Video: Guarding the Gaps: Cybersecurity for Small Businesses | Duration: 1710s | Summary: Guarding the Gaps: Cybersecurity for Small Businesses | Chapters: Welcome & Introduction (0.28000000000000025s), Brite Introduction (207.535s), Breach Cost Impact (358.07500000000005s), Increasing Vulnerability for SMBs (516.735s), Anatomy of Breach (591.68s), Are You Prepared? (802.095s), MSSP Solutions (930.45s), AI-Powered Defense (1074.473s), Key Benefits of BriteProtect (1202.4830000000002s), Payment Scam Case Study (1280.353s), Connect with Brite (1357.0580000000004s), Q&A (1406.2330000000004s), Closing & Helpful Resources (1597.4380000000006s)
Transcript for "Guarding the Gaps: Cybersecurity for Small Businesses": Hello, everyone, and welcome to today's marketplace partner webinar presented by Paychex and Brite. Our topic today is guarding the gaps, cybersecurity for small businesses, and boy is this timely given that we're just around the corner from cybersecurity month. Many businesses today are more vulnerable than ever to potential threats that could compromise your business data across multiple digital fronts, especially with the growing expansion of AI. And when the pressures of tight budgets and potential staffing challenges are added in, your business may be facing some big data and cybersecurity challenges. Well, you're in the right place as today's speaker from Brite will be covering these concerns. Now before we dive in, I just wanna cover some quick housekeeping items. At the right side of your console, you'll find a docs column with related resources, including a printable copy of the slide deck, and there's also a q and a column where you can type in your questions. We have a few team members, including staff from Brite in the back end, and they'll be helping provide answers privately. Now we can't guarantee a response to every question, but they're all really valuable to us. We've received them all, and we we pay attention so we can create future resources like this that will strengthen your business. Now, occasionally, you may also see an audience poll come up. When a poll opens, a blue alert blue alert card will briefly appear at the lower right of your console or the lower left. I'm sorry. Click the button on it or the poll column at the right, which will be marked with a red dot, to view the poll. And there are no wrong answers. Just select your response, click submit, and you'll receive a confirmation. And then finally, please note this presentation does not constitute legal advice. This is for informational purposes only. And now I'd like to introduce today's speaker. With more than twenty years of experience in the technology industry, Trevor Smith is a business leader focused on sales, marketing, strategic partnerships, and organizational growth. He has played a key role in transforming Brite market positioning and has worked with organizations nationwide to develop and implement technology strategies that drive business success. Before I hand this off to Trevor, I would like to get started with a quick bold poll today just to set the stage. So our poll question is gonna open up here. You'll see it at the column on the right, and you'll see that little blue, little blue box on the lower left. So go ahead and just mark your response and click the submit button. So what concerns you most about today's cyber threats? Is it, a, we don't have the staff or the expertise to catch threats early? Is it, b, the security solutions we may need are are just out of our budget? Is it, c, AI is making scams and attacks harder to spot? I I can see that one happening. And let's see what we've got here because we've got a d two is that the potential disruption to the business operations, which is a big deal. So this is really interesting, Trevor. I'm watching these results come in, and, you know, AI is making it more difficult, and the potential disruption to our business operations is the real that's the real impact. That's the real concern, isn't it there? That makes sense. We're gonna talk a little bit about that impact and how to measure it as well. Fantastic. Well, why don't I hand this off to you, and you can go ahead and start taking us through this content. Fantastic. Thank you so much, Robert, for having us here today and for that great introduction, and thank you for Paychex, for including us in the marketplace and asking us to speak to the audience today a little bit about how we're helping organizations throughout The United States, especially small businesses, protect their organization and their business against the onslaught of of attacks. Is it just a little introduction who we are? Robert gave a brief introduction to me and my company. You know, we've been providing cybersecurity and IT solutions for organizations since the early two thousands, And we are very proactive in how we protect the organizations and communities at large with innovative technology solutions. And these are all delivered by our internal team. We have been a recognized leader in the managed services and managed security services space even to a point where we are recognized as one of the top 30, MSSPs globally. We do all of that with US based employees delivered by Brite employees. None of it's outsourced and happy to discuss how we can become a true extension for your organization. One unique ability is as I talk through today the impact that cyber is having on organizations, I'll talk a little bit about the prevention and the solution to it. And what we've tried to do is take the approach that large enterprises like Paychex and