
That’s ridiculous, you say. But what does that have to do with my business? I’m not the FBI, and nobody is going to spend the kind of time or resources attacking my company that they would spend attacking a federal agency. (As an aside, note that the hackers expressed shock at how little effort they had to spend to get this data).
But there is something worth paying attention to here for business owners, and it has less to do with the FBI itself and more to do with what happens when something goes wrong. The FBI confirmed in September that it was investigating a compromise involving FBIJobs.gov, its employment portal. The bureau said the point of the breach had not yet been determined and that it was working with third-party providers supporting the site. Subsequent reporting indicated that sensitive information may have been exposed, and the FBI began treating the incident as potentially affecting its employees.
The obvious question is, “How could the FBI get hacked?”
But the better question for a business owner: What happens to your business when something goes wrong?
You Don’t Hear About Most of the Local Ones
Every time a major organization gets hacked, we hear about it. The FBI gets breached, a hospital gets hit, a major retailer loses customer information, or a university has its systems taken offline, and suddenly cybersecurity is everywhere. There are news stories, press releases, experts explaining what happened, and plenty of advice about what everyone else should be doing to protect themselves.
You Probably Don’t Hear About the Small Business Down the Road
They don’t call the Augusta Chronicle or the Aiken Standard and report themselves when somebody compromises an email account, encrypts a server, steals credentials, initiates a fraudulent wire transfer, or takes a critical system offline. WJBF and WRDW aren’t going to show up with cameras every time a local business has an IT problem that turns into a serious business problem.
But these things happen, and we know because businesses come to us after the fact. Sometimes they need help figuring out what happened. Sometimes they need to clean up a mess that started with one compromised account and eventually affected other systems. Sometimes they need to recover data or rebuild equipment. And sometimes the biggest problem isn’t the attack itself. It’s everything that happens afterward.
Oh, by the way, some research suggests that 1 in 5 SMBs would fail after a successful cyberattack.
So, this is where the ideas of Business Risk and Resilience come into play. Here are 4 questions you can ask of your business as you consider how to be resilient over the long haul.
Risk and Resilience Questions
1. What could seriously disrupt our business?
Start by thinking about the things that could bring your business to a halt or seriously interfere with your ability to serve customers. That could be losing your building, a key employee, an important vendor, your ability to accept payments, or access to the information you need to operate. What bottlenecks, chokepoints, and weak links exist in your business?
It could also be an IT or cybersecurity incident. A ransomware attack, compromised email account, failed server, damaged network, or outage involving a critical cloud application can all become business problems very quickly. The important thing is to look beyond the technology itself and ask what business functions depend on it.
2. How bad would it be if it happened?
Not every risk deserves the same level of attention. Losing email for an hour may be an inconvenience, while losing access to your accounting system or customer database for several days could have a much greater financial impact.
The same is true of cybersecurity risks. A compromised employee account might be contained relatively quickly, while ransomware that takes down your critical systems could disrupt operations for days or longer. Consider lost revenue, employee downtime, customer impact, data loss, regulatory or contractual consequences, and the cost of getting the business back to normal. The goal is to understand which risks could genuinely hurt the business rather than treating every possible problem as an emergency.
3. How prepared are we to deal with it?
This is where technology and cybersecurity become especially important. If something happened tomorrow, would you know what to do? Do you have reliable backups, and have you actually tested your ability to restore them? Do you know who has access to your critical systems? Do you have a plan for dealing with a compromised account or an unavailable server? Do you know who to call if your network goes down?
Having security tools and backups is important, but resilience comes from knowing that those protections will actually work when you need them. A plan that exists only in someone’s head, or a backup that has never been tested, isn’t much of a plan when the pressure is on.
4. What are we going to do about it?
Once you understand your risks and how prepared you are, you can make some decisions. You may be able to eliminate a risk, reduce it with better processes or technology, transfer some of the financial impact through insurance or contracts, or consciously accept it because the cost of addressing it outweighs the potential impact.
The same approach applies to cybersecurity. You might decide that an old system needs to be replaced, that certain accounts need stronger protection, that your backup strategy needs to change, or that you need someone to regularly assess your network and security. The important thing is that you’re making an informed decision about the risk rather than simply assuming your existing IT is taking care of it.
Conclusion
The FBI breach is a reminder that nobody gets to operate in a world without risk. You can have good people, good technology, and good security practices…and still have something go wrong.
For a small or midsized business, the answer isn’t to try to eliminate every possible threat. It’s to understand where your business is vulnerable, determine which risks could do the most damage, and make sure you are prepared to respond when something doesn’t go according to plan.
That is what resilience really means. It isn’t simply having a good firewall or a backup system, and it isn’t a binder full of procedures that nobody has looked at in three years. It is knowing what your business depends on, understanding what could disrupt it, having reasonable protections in place, and knowing how you will recover when those protections aren’t enough. The businesses that are prepared for the long haul aren’t necessarily the ones that never have problems. They’re the ones that can take a hit, recover, and keep moving.
