NIST IR 7621 Revision 1 (2016)
Overview of NIST IR 7621 Revision 1
NIST Interagency Report (IR) 7621 Revision 1, published in October 2016, provides updated, practical cybersecurity guidance specifically designed for small businesses, building upon the foundation established in the 2009 version while addressing evolving threats and technologies. Revision 1 maintains the same practical, small business-focused approach as the original while expanding guidance on phishing attacks, malware threats, mobile device security, and cloud services. The update reflects recognition that small businesses face increasingly sophisticated threats and rely on technologies that have evolved significantly since 2009, requiring updated guidance that addresses modern security challenges.
The revision emerged from recognition that cybersecurity threats facing small businesses had evolved significantly since 2009, with phishing attacks becoming more sophisticated, malware threats expanding, and mobile devices and cloud services becoming integral to small business operations. Revision 1 addresses these evolving threats while maintaining the practical, non-technical approach that makes the guidance accessible to small business owners and managers. The update provides expanded guidance on topics that have become more critical for small businesses, ensuring that guidance remains relevant and practical for small business contexts.
NIST IR 7621 Revision 1 applies to small businesses across all sectors, recognizing that cybersecurity risk management is essential regardless of business size or industry. The guidance is particularly valuable for small businesses that handle customer data, process financial transactions, rely on mobile devices and cloud services, or connect to larger business partners. Revision 1's expanded guidance on phishing, malware, and mobile device security makes it especially relevant for small businesses facing these increasingly common threats.
Key Updates and Enhancements in Revision 1
NIST IR 7621 Revision 1 introduces several important updates compared to the 2009 version, reflecting evolving cybersecurity threats and technologies. Understanding these updates helps small businesses transitioning from the 2009 version and enables new implementers to benefit from updated guidance.
Expanded Phishing Guidance: Revision 1 significantly expands guidance on phishing attacks, recognizing that phishing has become one of the most common attack vectors targeting small businesses. The update provides detailed guidance on recognizing phishing attempts, protecting against phishing attacks, and responding to phishing incidents. Small businesses receive practical advice on identifying suspicious emails, training employees to recognize phishing attempts, and implementing technical controls that reduce phishing risk. The expanded guidance helps small businesses protect against increasingly sophisticated phishing attacks that can lead to data breaches, financial losses, and business disruption.
Enhanced Malware Protection: Revision 1 enhances guidance on malware protection, recognizing that malware threats have evolved significantly since 2009. The update provides expanded guidance on protecting against various types of malware including ransomware, spyware, and trojans. Small businesses receive practical advice on implementing antivirus and anti-malware software, protecting against ransomware attacks, and responding to malware incidents. The enhanced guidance helps small businesses protect against evolving malware threats that can disrupt operations, compromise data, and cause financial losses.
Mobile Device Security: Revision 1 adds comprehensive guidance on mobile device security, recognizing that mobile devices have become integral to small business operations since 2009. The update provides guidance on securing smartphones, tablets, and other mobile devices used for business purposes. Small businesses receive practical advice on implementing mobile device security controls, managing mobile device access, and protecting mobile device data. The new guidance helps small businesses address security risks introduced by mobile devices, which have become common attack vectors.
Cloud Services Security: Revision 1 adds guidance on cloud services security, recognizing that small businesses increasingly rely on cloud services for business operations. The update provides guidance on selecting secure cloud service providers, implementing cloud security controls, and protecting data stored in cloud services. Small businesses receive practical advice on evaluating cloud service provider security, implementing cloud security best practices, and managing cloud service risks. The new guidance helps small businesses address security risks introduced by cloud services, which have become essential to many small business operations.
Simplified Best Practices: Revision 1 simplifies best practices for practical implementation, making guidance more actionable for small businesses. The update reorganizes guidance to make it easier to understand and implement, provides clearer recommendations, and includes more practical examples. The simplified approach helps small businesses implement security practices more effectively, ensuring that guidance remains accessible and actionable despite addressing more complex threats.
Framework Applicability and Adoption
NIST IR 7621 Revision 1 applies to small businesses of all types and sectors, providing updated guidance appropriate for organizations with limited resources and technical expertise. The revision maintains the same practical, small business-focused approach as the 2009 version while addressing threats and technologies that have emerged since 2009. Small businesses using the 2009 version should review Revision 1 to understand updates and determine whether to adopt updated guidance.
