4 estrategias de ciberseguridad para negocios pequeños y medianos

por Estrategia y Decisiones

Entre los ciberdelincuentes existe la idea errónea de que las empresas medianas hacen muy poco para reforzar su ciberseguridad, lo que las convierte en objetivos atractivos.

E

n marzo del año pasado, la inteligencia artificial detectó un ciberataque sofisticado y altamente dirigido a múltiples empresas. La brecha explotó una vulnerabilidad de día cero (una falla no intencional en el software o hardware, que puede ser aprovechada por los ciberdelincuentes) y fue detectada, investigada y contenida por la IA. Dos semanas más tarde, esta campaña se atribuyó públicamente a un actor estatal chino conocido como APT41. Las organizaciones amenazadas por el ataque incluían entidades gubernamentales, infraestructuras críticas, grandes empresas, pero también, sorprendentemente, empresas medianas.

Entre los ciberdelincuentes existe la idea errónea de que las empresas medianas hacen muy poco para reforzar su ciberseguridad, lo que las convierte en objetivos atractivos. A menudo se utilizan como vía de acceso a objetivos de mayor valor, sistemas críticos e información altamente clasificada. La mayoría de las empresas planean realizar, o han empezado a hacer, los generalizados cambios tecnológicos organizacionales que definen una transformación digital, y dicen que estos ajustes pronto serán esenciales para su competitividad.

Este tipo de disrupción es intolerable para las empresas medianas. Los ciberataques no sólo son potencialmente perjudiciales para las relaciones con los clientes y para la reputación de la organización en general, sino que el costo puede ser enorme. En el caso de los ataques de ransomware, el coste de recuperación de un apagón es a menudo 10 veces superior a la cantidad exigida como rescate por los atacantes.

Sin embargo, los retos son multifacéticos. Las empresas medianas carecen de recursos y se ven especialmente afectadas por la escasez global de ciberhabilidades. Sus equipos de seguridad, pequeños o inexistentes, tienen la tarea de defender a la empresa tanto de campañas sofisticadas, novedosas y dirigidas, como de rápidos ataques de tipo “smash-and-grab”,  mientras gestionan una plantilla cada vez más distribuida y una infraestructura digital compleja. Estas amenazas son demasiado rápidas o sigilosas para que los seres humanos puedan enfrentarse a ellas y el número de nuevas vías de entrada de los hackers crece a un ritmo demasiado rápido como para que los equipos de seguridad puedan monitorearlas.

El simplemente tratar de impedir que los atacantes entren en los sistemas no funciona ante los ataques avanzados a los que ahora se enfrentan estas empresas. En su lugar, los líderes empresariales deben contener rápidamente los ataques y minimizar las disrupciones, de forma que la organización no se vea afectada negativamente. Emplee estas estrategias para responder eficazmente.

— Vigile y dirija: Una vez que el atacante consolida una cabeza de playa dentro de una organización, es vital que el equipo de seguridad vigile continuamente el comportamiento anormal para detectar las señales de los ataques emergentes. Siempre hay un periodo en el que el atacante tiene un punto de apoyo inicial y está calculando qué movimiento hacer a continuación; este periodo puede utilizarse en beneficio de la empresa.

— Siempre espere una brecha: Las empresas deben poner a prueba sus capacidades actuales y monitorear constantemente si los mecanismos existentes dan suficiente aviso y son capaces de mantener a raya las amenazas el tiempo suficiente para que la empresa pueda actuar. ¿En qué punto del ataque se alerta al equipo de seguridad? ¿Las defensas frenan al atacante, dando al equipo la oportunidad de contraatacar? Segregar las redes dificultará el movimiento lateral del atacante.

— Cree una cultura de seguridad: Los líderes de la empresa deben hablar de la importancia de la ciberseguridad, y todos los departamentos deberían saber que la ciberseguridad es relevante para ellos. La junta directiva debe ser informada regularmente sobre ciberseguridad y los proveedores de seguridad deben participar en este proceso. Lo ideal es que el jefe de seguridad de la información forme parte del equipo de alta dirección.

— Revise su cadena de suministro: Los atacantes están recurriendo a los proveedores o a pequeños vendedores externos para encontrar vulnerabilidades y entrar al corazón de los sistemas críticos. ¿Qué tan robusta es la seguridad de sus proveedores? ¿Disponen de certificaciones externas que verifiquen que se toman la seguridad en serio?

© 2025 Harvard Business School Publishing Corp. | De: hbr.org  |  Distribuido por: The New York Times Syndicate.

Artículo en inglés

In March of last year, artificial intelligence caught a sophisticated, highly targeted cyberattack across multiple businesses. The breach exploited a zero-day vulnerability — an unintentional software or hardware flaw that can be taken advantage of by cybercriminals — and was detected, investigated and contained by the AI. Two weeks later, this campaign was publicly attributed to a Chinese nation-state actor known as APT41. The organizations threatened by the attack included governments entities, critical infrastructure, large enterprises, but also, surprisingly, midsize businesses.

A common misconception exists among cybercriminals that midsize businesses do too little to strengthen their cybersecurity, which makes them appealing targets. They are often used as a thoroughfare to higher-value targets, critical systems and highly classified information. Most companies are planning to make, or have begun making, the sweeping, technology-driven organizational changes that define a digital transformation, and say these adjustments will soon be essential to their competitiveness.

This kind of disruption is intolerable for midsize businesses. Not only are cyberattacks potentially damaging to customer relationships and to the wider reputation of the organization, but the cost can be enormous. In the case of ransomware attacks, the cost of recovery from a shutdown is often 10 times the amount demanded in ransom by the attackers.

But the challenges are multifaceted. Midsize businesses are indeed under-resourced and particularly affected by a global cyber-skills shortage. Small, or nonexistent, security teams are tasked with defending the business from sophisticated, novel and targeted campaigns to very fast-moving smash-and-grab attacks — while managing an increasingly distributed workforce and complex digital infrastructure. These threats are too fast or stealthy for humans to contend with and the number of new avenues for hackers to gain entry is growing at a rate too rapid for security teams to monitor.

Simply trying to stop attackers from getting onto systems doesn’t work for the advanced attacks that these businesses now face. Instead, business leaders must contain attacks quickly and minimize disruption so that the organization isn’t negatively impacted. Employ these strategies to effectively respond.

MONITOR AND TARGET: Once an attacker has gained a foothold within an organization, it is vital that the security team continuously monitor abnormal behavior to detect the breadcrumbs of emerging attacks. There is always a period when the attacker has an initial foothold and is working out what move to make next; this period can be used to a business’ advantage.

ALWAYS EXPECT A BREACH: Companies should test their existing capabilities and consistently monitor whether existing mechanisms give enough warning and are able to hold threats at bay long enough for the company to act. How early in the attack is the security team alerted? Do defenses slow the attacker, giving the team the opportunity to counterattack? Segregating networks will make it difficult for the attacker to move laterally.

CREATE A CULTURE OF SECURITY: Business leaders should be vocal about the importance of cybersecurity, and all departments should know that cybersecurity is relevant to them. The board should be briefed regularly on cybersecurity and security providers should be involved in this process. Ideally, the chief information security officer should be part of the top management team.

SCRUTINIZE YOUR SUPPLY CHAIN: Attackers are turning to suppliers or smaller third-party vendors to find vulnerabilities and get into the heart of critical systems. How robust is the supplier’s security? Do they have external certifications that verify they take security seriously?

Autor

Sobre el Autor

Es CEO de Darktrace.