As small and medium-sized businesses (SMBs) are making strides in utilizing cloud technology, Amazon Web Services (AWS) debunked three major misconceptions that are holding SMBs back from prioritizing security.
“Cloud security isn't as hard as you think it is,” Ben Schreiner, AWS head of business innovation for U.S. SMBs, told SDxCentral after investing the time to learn more about it.
“I think they'll find that it's easier and more efficient, and then, therefore, more cost-effective.”
Misconception No. 1: Cloud security is costly and not a top priorityAWS recently surveyed over 800 C-suite executives, VPs and directors from global SMBs and found that 35% of the respondents reported that investments in data security weren’t a strategic priority.
SMB owners juggle numerous priorities — from cash flow and talent recruitment to technology investments aimed at boosting productivity. Through that lens, cybersecurity may appear as an added cost rather than a direct contributor to growth and revenue, AWS noted in a blog post.
“Security should be a strategic priority for all small and medium businesses, just because they can't afford to have the disruption,” Schreiner said.
“Whether you're in the cloud or not, security just has to be a higher priority than it ever has been. There's too many bad guys out there and they don't care how big your company is,” he added. “And unfortunately, the small and medium businesses don't have as much security as the big banks, let's compare. And so they're easier targets, unfortunately, for the bad actors.”
AWS’s survey also found that 41% of surveyed SMBs have not provided any security training to their employees, while 43% are planning to do so in the next year, another indicator that some SMBs haven’t seen cybersecurity as a top priority.
Schreiner noted there are various free cloud security trainings available online. Additionally, AWS offers cybersecurity certifications to help organizations identify and train skilled professionals.
Misconception No. 2: Data in the cloud is harder to secure than on-premisesHalf of the survey respondents expressed some degree of concern about cloud security, viewing migration as a risk.
“While on-premises solutions may seem like the more familiar — and therefore safer — choice, the cloud offers a more flexible and scalable way to manage security compared to on-prem solutions,” the AWS team wrote.
“We find that a lot of companies that we talked to have many security tools. And sometimes when they come to AWS, they can reduce the number of tools that they have, trying to simplify because they have better visibility,” Schreiner said, adding that many of these on-premises security tools are also available to be used on AWS.
For cloud security, AWS operates on a Shared Responsibility Model.
Schreiner noted that in this model, users are responsible for keeping their operating system current and standard, as well as the applications they put on the operating system. “The data that they store on AWS, we default to making it very secure, but we tell them if they make it unsecure, so that they realize what they're doing.“
Additionally, the cloud provider also offers tools like automated security checks against industry standards and best practices, AWS Security Hub for visibility, threat detection and response, recommendations based on best practices, and workflow automation to enhance their security measures.
Misconception No.3: Cloud security is too complex and needs a large IT teamAWS’s survey showed around 30% of respondents admitted to understanding their company’s security, risk and compliance requirements but were unsure how to manage them. A further 40% cited a lack of skilled staff as a barrier to investing in security.
“The struggle for an SMB is just staffing, right? They just never have enough staff or enough time,” Schreiner said. “And so they have to be clever and smart about the tools and partners that they leverage.”
He highlights the importance of making security everyone’s responsibility, especially in SMBs where a dedicated security leader is rare.
“In a small and medium business, it's quite rare to come across a CISO, somebody that's dedicated to nothing but security,” Schreiner said. “Then everybody else needs to kind of carry their weight more, they need to do a little bit more. And they need folks like us and our partners to make it easier to be compliant, to make it easier to protect the data that they're trying to protect.”
There are several ways for SMBs to address that skills gap. One is focused training for their existing staff. The other is leveraging expertise from others for other solutions to make security more robust, he added.
Comments