other big organizations take the technology, the approach that they're implementing and bring that to the small and medium business. And as one of those polling questions, that came up was the lack of internal resources or the dedicated resources, that's where a managed services provider can really help, an organization. So I'll talk a little bit about that too. What we've been asked and what we prepared for today's discussion is really four key areas. One is the threat today, which you guys were acknowledging that that threat is there and that the, the ability to spot those threats is harder and harder, and AI is, you know, increasing that ever ever so much more, every single day. We're gonna talk a little bit about anatomy of a breach and, a parallel I like to use that it's a very common and well understood scenario. And then we'll talk about the benefits of managed security services, and we'll visit briefly a case study. There'll also be some questions at the end if you have questions. You throw them in the q and a as Robert said or be happy to wait till the end. We'll we'll do that. But one of the reasons we're here today is that cyber breaches are very expensive. IBM released a study that talked about the impact of a cyber breach on small business. So organizations of less than 500 employees, the average breach was $3,310,000. And as a small business owner, a surprise bill of $3,300,000 is a hefty task and very difficult to endure. You might look at that and you say, okay, what really contributes to that cost? Is it really gonna cost me $3,300,000 if I have a breach? Well, there's a lot that goes into that. The first two components of that are the actual investigation, like what happened and what's it gonna take to figure out what happened? And most organizations have to bring in a third party to do that. They also have to bring in a third party to help with the response and the remediation, cleaning up their devices, making sure the malware is gone and, you know, wiping or refreshing, systems. And that effort is... Causes significant disruption to the business. There also are a lot of fines that come into place. If you live in New York or California or many of these states that have cyber breach notification laws, you must also pay a fine in addition to notifying those individuals that information might have been stolen. Also, in health care, finance, many of the regulated industries, there's... There also could be fines that come down. Your insurance provider might require that you implement new security tools either immediately or over a period of time. There's also legal, fees that come into play. You have to bring lawyers in to make sure that you're, following the rules within your industry or the state, and maybe you've received some of these notifications, like a legal notification that your information was stolen by some retail organization, maybe hotels.com or someone else. And and and from that, notification has to be written by a lawyer. And the last three, the opportunity cost, reputation cost, and lost revenue really significantly impact small business. So if you ask yourself, what would the impact to our organization be if we were out for one, three, ten, or more days? What would it really cost our business? And if you're unsure, we've built a data breach cost calculator, which you can get to through this QR code or on the right hand side under the docs. We have a link to the Brite security breach cost calculator and where you can enter in a bunch of this information, and it will report back what that estimated cost would be to your business based on your employee count and revenue, etcetera. So if we look at that, a lot of customers will say, well, hey, I'm a small business. I'm really a target. The truth of the matter is that nearly half of cyber attacks are now targeting small business, 43%. And they're attacked through email, which one in over 300 malicious emails hit a small business employee. And as we talked about with that $3,000,000 cost, sixty percent of businesses that suffer a cyber attack go out of business within six months. So we're not just talking about a cost, we're also talking about longevity. And if you look at this, why are almost half of these, attacks targeting small business? The truth of the matter is is most are not well prepared. And the survey that was done by IBM again, less than 15%, 14% of small businesses said they were not prepared. And as we see the the advancements in innovation in cyberattacks, that number becomes even lower. The truth is that, you know, attackers are preferring the small business and we're seeing that, arise especially with the the onslaught of AI. So there is an element of doom and gloom to this. There is an element of true impact, but, also, we wanted to educate a little bit on, hey, what is a cyber attack and what is kind of the anatomy of a typical attack that occurs? And an example that we like to use is paralleling it to a bank robbery. Well, hopefully none of you are bank robbers in the audience. However, I'm sure you've seen many movies and and understand that how bank robbery might occur. Some of those are some of my favorite movies. So if you think about it, right, the first thing that they do is they're gonna do some reconnaissance. They're gonna case the building. They're gonna walk around and check it out. They're gonna maybe make contact by building, by going in and creating an account and seeing what the workflow is. Then they're gonna identify the vulnerabilities of it. You know, is there a sewer pipe they can go? Is there an HVAC