital to designate a competent team responsible for responding to reported incidents. Ideally, this should involve a cyber security expert. If you don’t have a dedicated resource, it can be a group of employees with some IT experience, along with an external vendor with expertise. This team should consist of at least one member who understands cyber threat response procedures or who has had some training, and is capable of assessing the severity of the situation and implementing countermeasures.

 

To inform relevant stakeholders about the security incident, you also need clear communication protocols in place. Identify the channels that you will use for communication in the event of an incident and ensure that pertinent information reaches the right individuals promptly. For example, you may want to create a separate channel in Microsoft Teams or a new group in WhatsApp if an incident response is in progress, with relevant team members added.  

 

Foster a culture of learning with training courses

When it comes to defending against cyber attacks, one has to take a long-term view. As the type of threats evolve and become more sophisticated, your employees also need to constantly upskill their cyber security education. To help them be ahead of the curve, encourage participation in training courses and programmes.

 

There are numerous courses available in Singapore that SMBs can access. Most recently, the Cyber Security Agency of Singapore launched SG Cyber Associates, a new programme  that will provide training for non-cybersecurity professionals. Singtel also offers the Singtel Cyber Elevate Programme that offers mentorship and training for SMBs, including cyber risk audits of the business, workshops on the best cyber security practices and legal and forensics support. There is also a 90 percent subsidy that eligible SMBs can apply for when selecting this programme.

facebooktwitterlinkedin

Discover more insights

How the PSG helps SMBs stay competitive
Article
How the PSG helps SMBs stay...

SMB, Digitalisation

Innovation and technology need not be out-of-reach and expensive. For SMBs...

5 things to consider when choosing your business broadband
Article
5 things to consider when choosing ...

SMB, Digitalisation, Connectivity

Whether you are a new business setting up broadband for your office,...

Secure your remote workforce: 5 essential steps for SMBs
Article
Secure your remote workforce: 5...

SMB, Cyber security, Digitalisation, Business Launch & Operations

As an SMB owner, ensuring the security of your remote workforce is paramount....

A basic guide to malware protection for SMBs
Article
A basic guide to malware protec...

SMB, Cyber security, Digitalisation, Business Launch & Operations

With more SMBs being targeted by malware-based cyber attacks, it is critical...

Defending against scams: 5 basic steps for SMBs
Article
Defending against scams: 5 basic s...

SMB, Cyber security, Digitalisation, Business Launch & Operations

Want to ensure that your business does not fall victim to online scams?...

Curated Content for You

Learn about how digitalisation enables businesses to grow by accessing our guides, case studies and more. Sign up now for free to receive new content updates.

Ready to get more out of digitalising your business?

Let us help you explore the right digital solutions that can boost the growth of your business.

Grow Your Business
Grow Your Business
Let us recommend the right digital solutions that are suited for your business.
Latest Promotions
Latest Promotions
Find the latest deals for mobile, broadband and more at Singtel Business eShop.