Small businesses that handle customer data, process financial transactions, rely on mobile devices and cloud services, or connect to larger business partners find Revision 1 particularly valuable. The expanded guidance on phishing, malware, and mobile device security helps small businesses protect against increasingly common threats, while cloud services guidance helps small businesses address security risks introduced by cloud adoption. Revision 1's updates make it especially relevant for small businesses facing modern cybersecurity challenges.
Revision 1's adoption has been driven by small businesses seeking updated cybersecurity guidance, as well as larger organizations requiring their small business partners to implement current security practices. The revision's practical, non-technical approach makes it accessible to small business owners and managers, enabling them to implement updated security practices without requiring extensive technical expertise. Small businesses implementing Revision 1 benefit from protection against evolving threats, improved customer trust, and better ability to meet partner security requirements.
Key Security Recommendations for Small Businesses
NIST IR 7621 Revision 1 organizes cybersecurity recommendations into practical areas that small businesses can understand and implement. The guidance focuses on fundamental cybersecurity practices that provide the greatest protection for limited investment, while addressing evolving threats including phishing, malware, mobile device security, and cloud services.
Protect Against Phishing Attacks
Revision 1 significantly expands guidance on protecting against phishing attacks, recognizing that phishing has become one of the most common attack vectors targeting small businesses. Small businesses must implement protections against phishing attacks that can lead to data breaches, financial losses, and business disruption. The guidance provides practical advice on recognizing phishing attempts, training employees to identify suspicious emails, and implementing technical controls that reduce phishing risk.
Small businesses should train employees to recognize phishing attempts, including suspicious email characteristics, requests for sensitive information, and links or attachments from unknown sources. Training should be provided regularly, updated as phishing techniques evolve, and reinforced through ongoing communication about phishing threats. Small businesses should also implement technical controls including email filtering, spam protection, and web filtering that reduce phishing risk. These controls can be implemented cost-effectively and provide significant protection against phishing attacks.
Small businesses should establish procedures for reporting suspected phishing attempts, ensuring that employees know how to report suspicious emails and that reported emails are investigated promptly. Incident response procedures should address phishing incidents, including steps for containing incidents, investigating compromises, and recovering from phishing attacks. Small businesses should also establish relationships with IT service providers or security experts who can assist with phishing incident response when needed.
Protect Against Malware Threats
Revision 1 enhances guidance on protecting against malware threats, recognizing that malware threats have evolved significantly since 2009. Small businesses must implement protections against various types of malware including ransomware, spyware, trojans, and other malicious software. The guidance provides practical advice on implementing antivirus and anti-malware software, protecting against ransomware attacks, and responding to malware incidents.
Small businesses should implement and maintain antivirus and anti-malware software on all computers and devices, ensuring that software is kept current and scans are performed regularly. Antivirus software should be configured to update automatically, scan files automatically, and provide real-time protection against malware threats. Small businesses should also implement protections against ransomware attacks, including regular backups, user training, and technical controls that prevent ransomware execution.
Small businesses should establish procedures for responding to malware incidents, including steps for containing infections, removing malware, and recovering from malware attacks. Incident response procedures should address various types of malware threats, recognizing that different malware types may require different response approaches. Small businesses should also establish relationships with IT service providers or security experts who can assist with malware incident response, particularly for complex malware infections that may be difficult to remove.
Secure Mobile Devices
Revision 1 adds comprehensive guidance on securing mobile devices, recognizing that mobile devices have become integral to small business operations. Small businesses must implement security controls for smartphones, tablets, and other mobile devices used for business purposes. The guidance provides practical advice on implementing mobile device security controls, managing mobile device access, and protecting mobile device data.
Small businesses should implement mobile device security controls including device encryption, screen locks, and remote wipe capabilities. Mobile devices should be configured securely, with strong passwords or biometric authentication, encryption enabled, and security settings configured appropriately. Small businesses should also implement mobile device management (MDM) solutions or policies that enable centralized management of mobile device security, ensuring that security controls are applied consistently across all mobile devices.
Small businesses should establish policies for mobile device use, including acceptable use policies, security requirements, and procedures for managing mobile device access. Policies should address topics including device ownership (business-owned vs. personal devices), access to business information, and security requirements for mobile devices. Small businesses should also train employees on mobile device security, ensuring that employees understand security risks and follow security procedures when using mobile devices for business purposes.