system they can go through? Are there times when the security guards are taking their lunch break or going on shift? All the common things we see within the plans of Ocean's Eleven and others. And then there might be the installation or the act of of starting the break in. Once that... They are successful, they get into what we call command and control where the bank robbery gains unauthorized access. The bank robbers, they get in there, they're able to gain access to the vault or or to the tellers or whoever they need to get the information, and ultimately, they take the money out. So if we take this same approach and we now parallel that to a cyber attack, this... The bad actors first build a list of targets. And this is where, if you look at that stat of 43% target small businesses, there's no bias here anymore. Yes, there are spear phishing attacks and singular attacks that are gonna go after a casino or a big bank or healthcare institution, but if you're building a list of targets that can be impersonal or not necessarily geared just towards the business, but it's geared towards a 100,000 companies that they're trying to target, which becomes really, faceless. The next part is they're going to launch some type of attack, and 80% of these attacks start with phishing email or email in general, but phishing is is a component to that email and and the the incorporator kickoff the attack with email. The next thing that happens is it's typically exploiting some type of vulnerability. You hear about Java and Adobe and all these vulnerabilities that exist on a system, and so the attack is targeting that specific vulnerability. So if you open up that email and you don't have a patch system, it's going to gain access to your sis... To your system. And most of the time, that's installing site... Some type of malicious software. That malicious software is going to then radio back to the bad actors saying, hey, I'm in. I'm in. Just like they would on a walkie talkie or a cell phone. And then once they have that access, they will then perform what they wanna do. Maybe it's encrypting your machines, maybe it's stealing data, maybe it's leading data, creating some type of operational disruption. So if you look at the in... Anatomy of a breach and look at it with the parallel between this real world scenario and changing from six shooters and explosives into keyboard and mouse, Maybe you you can understand how how impactful this can potentially be and really how sophisticated these attacks are. So if we go into the next part of this, we say, are you prepared? Do you have the systems in place to protect your organization from that cyber attack? And the first step of that is prevention. Now prevention is never a 100%, but we we look to deploy prevention that did, defense in-depth strategy, which is multiple layers of attack. You look at the bank, you got doors, you got security guards, you got video cameras, you have, you know, 911 call buttons, you got a vault that's locked up, all those different steps. And if we look at the firewall, the endpoint security, email security, multifactor authentication, those are defense in-depth strategies that help lock the phishing attack before it lands in your environment. The next step to that is all of these different tools generate alerts. They generate alerts and it needs to go to a place where it can be analyzed and collect in a centralized place. And this is what a... It's called a SIEM, a security incident event management or XDR, extended detection and response. These tools are capturing this information from all these different security tools that you have in your organization and they're then put into a place where they can be actively investigated, which is the third column here. And from this information that's provided, they can make a determine a determination. Is there an action that needs to occur? Is there an attack that's occurring? Is there a response that we need to put in place to shut it down quickly and easily? This ties into the whole idea of, if a tree falls in the woods, there's nobody's there to hear a sound, does it make a noise? And if you've spent money on prevention solutions, if you spent money on alerting but no one's watching the alerts, you're wasting your time and money. And so when you look at this preparation, understand, look at prevention, alert collection, and investigation and response. So that's where an MSP comes into play. We talked about at the very beginning the need for resources and the challenges for small businesses to bring on the necessary resources to defend from a cyber attacks. Large enterprises have dedicated teams. It's much smaller for small to medium businesses to do so, and that's where an MSSP comes to play. And if we look at this graph, which is a little bit of an eye chart, I apologize for that, but I will talk you through a little bit of what we're looking for. We're putting that defense in-depth strategy here within our entire ecosystem. And our ecosystem is what we call Brite Protect. And within the Paychex marketplace, you can find us under Brite Protect and the different packages for the small business. But we start in the middle with the yellow circle. We're providing 24 by seven security operations center services. And all of this, other elements on this screen tie into that 24 by seven protection of your organization. It starts with resources in the upper left square and the process... The resources of the people, the processes, which are mature and have been established over years and years of practice to understand, hey. What