No Results Found.
The page you requested could not be found. Try refining your search, or use the navigation above to locate the post.
Aaron R. Warner
•
March 20, 2017
In the world of startups, cybersecurity is often an afterthought.
Not because budding entrepreneurs haven’t heard the horror stories, but it seldom ranks highly among things that directly generate cash or hurry a company to market. Like so many other priorities, cybersecurity often falls to the wayside in the early business stages.
This is largely due to a few immutable truths of the startup world:
This sort of environment makes it difficult to consider infosec as anything more than another hampering cost center. So startups often choose to roll the dice and hope for the best.
In years past this might have been a valid approach. No longer the case.
Startups are influencing and reinventing every part of our world—healthcare, finance, childcare, transportation, energy—and this hasn’t been lost on thieves. Leaving aside the state-sponsored thirst for acquiring intellectual property through theft, the data stored by flourishing startups has been recognized as valuable and marketable by denizens of the dark web.
Personally identifiable information (PII) and healthcare data translates into identities for sale. Financial information, either as account data or credit card information, is valuable both for direct abuse or resale. And the word is out—startups generally suck at protecting their data.
We know starting a business is arduous, so why should you give cybersecurity the same attention that you dedicate to UX, product design or financial management? Here are some of the reasons to make cybersecurity part of your startup’s Core Value Proposition.
Competitive Advantage:
You’re not the only one to recognize the need for cybersecurity. Your customers are reading the headlines and they’re often in no better shape themselves. Rather than fix their own internal problems, they’re increasingly looking for vendors that have these issues solved for them. This risk transfer approach is a common reason for shopping solutions in the first place. You may well have competitors with similar features or capabilities, having every major news outlet marketing one of your standout features (privacy or security) can be a great advantage.
Apple may have its challenges, but compared to many of their competitors they’ve done a great job of making security and privacy a competitive advantage. Their very public disagreements with the FBI in a number of recent cases have proven that the company takes the protection of their customers’ data seriously. Web hosting companies like Pagely or Armor.com are able to charge a significant premium due to the quality of their security programs and compliance. No longer just a comforting reassurance, security now adds to value.
Compliance and Regulatory
Whether you realize it or not, you may already have regulatory compliance requirements built into your business model. Here’s a quick reference of data types and the requirements that come along for the ride:
The rule requires appropriate safeguards to protect the privacy of personal health information, and sets limits and conditions on the uses and disclosures of such information without patient authorization. The Rule also gives patients’ rights over their health information, including rights to examine and obtain a copy of their health records, and to request corrections.
These include:
Individually identifiable health information includes many common identifiers (e.g., name, address, birth date, Social Security Number, diagnosis ,condition, medication, etc.).
Maintaining payment security is required for all entities that store, process or transmit cardholder data. Guidance for maintaining payment security is provided in PCI security standards. These set the technical and operational requirements for organizations accepting or processing payment transactions, and for software developers and manufacturers of applications and devices used in those transactions.
The Family Educational Rights and Privacy Act gives parents and eligible students these basic rights:
An important point to consider is that these standards apply to both your organization and the third parties you’re using to host your data. If you move the data to which these regulations comply to the cloud in any way they’ll also need to be compliant. This applies to the storage of the data, whether in a database or a flat file, as well as the applications used to access it and the methods you use to transfer the information. You’ll need to review each of your cloud vendors very closely, and perhaps perform an onsite inspection, in order to be in full compliance with the standards.
Making Cybersecurity and Compliance a Competitive Advantage
Noting these advantages and obligations, how can your startup join the ranks that use security and privacy as a competitive advantage? The steps are less daunting than you might think.
ProCircular’s recommendations for startups are a subset of guidance provided by a recent Department of Homeland Security publication (Reference Number JAR-16-20296, NCCIC/FBI/DHS) that states that 85% of the targeted cyber attacks can be prevented by taking these steps.
Note: We’ve rearranged the list and modified the comments to make them more realistic for cash-strapped and time-hungry startups:
I’ve separated these last three because they’re often difficult for smaller organizations. If you can afford them, or your organization deals with some of the sensitive data mentioned above, private health records (PHI) in particular, you may want to budget for them regardless:
Your Startup’s First Disaster Recover/Cyber Meeting
A good start is to have ask everyone to read this article that you’ve already worked 2/3rds of the way through. Once they’ve given this modest piece a read, gather the team for an open and honest discussion of your risks. This can be divided into three steps:
Cyber Risk
Business Impact Analysis (BIA)
Incident Response
Once you’ve pulled all of this together, divide up the work. Go around the room and have each person read off the work that they’ve promising to do. Put these down as action items and use them for a follow up meeting to be scheduled in a month. Get together each month for two hours and stay religious about it and VOILA! You have a functioning cybersecurity program.
We’re going to sound like a broken record, but PLEASE insist that backups and a recovery test is done as one of the action items. Even if you’re sure you’re already doing them, have someone demonstrate that it’s been done again at the next meeting. This is the most effective way to protect yourself and your business, and it’s so rarely done well. Ransomware preys on those who don’t back up, and you’ll enjoy telling the hackers to ‘go kick rocks’ if your backups are in order.
Summary
While this may seem like a lot, it’s a body of work that any startup can complete with about ten hours from roughly three people. If this reasonable commitment might derail your product launch, you may want to rethink what you’re launching and when.
Think about it this way – how much would losing all of your shared files impact your product launch or cashflow? If you divide that impact by ten, the result is probably more than what’s needed to pull together a plan. Meanwhile, staying operational and available to your customers may be just the thing to put you ahead of your competitors.
We know that these things can be confusing. Want to chat more with our experts and see a list of recommended services to get you started? Learn More!
Talk with ProCircular about incident response, tabletop exercises, security assessment, and practical ways to reduce risk.