Despite the risk of data loss, 20 percent of SMBs do not use Internet security software other than firewall and anti-virus products, as they mistakenly feel these are sufficient. Additionally, 12 percent of IT managers admit, while they have an Internet usage policy, they have no way of enforcing it.
The study also found that business-owned computers are left vulnerable to security threats for more than 21 days, on average, despite the daily updates promoted and offered by operating system and anti-virus vendors. In fact, only 4 percent of SMB employees have daily security updates on their work PC, while 11 percent of employees say the security software on their work PC has never been updated.
On the bright side, 94 percent of SMBs claim to have an Internet use policy in place, and 67 percent say that all companies should have equal levels of protection from Internet security threats, irrespective of their size.
2007 SMB State of Security Key Findings:
- Preventing Data Loss: While 46 percent of IT managers say they have software to protect company confidential data, 81 percent of SMBs do not use software to block the use of peer-to-peer applications, block USB devices (80 percent), control the use of instant messaging (76 percent), or stop spyware from sending out information to external sources (47 percent).
- Risky Behavior: IT security managers say the top risks to their business include employees clicking on e-mail links from unknown sources (74 percent), employees sending company e-mail to the wrong address (53 percent), and employees accidentally or deliberately accessing adult Web sites (50 percent). Alarmingly, 73 percent of SMB employees admit to at least one of these high-risk activities with their work-owned computer, 54 percent admit more than one, while 27 percent admit three or more.
- False Sense of Security: 99 percent of SMB IT managers feel their company is protected to some degree from exposure to Internet security threats. But only 22 percent say they feel 100 percent protected -- meaning 78 percent do not. Additionally, 20 percent of SMBs do not use Internet security software other than firewall and anti-virus products, as they mistakenly feel these are sufficient.
- Window of Exposure: The average length of time that employees have continued to use their work PCs before security is updated is 21.2 days. Only 4 percent of employees have daily security updates on their work PC, while 11 percent have never updated security on their work PC. On a daily basis, Websense discovers Web sites that contain malicious code -- numbering in the hundreds of thousands -- that threaten vulnerable computers.
- Protection Overconfidence: Confidence levels in IT security are high among SMB employees, with 41 percent confident that their IT department protects them from every Internet security threat. However, 45 percent say they have some level of protection but admit they are not sure what is protected. Another 12 percent of employees say they do not know if their work PC is protected.