No Results Found.
The page you requested could not be found. Try refining your search, or use the navigation above to locate the post.
Aaron R. Warner
•
August 29, 2018
Earlier this month, the National Institute of Standards & Technology (NIST) Small Business Cybersecurity Act became law. There are a few important things you should know about these new guidelines.
Designed for small and medium-sized businesses, this law requires NIST to – within the next year – release a collection of informational resources that will help organizations identify, assess, and reduce their cybersecurity risks.
Although NIST is required to create these recommendations, small and medium-sized businesses aren’t required to follow them. Applying the recommendations is voluntary – but will likely offer a good place to start as you form your own cybersecurity plan.
Why an NIST Framework for Small Businesses?
NIST already offers a Cybersecurity Framework that outlines cybersecurity standards, guidelines, and practices enterprises can use to protect their critical infrastructure; however, most small organizations find this NIST framework to be too expensive and difficult to implement.
The new Small Business Cybersecurity Act specifically targets small and medium-sized businesses for a few reasons:
It can be awfully tempting for a small business to ignore cybersecurity altogether. After all, the events that make the news involve large, well-known organizations. But bad actors know this tendency for small businesses to be a little lax about cybersecurity – which is one of the things that makes smaller businesses enticing.
According to the 2017 State of Cybersecurity in Small & Medium-Sized Businesses report from Ponemon Institute, 61% of small businesses experienced a cyberattack in 2017 (up from 55% in 2016). And KnowBe4 reports that 57% of small and medium-sized businesses report an increase in attack volume over the past 12 months.
What the New NIST Framework Covers
Per the Small Business Cybersecurity Act, the guidelines in this new NIST framework must:
We anticipate that the guidelines will offer information to small businesses on things like:
As the NIST Small Business Cybersecurity Act guidelines are rolled out over the next year, we’ll keep you updated on what they recommend.
In the meantime, if you have any questions about these guidelines, how they might impact you, or how you can integrate them into our own cybersecurity plan, don’t hesitate to send me a note – I’m here to answer your questions.
Talk with ProCircular about incident response, tabletop exercises, security assessment, and practical ways to reduce risk.