happens when we get a certain type of alert or we see a certain type of action? How do we communicate in the bottom left corner to the end customer or to the applications and and respond? We do our own development inside of, the... Threaten... Excuse do our own development inside of the platform to continuously evolve and support the, changing environment and changing industry. That includes detection engineering and threat intelligence and understanding social engineering and the approach. And then if you look at the defense in-depth strategy and need to deploy these technologies, you can have dedicated people for each of these. And so we have teams that are able to monitor, manage, deploy, and support these technologies. So happy to go through more about the different platforms and technologies and additional discussions. If there's gaps that you have, maybe you have a good firewall solution. Maybe you have good endpoint technology, but you're missing some of the other parts. We're happy to talk about the benefits and prioritization of these different, defenses. I picked out a couple just to, to to highlight and define a little bit further. Those three are security operations, endpoint detection and response, and email. And the reason I brought these three up is that we heavily leverage artificial intelligence to fight the attacks launched with artificial intelligence. The need and the requirement is to operate at machine speed. And so our security operation center where four or five years ago, the average response and investigation was twenty to thirty minutes, it's now down to twenty and thirty seconds. And it has to be because the attacks are happening that fast. That's in the security operations center of using machine learned, intelligence and artificial intelligence, generative AI for communications platforms and hypotheses and summarization, and true agentic AI triage which evaluates thousands and millions of alerts super fast, triage those and helps us clearly get a picture in seconds. Maybe you've heard of CrowdStrike, very successful cybersecurity... Publicly traded cybersecurity company, and we have taken a true enterprise technology to bring this to the small to medium businesses. Historically, this was expensive and challenging to implement and and tough for small businesses to to deploy and use, but it is an industry best. And so we've done our best to help organizations and make this available to small and medium businesses to protect their endpoints. And the third one is, a company called Abnormal Security and this is focusing on email security, which I mentioned is 80% of attacks start with email. It's critically important to be able to understand this. Understand the context of the email, the intention of the email, and not just rely on your end user's identification, which you mentioned at the beginning is very hard to rely on. So what Abnormal does is uses AI to understand the context origination of email to ensure that it's not malicious. The last slide I'll talk about here is the benefits. By... And these are the benefits of our MSSP offering. It could be very... It could vary based on others, but what we wanna bring up. The first is these acronyms MTDDR, m t d... MTD, and MTD are, mean time detection and mean time to response. How fast can we detect and respond? And I mentioned how quickly we're able to do that in tens of seconds versus twenty, thirty minutes. We're employing an AI powered platform to fight AI with AI. We work with whatever technologies you currently have in place from firewalls to endpoints. We're looking at a true 360 degree view of the environment, not just looking at a single alert, not just looking at malware or endpoint security. You have to expand this to understand the attacks at the identity, at the perimeter, at the, email at other different spots. And we're bringing true enterprise solutions to the small business, which again, log collection, you look at user anomaly behaviors, other areas. All of this is wrapped up with our 24 by seven service we talked about before. So last part. Just a case study. It's a pretty common attack that we see, a man in the middle payment scam, an email's going back and forth between, you know, an accounts payable individual and a vendor. A bad actor slides into the middle of that conversation, intercepts the communication from the accounts payable person to a vendor. It starts impersonating the vendor. They can change a single character or or a single part of that email address and it makes it look like the same person. Because they've been watching the communication for a little while, they know the language, the frequency, the timing, and other things that are occurring. And they're able to capture, recognize when a payment is about to occur, request banking information, and then that, funds are potentially wired. Where we're able to see this, we're able to identify that change in the vendor. We're able to alert the end user of that change in the vendor. We're able to identify the changes in an, inbox where emails are changed and moved from an inbox to go into a delete, and other things that bad actors do to obfuscate this attack that's occurring. And through this process, we've been able to protect many companies and organizations and we see it quite often. So the end result is Bryte's... We're here to help. Love the opportunity to connect with you, you know, through... You can come to our website or email. We are listed on the Paychex marketplace under BriteProtect where we have our different offerings and a lot of benefits specific