Small, Medium Biz Uncertain on Breach Rules

AUSTIN, Texas—Although 47 states have security breach notification laws, which require organizations that store sensitive information to notify customers and clients if their personal data is breached, only one-third of small and midsize businesses say they are “very confident” of what those laws require, according to a new study.

Software Advice 1

The study, from SoftwareAdvice.com, also found that just 49%  of small and midsize businesses (SMB) say their company already has a breach response plan in place, but 82% of decision-makers at those companies report that they do encrypt customer information.

The study’s findings are being released at the same time President Obama has proposed new federal laws that would require organizations to alert customers within 30 days of discovering that their personal information had been exposed in a data breach. Congress has yet to act on that proposal. Alabama, South Dakota and New Mexico are the only states without breach notification laws.

Most data breach notification laws kick in any time an individual’s personally identifiable information (PII) is breached, such as social security numbers, credit card numbers, etc. Timing is critical, SoftwareAdvice.com noted, as analysts have stressed that once a breach occurs criminals move to instantly monetize it.

Other Findings

Among the findings in the SoftwareAdvice.com survey of SMBs that were asked about their knowledge of their respective state’s breach notification laws:

  • 33% of respondents are “very confident,” while 34% described themselves as “moderately confident.”
  • Another one-third, combined, are largely (19%) or completely (14%) unaware of their state’s breach disclosure requirements.

While Target and Home Depot get the headlines, SoftwareAdvice.com pointed to research by Symantec that found that targeted attacks on SMBs accounted for 30% of all “spear phishing” attacks in 2013.

So what are SMBs doing to prepare for a cyberattack? SoftwareAdvice.com asked that question, and found:

* 49% reported they do have a plan in place to respond.

* 74% daid they have done security awareness training for staff (but that could be as simple as having watched a video).

* 59% said they have conducted policy compliance tests.

* 58% said they conduct regular vulnerability assessments.

* 29% said they have purchased “cyber insurance,” but SoftwareAdvice.com opined that many may misunderstand their coverage, and may not have the cyber-insurance coverage they believe they have.

* 9% don’t have any of these common preparations in place.

Finally, when SMBs were asked how they handle customer data:

  • 82% said they are encrypting their customers’ PII.
  • * 9% said they are “unsure” if they encrypt customer data.
  • 9% said they do not encrypt customer data.
Software Advice 2
Software Advice 3
Section: Standard
Word Count: 681
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-news/Small-Medium-Biz-Uncertain-on-Breach-Rules