Secure Cloud Services
Revision 1 adds guidance on securing cloud services, recognizing that small businesses increasingly rely on cloud services for business operations. Small businesses must implement security controls for cloud services including email, file storage, and business applications. The guidance provides practical advice on selecting secure cloud service providers, implementing cloud security controls, and protecting data stored in cloud services.
Small businesses should evaluate cloud service provider security before adopting cloud services, ensuring that providers implement appropriate security controls and meet security requirements. Evaluation should include reviewing provider security practices, understanding data protection measures, and assessing provider security capabilities. Small businesses should also implement cloud security controls including strong authentication, encryption, and access controls that protect data stored in cloud services.
Small businesses should establish policies for cloud service use, including acceptable use policies, security requirements, and procedures for managing cloud service access. Policies should address topics including which cloud services are approved for business use, security requirements for cloud services, and procedures for managing cloud service accounts. Small businesses should also train employees on cloud service security, ensuring that employees understand security risks and follow security procedures when using cloud services for business purposes.
Protect Information Systems and Networks
Revision 1 maintains guidance on protecting information systems and networks, recognizing that fundamental protections remain essential despite evolving threats. Small businesses must implement basic security controls including firewalls, antivirus software, and secure network configurations. The guidance provides practical advice on implementing and maintaining these fundamental protections, ensuring that basic security controls remain effective.
Small businesses should ensure that all systems are protected by firewalls that block unauthorized access, install and maintain antivirus software on all computers, and configure networks securely to prevent unauthorized access. Firewalls should be configured correctly, antivirus software should be kept current, and networks should be secured appropriately. Regular reviews of security configurations help ensure that protections remain effective as systems and threats evolve.
Small businesses should also implement secure wireless network configurations, recognizing that wireless networks represent common attack vectors. Wireless networks should be secured with strong encryption (WPA2 or WPA3), strong passwords, and access controls that restrict network access to authorized devices. Small businesses should disable wireless networks when not needed, change default passwords, and regularly review wireless network configurations to ensure they remain secure.
Control Access to Information Systems
Revision 1 maintains guidance on controlling access to information systems, recognizing that access control remains fundamental to security. Small businesses must implement basic access controls including user accounts, passwords, and access restrictions. The guidance provides practical advice on implementing and maintaining access controls, ensuring that access remains appropriate and secure.
Small businesses should create individual user accounts for each employee, require strong passwords, and restrict access to information based on job functions. Password policies should require strong passwords, password changes should be enforced regularly, and access should be restricted based on job functions. Regular reviews of user accounts and access permissions help ensure that access remains appropriate as employees join, change roles, or leave the organization.
Small businesses should also implement physical security controls that protect information systems from unauthorized physical access. Physical security controls should include locks on doors and windows, access controls for server rooms or areas containing sensitive systems, and procedures for managing visitors and contractors. Small businesses should ensure that sensitive systems are protected from physical access by unauthorized individuals, and that physical security controls are maintained effectively.
Protect Sensitive Information
Revision 1 maintains guidance on protecting sensitive information, recognizing that data protection remains essential despite evolving threats. Small businesses must implement basic data protection controls including encryption, secure storage, and secure disposal. The guidance provides practical advice on implementing and maintaining data protection controls, ensuring that sensitive information remains protected.
Small businesses should encrypt sensitive data, store data securely, and dispose of data securely when no longer needed. Encryption should be implemented for sensitive data at rest and in transit, secure storage should protect data from unauthorized access, and secure disposal should ensure that data cannot be recovered from disposed media. Small businesses should identify what information they collect and store, determine what information is sensitive, and implement protections appropriate for information sensitivity.
Small businesses should also implement backup procedures that protect information from loss, recognizing that data loss can disrupt business operations. Backup procedures should include regular backups of important data, secure storage of backup media, and testing of backup restoration procedures. Small businesses should ensure that backups are performed regularly, stored securely, and can be restored when needed to support business continuity.
Implementation Strategies and Best Practices
Successfully implementing NIST IR 7621 Revision 1 requires small businesses to prioritize security practices, allocate limited resources effectively, and implement controls appropriate for their contexts. Small businesses should begin by understanding their security risks, identifying critical information and systems, and implementing basic protections that provide the greatest protection for limited investment.
