Story image

Kiwi business? Ignoring security? You might face a triple backlash

17 May 17

KPMG says that New Zealand’s small and medium businesses must face up to the reasons why they need better cybersecurity, or risk backlash from the law, customers and partners - not to mention the attackers themselves, the company warns.

KPMG Cyber Security practice national leader Philip Whitmore says that while large enterprises are putting security measures in place, it’s now time for SMEs to do the same.

“As our larger corporates are entering a mature phase of protection, we are seeing attackers turn their attention to the ‘low-hanging fruit’ of exposed SME-size businesses,” he says.

New Zealand businesses will also need to prepare for any future mandatory breach laws that come into effect, such as in the case of Australia’s Data Breach Notification laws. Customers and business partners will also sit up and take notice of how businesses protect their data.

“If your data security is breached, you may be required by law to disclose this. This could have serious implications for your brand, loss of trust with your customers, and even your ability to win clients in future,” Whitmore says.

He believes that those customers and business partners will start asking questions about security. If businesses can show that they have effective controls in place that communicate trust and data security, that is a distinct competitive advantage. 

The recent Norton Cyber Security Insights Report showed that SMEs are prime targets for attacks. Whitmore says that because New Zealand is primarily made up of small businesses, attackers see the country as a ‘soft target’ for phishing attacks.

“Many smaller businesses think they are covered by their antivirus software, or that their IT provider will protect them; but in reality, that’s wishful thinking. Good security is not just an IT issue; it’s a business issue. Every business owner should have oversight across it,” Whitmore says.

KPMG has moved into the cybersecurity space by developing a new ‘Cyber Accelerate’ service to help small and medium businesses. 

“We’ve designed a suite of nine products that are low-cost yet deliver a high return in terms of protection. It’s important to remember that every business has something of value to cyber-criminals – whether it’s money, database information, or other intellectual property,” Whitmore concludes.

Hillstone CTO's 2019 security predictions
Hillstone Networks CTO Tim Liu shares what key developments could be expected in the areas of security compliance, cloud, security, AI and IoT.
Can it be trusted? Huawei’s founder speaks out
Ren Zhengfei spoke candidly in a recent media roundtable about security, 5G, his daughter’s detainment, the USA, and the West’s perception of Huawei.
Oracle Java Card update boosts security for IoT devices
"Java Card 3.1 is very significant to the Internet of Things, bringing interoperability, security and flexibility to a fast-growing market currently lacking high-security and flexible edge security solutions."
Updated: Chch crypto-exchange Cryptopia suffers breach
Cryptopia has reportedly experienced a security breach that has taken the entire platform offline – and resulted in ‘significant losses’.
Sophos hires ex-McAfee SVP Gavin Struther
After 16 years as the APAC senior vice president and president for McAfee, Struthers is now heading the APJ arm of Sophos.
Security platform provider Deep Instinct expands local presence
The company has made two A/NZ specific leadership hires and formed several partnerships with organisations in the region.
Half of companies unable to detect IoT device breaches
A Gemalto study also shows that the of blockchain technology to help secure IoT data, services and devices has doubled in a year.
Stepping up to sell security services in A/NZ
WatchGuard Technologies A/NZ regional director gives his top tips on how to make a move into the increasingly lucrative cybersecurity services market.