to Paychex customers and the discounted pricing that Paychex is negotiated for the customers. We also have some assets here around our data breach calculator, and we also have the ability to provide a cybersecurity, assessment. If you'd like to understand how mature your organization is, there's no cost associated with it. We can help run a quick assessment and help you, understand where you sit today and what recommendations we might have for you to protect your organization better. Thank. you very much. Thanks, Robert. Thank you, Trevor. That was great. A lot of great information there. It is it is challenging. All the points you touched on that that attacks are more frequent, that it's tough to for a small business to get all of the tools and all of the resources and all of the support needed to protect themselves. So thank you for just laying that all out, and I love the oceans I love the oceans 11 analogy. It really helps, it helps understand how challenging it is and how sophisticated these bad actors really are. I do have just a couple questions I wanted to bring into play here. There's a lot happening here in terms of my technology, you know, as a small business. Can Brite protect work with the technology and security tools I already have, or is it do you do I have to change my systems to accommodate this new security solution? Yeah. That's a really good question, Robert. And it's a common question. You know, you've made investments in firewalls or endpoints or other tools out there. So you're generating some of those alerts that I mentioned. The platform that we have, we we refer to it as an open XDR platform. An open meaning that we can integrate with almost anything. So we can capture those alerts. Now we'll take those alerts, bring them into our system, watch those, correlate them together with others to get early indications of attack. We wanna find someone when they're knocking on the door, not when they're running out of the bank with the money. And that's what we're able to do. That's great. And that actually leads me to my next question. I imagine there's all kinds of security alerts. I mean, there is all kinds of poking and prodding happening. Who reviews the security alerts, and and how is a small business owner or somebody maybe who's just in charge of the IT side of the house? How do I know which ones are urgent? How do I know which ones to pay attention to? That's a really, really good question. So, when we talk... I talked a bit about our security operations center being bright badged employees all in The US. We will do that analysis. We... Overnight, when we sign with a customer, our typical implementation time is two to three weeks. In... Immediately, you now have a entire cybersecurity team behind your organization, behind your IT team watching your environment and looking for those early indications of attack. At the same time, this has been heavily augmented with AI as I mentioned before, and it has to be because we have to move machine speed. When we first launched this platform, we were heavily using machine learned AI. We were looking for patterns. We were understanding, hey, where's the anomaly that's occurring? How do we correlate these things together? And now we've moved beyond just machine learned and, as you can imagine, moving more into this agentic world where AI is understanding context and taking it further. And we still stay within a human in the loop scenario where the analysts are reviewing the results, but they're enabling and getting more and more confidence for us to be able to move at the same speed that the bad actors. are moving. you so much, Trevor. A lot of great information here. I do wanna share with our audience some of the resources that the Brite team has made available. We've got them in the docs column to the right side. There's a printable PDF of the slide deck. There's also a free security assessment from Brite, which if you just click over the learn more, tab there or the explore Brite Protect, button at the top of your screen, it'll take you to the marketplace. And on that tile, just click learn more, and you'll get access to the to the free assessment to see where you're doing in terms of your cybersecurity and how well you're protected. Nowadays, Just business is not just free from free from danger. The the bad actors are after everyone, all the time, and security does not mean security. So I really recommend you look into this and see what might help you out. Also, if you haven't yet completed the brief survey that launched previously, I encourage you to complete that now before we close. We value and appreciate your feedback. It helps us improve future resources like this to support your business. We'll also be sending a follow-up email to everybody that registered for this event. There'll be a link on demand recording so you can watch it again at your convenience, and you can share it with anybody you'd like who you think might find it valuable. You'll also have access to all these resources that we mentioned, when you're viewing it on demand. So once again, I encourage you to hit that explore Brite Protect button, get that free assessment, and at a minimum, claim your free, cost calculator to see what you're up against. Thank you again, Trevor Smith, president of Brite, for sharing your expertise with us today. And thank you, our audience, for joining us for Guarding the Gaps, Cybersecurity for Small Business. We really appreciate, you investing your time with us, and I really hope you have a great rest of your day. Thanks, Robert. Have a great day.