LocalExperts Emphasize Strategy, Culture, and Vigilance in Cybersecurity

0
16

Key Takeaways

  • Many small and mid‑sized businesses are not indifferent to cybersecurity; they feel overwhelmed and uncertain about where to start.
  • Artificial intelligence is amplifying the sophistication of cyberattacks, making secure AI governance a necessity for any organization adopting AI tools.
  • A well‑designed cybersecurity program can generate tangible business value—cost savings, competitive advantage, lower insurance premiums, and improved reputation.
  • Privacy‑ and data‑related litigation is rising, especially for smaller firms, so regular risk assessments and expert guidance are essential to mitigate legal exposure.

Understanding the Real Barrier for SMBs
Small and mid‑sized businesses often struggle with cybersecurity not because they dismiss the risk, but because they feel overwhelmed and unsure of the next steps. Chris Sirianni, president and founder of IT Insights, emphasized during a Rochester Business Journal virtual panel that many owners genuinely want to protect their assets but lack a clear roadmap. This sense of paralysis leads to ad‑hoc measures rather than a coherent strategy, leaving gaps that attackers can exploit. Recognizing that the problem is one of capacity and knowledge, not apathy, is the first step toward building an effective defense posture.


Foundational Technical Controls Recommended by Experts
Sirianni outlined a set of baseline controls that any smaller organization can implement relatively quickly and affordably. These include enabling multifactor authentication (MFA) across all critical systems, deploying password managers to eliminate weak or reused credentials, and delivering regular security‑awareness training to staff. He also advised partnering with managed service providers (MSPs) that can supply continuous monitoring and expertise, and evaluating whether a managed detection and response (MDR) platform fits the organization’s threat landscape. By layering these controls, businesses create a defensive baseline that raises the cost and complexity for attackers.


Embedding Security into Organizational Culture
Beyond tools and policies, Sirianni stressed that cybersecurity must become part of the company’s DNA. He cautioned against viewing security as a checklist of isolated rules; instead, leaders should weave safe practices into everyday workflows and decision‑making processes. When employees see security as a shared responsibility rather than an IT‑only concern, compliance improves, and the organization becomes more resilient to social engineering and insider threats. Cultural integration also facilitates faster adoption of new controls as threats evolve.


AI’s Dual Role in the Threat Landscape
Trevor Smith, president of Brite, highlighted how artificial intelligence is reshaping both offense and defense in cybersecurity. Cybercriminals are leveraging AI to automate reconnaissance, craft convincing phishing lures, and evade traditional detection mechanisms, making attacks more sophisticated and harder to spot. At the same time, AI can empower defenders through anomaly detection, predictive threat intelligence, and automated response. Smith urged businesses to adopt a secure AI strategy that begins with inventorying data assets and access rights, establishing usage policies, implementing governance oversight, and weighing the financial impact of AI investments.


Crafting a Secure AI Governance Framework
To reap AI’s benefits while minimizing risk, Smith recommended a structured approach: first, understand what data the organization possesses and who can access it; second, define clear policies governing AI model development, deployment, and monitoring; third, establish oversight bodies—such as an AI ethics committee or cross‑functional security team—to enforce those policies; and fourth, continuously measure the tangible business outcomes driven by AI initiatives. By aligning AI adoption with measurable value, companies avoid “AI for AI’s sake” projects that could introduce unnecessary vulnerabilities.


Reframing Cybersecurity as an Investment
Reg Harnish, CEO of OrbitalFire Cybersecurity, challenged the prevailing myth that cybersecurity is merely a cost center. He argued that a well‑executed security program can deliver a meaningful return on investment through several channels: competitive advantage (customers prefer secure partners), lower operating costs (fewer incidents mean less downtime), streamlined business development (security certifications open new markets), enhanced reputation, and reduced cyber‑insurance premiums. Achieving these benefits, however, requires a mindset shift—seeing security not as a compulsory burden but as an enabler of strategic objectives.


Translating Security Goals into Actionable Work
Harnish advised leaders to start by articulating specific security objectives aligned with broader business goals, then systematically execute the work needed to meet them. This could involve prioritizing risk‑based remediation, investing in staff training, or adopting technologies that directly support those objectives. By treating cybersecurity initiatives as projects with clear milestones and measurable outcomes, organizations can track progress, justify expenditures, and demonstrate value to stakeholders. The result is a security program that feels purposeful rather than perfunctory.


Growing Legal Exposure Around Privacy and Data
Anna Mercado Clark, partner at Phillips Lytle LLP, turned the conversation toward the rising tide of privacy‑ and data‑related litigation. She noted a significant increase in class‑action lawsuits targeting small and mid‑sized firms, many of which allege inadequate safeguards for personal information. Importantly, she warned that simply following common industry practices does not guarantee legal protection; courts often look beyond “what everyone else does” to assess whether a company exercised reasonable care. Consequently, reliance on industry norms alone can leave businesses vulnerable to costly settlements and reputational harm.


Mitigating Litigation Risk Through Proactive Assessments
To counter this trend, Mercado Clark advocated for periodic risk assessments conducted jointly by legal and cybersecurity experts. These assessments should map data flows, identify where personal or sensitive information resides, evaluate third‑party access rights, and test the effectiveness of existing controls. Findings from such assessments inform remediation priorities, policy updates, and incident‑response planning. By demonstrating a documented, diligent approach to risk management, companies can strengthen their defensibility in litigation and potentially reduce damages or penalties.


Practical Steps for Immediate Improvement
Synthesizing the panel’s insights, a pragmatic action plan for SMBs emerges: (1) Deploy MFA and password managers across all user accounts; (2) Conduct baseline security‑awareness training and schedule regular refresher sessions; (3) Engage an MSP or MDR provider for continuous monitoring and expert guidance; (4) Perform a data inventory and establish clear AI usage policies if AI tools are in use; (5) Align security initiatives with defined business objectives and track measurable outcomes; (6) Schedule quarterly risk assessments with legal and cybersecurity professionals to stay ahead of privacy‑related litigation. Implementing these steps creates a layered defense that addresses technical, human, and legal dimensions of risk.


Conclusion: From Overwhelm to Empowerment
The discussion underscored that the primary obstacle for many small and mid‑sized businesses is not a lack of concern but a feeling of being overwhelmed by the complexity of cybersecurity. By breaking down the challenge into manageable, culturally embedded actions—leveraging foundational controls, integrating security into daily operations, governing AI responsibly, viewing security as a value‑driver, and proactively managing legal risk—organizations can transform cybersecurity from a source of anxiety into a strategic asset. The payoff includes stronger protection against evolving threats, tangible cost savings, competitive differentiation, and greater resilience in an increasingly litigious digital environment.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here