Start with Basic Protections: Small businesses should begin by implementing basic security protections that provide the greatest protection for limited investment. Basic protections include firewalls, antivirus software, strong passwords, and regular backups. These fundamental controls provide significant protection against common threats and can be implemented without extensive technical expertise or significant financial investment. Small businesses should prioritize basic protections before implementing more advanced controls.
Address Evolving Threats: Revision 1's expanded guidance on phishing, malware, mobile device security, and cloud services addresses threats that have become more critical for small businesses. Small businesses should review Revision 1's updates, identify areas where threats have evolved, and implement updated protections accordingly. The expanded guidance helps small businesses protect against increasingly common threats that may not have been addressed in the 2009 version.
Implement Phishing Protections: Small businesses should implement protections against phishing attacks, including employee training, email filtering, and incident response procedures. Phishing training should help employees recognize phishing attempts, email filtering should reduce phishing risk, and incident response procedures should address phishing incidents effectively. Small businesses should prioritize phishing protections, recognizing that phishing attacks are among the most common threats targeting small businesses.
Enhance Malware Protection: Small businesses should enhance malware protection, including updated antivirus software, ransomware protections, and malware incident response procedures. Antivirus software should be kept current, ransomware protections should include regular backups, and malware incident response procedures should address various types of malware threats. Small businesses should prioritize malware protection, recognizing that malware threats have evolved significantly since 2009.
Secure Mobile Devices: Small businesses should implement mobile device security controls, including device encryption, screen locks, and mobile device management. Mobile devices should be configured securely, policies should govern mobile device use, and employees should be trained on mobile device security. Small businesses should prioritize mobile device security, recognizing that mobile devices have become integral to business operations and represent common attack vectors.
Secure Cloud Services: Small businesses should implement cloud service security controls, including provider evaluation, strong authentication, and cloud security policies. Cloud service providers should be evaluated for security, cloud services should be configured securely, and policies should govern cloud service use. Small businesses should prioritize cloud service security, recognizing that cloud services have become essential to many business operations and introduce security risks that must be managed.
Establish Security Policies and Procedures: Small businesses should establish basic security policies and procedures that guide employee behavior and establish expectations for security practices. Security policies should address topics including password requirements, acceptable use of information systems, procedures for handling sensitive information, mobile device use, cloud service use, and incident response procedures. Policies should be practical and appropriate for small business contexts, avoiding overly complex requirements that may be difficult to implement or enforce.
Provide Security Awareness Training: Small businesses should provide basic security awareness training to all employees, helping employees recognize security threats and follow security procedures. Training should cover topics including password security, email security, recognizing phishing attempts, mobile device security, cloud service security, and procedures for handling sensitive information. Training should be provided regularly, updated as threats evolve, and reinforced through ongoing communication about security threats and procedures.
Work with IT Service Providers: Small businesses that lack internal IT expertise should work with IT service providers or consultants to implement and maintain security controls. IT service providers can help small businesses implement basic security controls, maintain systems securely, respond to security incidents, and address evolving threats. Small businesses should select IT service providers carefully, ensuring that providers understand small business security needs and can provide appropriate services.
Relationship to Other Frameworks and Standards
NIST IR 7621 Revision 1 exists within a broader ecosystem of cybersecurity frameworks and standards, with important relationships that help small businesses understand how guidance relates to other frameworks. Understanding these relationships enables small businesses to leverage guidance from multiple sources and avoid duplicative efforts.
NIST IR 7621 (2009) provides the foundation for Revision 1, with Revision 1 building upon the 2009 version while addressing evolving threats and technologies. Small businesses using the 2009 version should review Revision 1 to understand updates, particularly for phishing, malware, mobile device security, and cloud services. The transition to Revision 1 typically requires minimal effort, as Revision 1 maintains the same practical approach while providing updated guidance.
NIST Cybersecurity Framework provides comprehensive cybersecurity guidance that small businesses can use to structure their cybersecurity programs. While NIST CSF is designed for organizations of all sizes, NIST IR 7621 Revision 1 provides small business-specific guidance that helps small businesses implement NIST CSF principles in ways appropriate for their contexts. Small businesses can use Revision 1 to understand how to apply NIST CSF concepts with limited resources and expertise, providing a practical bridge between comprehensive frameworks and small business needs.
