Think you’d know if your business was being hacked? Here are five common cyber attack misconceptions.

Think you’d know if your business was being hacked? You might be surprised.
Cyber attacks aren’t always obvious, and they don’t always look like the dramatic scenes you see in the films. In reality, an attack can start with something as simple as one convincing email and then develop quietly in the background.
Here are five things we often hear businesses say about cyber attacks and why they’re not always true.
This is one of the biggest misconceptions about cyber attacks.
It’s easy to imagine that a cyber attack would be obvious: computers stop working, files disappear and a ransom note appears on screen, flashing warning signs and alarms blaring.
But many attacks don’t start that way. Attackers can spend time inside a network without making themselves obvious, looking for valuable information, accounts and systems they can access. By the time something visibly goes wrong, they may already have gained significant access.
That’s why having security measures in place to detect unusual activity is so important. You don't want to rely on noticing something is wrong after the damage has already been done.
Antivirus and endpoint security are an important part of protecting your business, but they’re not some magic shield that makes your business impenetrable.
Modern attacks can involve phishing, stolen credentials, compromised accounts, social engineering and other techniques that don't necessarily rely on traditional malware.
Think of your cybersecurity as layers of protection rather than one tool doing everything. MFA, email security, endpoint protection, secure backups, staff awareness, monitoring and good security policies can all play a part in reducing your risk.
If one layer is bypassed, you want others there to help prevent an attacker from getting further.
It’s understandable to think cyber criminals would only be interested in large organisations with lots of money and valuable data.
Unfortunately, that isn't necessarily the case. Businesses of all sizes can be targeted, and attackers can use automated tools to find vulnerable systems, accounts and devices at scale.
For some attackers, it isn't about specifically choosing your business. If they find an opportunity, they may take it. Being a smaller business doesn't mean you're not worth targeting. It means having sensible security measures in place is just as important.
Backups are incredibly important. But having a backup doesn't automatically mean you're protected from a cyber attack.
You need to know:
A backup that doesn't work when you need it isn't much use. Regularly testing your backups and having a clear recovery plan can make a huge difference if your business is hit by ransomware or another disruptive attack.
Your IT team can be a crucial part of dealing with a cyber attack, but they shouldn't be expected to figure everything out once an incident has already happened.
When an attack happens, there can be a lot to deal with very quickly.
Who needs to know?
Who makes the decisions?
Who contacts customers or suppliers?
Who communicates with staff?
Which systems should be shut down?
How will you recover?
Having an incident response plan means you don't have to work all of this out under pressure. It also means everyone knows what their role is and what needs to happen next.
The biggest problem with these misconceptions is that they can give businesses a false sense of security.
You might have antivirus. You might have backups. Your staff might know not to click suspicious links. But what happens when something gets through?
That's exactly what we're going to explore in our upcoming live cyber attack webinar.
We'll demonstrate how an attack can unfold, what an attacker could do once they're inside and the warning signs businesses should be looking out for because understanding what an attack actually looks like is one of the best ways to be prepared for one.
Date: November 3rd, 11am