CIS Controls provide prescriptive technical security controls that can support NIST IR 7621 Revision 1 implementation. While CIS Controls are designed for organizations of all sizes, small businesses can use Revision 1 to understand how to implement basic CIS Controls with limited resources. Small businesses can prioritize CIS Controls based on Revision 1 recommendations, implementing controls that provide the greatest protection for limited investment.
Small businesses subject to sector-specific regulations may find that NIST IR 7621 Revision 1 guidance helps them meet regulatory requirements. For example, small businesses handling healthcare information may find that Revision 1 guidance supports HIPAA compliance, while small businesses processing payments may find that guidance supports PCI DSS compliance. Revision 1's expanded guidance on phishing, malware, and mobile device security may be particularly relevant for meeting regulatory requirements that address these threats.
Common Challenges and Solutions
Small businesses implementing NIST IR 7621 Revision 1 encounter similar challenges related to limited resources, limited technical expertise, evolving threats, and competing priorities. Understanding these common challenges helps small businesses plan proactively and implement security practices effectively.
Addressing Evolving Threats: Revision 1's expanded guidance on phishing, malware, mobile device security, and cloud services addresses threats that have become more critical for small businesses, but implementing protections against these evolving threats can be challenging. Small businesses may struggle to understand new threats, implement appropriate protections, or keep protections current as threats evolve. Solutions include leveraging Revision 1's expanded guidance, working with IT service providers who understand evolving threats, and participating in security information sharing organizations. Small businesses should prioritize protections against the most common threats, implementing controls incrementally as resources allow.
Implementing Phishing Protections: Revision 1's expanded phishing guidance requires small businesses to implement protections against increasingly sophisticated phishing attacks, which can be challenging with limited resources and expertise. Phishing protections require employee training, technical controls, and incident response procedures. Solutions include providing regular phishing training, implementing email filtering and spam protection, and establishing procedures for reporting and responding to phishing attempts. Small businesses should prioritize phishing protections, recognizing that phishing attacks are among the most common threats targeting small businesses.
Enhancing Malware Protection: Revision 1's enhanced malware guidance requires small businesses to protect against evolving malware threats including ransomware, which can be challenging with limited resources. Malware protection requires updated antivirus software, ransomware protections, and malware incident response procedures. Solutions include keeping antivirus software current, implementing regular backups to protect against ransomware, and establishing procedures for responding to malware incidents. Small businesses should prioritize malware protection, recognizing that malware threats have evolved significantly since 2009.
Securing Mobile Devices: Revision 1's new mobile device security guidance requires small businesses to implement security controls for mobile devices, which can be challenging when employees use personal devices for business purposes. Mobile device security requires device encryption, screen locks, mobile device management, and policies governing mobile device use. Solutions include implementing mobile device security controls, establishing policies for mobile device use, and training employees on mobile device security. Small businesses should prioritize mobile device security, recognizing that mobile devices have become integral to business operations and represent common attack vectors.
Securing Cloud Services: Revision 1's new cloud services security guidance requires small businesses to implement security controls for cloud services, which can be challenging when relying on cloud service providers for security. Cloud service security requires provider evaluation, strong authentication, encryption, and policies governing cloud service use. Solutions include evaluating cloud service provider security, implementing cloud security controls, and establishing policies for cloud service use. Small businesses should prioritize cloud service security, recognizing that cloud services have become essential to many business operations and introduce security risks that must be managed.
Limited Resources: Small businesses often have limited budgets, making it challenging to invest in security technologies and services needed to address evolving threats. Security investments must compete with other business priorities, and small businesses may struggle to justify security spending. Solutions include prioritizing security practices that provide the greatest protection for limited investment, leveraging free or low-cost security tools, and working with IT service providers who understand small business constraints. Small businesses should focus on fundamental protections first, building security capabilities incrementally as resources allow.
Limited Technical Expertise: Small businesses often lack dedicated IT or security staff, making it challenging to implement and maintain security controls needed to address evolving threats. Business owners and managers may not have technical expertise needed to implement security controls effectively. Solutions include working with IT service providers or consultants, using security tools designed for non-technical users, and providing training to employees who will manage security. Small businesses should seek IT service providers who understand small business needs and can provide appropriate services at reasonable costs.
Migration from the 2009 Version
Small businesses using NIST IR 7621 (2009) should plan to migrate to Revision 1 to benefit from updated guidance addressing evolving threats and technologies. Migration typically requires minimal effort, as Revision 1 maintains the same practical approach while providing updated guidance.
Migration activities should begin with reviewing Revision 1's updates, particularly for phishing, malware, mobile device security, and cloud services. Small businesses should identify areas where threats have evolved since 2009 and implement updated protections accordingly. Migration should be approached systematically, ensuring that updated guidance is incorporated effectively while maintaining existing capabilities.
Small businesses should update their security policies and procedures to reflect Revision 1's updates, particularly for phishing, malware, mobile device security, and cloud services. The updated guidance may identify new security practices or requirements that should be incorporated into policies and procedures. Small businesses should also update employee training to address evolving threats, ensuring that employees understand current security risks and procedures.
Frequently Asked Questions
What are the key updates in NIST IR 7621 Revision 1?
NIST IR 7621 Revision 1 introduces several important updates compared to the 2009 version, including expanded guidance on phishing attacks, enhanced malware protection, comprehensive mobile device security guidance, cloud services security guidance, and simplified best practices. The updates address threats and technologies that have emerged since 2009, ensuring that guidance remains relevant and practical for small businesses facing modern cybersecurity challenges. Revision 1 maintains the same practical, small business-focused approach while providing updated guidance.
Do small businesses need to migrate from the 2009 version to Revision 1?
While the 2009 version remains valid, small businesses should plan to migrate to Revision 1 to benefit from updated guidance addressing evolving threats and technologies. The migration typically requires minimal effort, as Revision 1 maintains the same practical approach while providing updated guidance. Small businesses should review Revision 1's updates, particularly for phishing, malware, mobile device security, and cloud services, and implement updated protections accordingly.
How does Revision 1 address phishing attacks?
Revision 1 significantly expands guidance on protecting against phishing attacks, recognizing that phishing has become one of the most common attack vectors targeting small businesses. The update provides detailed guidance on recognizing phishing attempts, training employees to identify suspicious emails, and implementing technical controls that reduce phishing risk. Small businesses receive practical advice on identifying suspicious emails, implementing email filtering and spam protection, and establishing procedures for reporting and responding to phishing attempts. The expanded guidance helps small businesses protect against increasingly sophisticated phishing attacks.
What mobile device security guidance does Revision 1 provide?
Revision 1 adds comprehensive guidance on securing mobile devices, recognizing that mobile devices have become integral to small business operations. The update provides guidance on securing smartphones, tablets, and other mobile devices used for business purposes. Small businesses receive practical advice on implementing mobile device security controls including device encryption, screen locks, and remote wipe capabilities, managing mobile device access, and establishing policies for mobile device use. The new guidance helps small businesses address security risks introduced by mobile devices.
How does Revision 1 address cloud services security?
Revision 1 adds guidance on securing cloud services, recognizing that small businesses increasingly rely on cloud services for business operations. The update provides guidance on selecting secure cloud service providers, implementing cloud security controls, and protecting data stored in cloud services. Small businesses receive practical advice on evaluating cloud service provider security, implementing cloud security best practices including strong authentication and encryption, and establishing policies for cloud service use. The new guidance helps small businesses address security risks introduced by cloud services.
Conclusion
NIST IR 7621 Revision 1 (2016) provides essential, updated cybersecurity guidance specifically designed for small businesses to protect their information systems from evolving security threats. The revision builds upon the foundation established in the 2009 version while addressing threats and technologies that have emerged since 2009, ensuring that guidance remains relevant and practical for small businesses facing modern cybersecurity challenges.
Successful NIST IR 7621 Revision 1 implementation requires small businesses to prioritize security practices, allocate limited resources effectively, and implement controls appropriate for their contexts. Small businesses should begin with fundamental protections including firewalls, antivirus software, strong passwords, and regular backups, then implement updated protections for phishing, malware, mobile device security, and cloud services. The guidance's practical, non-technical approach makes it accessible to small business owners and managers, enabling them to implement updated security practices without requiring extensive technical expertise.
By following NIST IR 7621 Revision 1 recommendations, working with IT service providers when needed, and maintaining security awareness among employees, small businesses can protect their information systems, customer data, and business operations from evolving security threats. The investment in updated security protections pays dividends through reduced security incident risk, improved customer trust, better ability to meet partner security requirements, and protection of business operations that small businesses depend on for survival and growth in an increasingly digital and threatened business environment.