Management consultants, accountants, public safety offices, marketing firms, and many more business and professional services organizations are high-value targets for cybercriminals due to the range of confidential client information they handle. Companies in this sector should all have solid security postures — and many do. But there’s still an alarming number of enterprises that do not.
A survey by Hiscox found that 7 out of 10 business and professional services organizations are not prepared for a cyber attack. Worse, 45% reported that they had experienced at least one cyber attack in the past year, while two-thirds had been hit by two or more attacks.
Meanwhile, Security Infowatch reports that 62% of law firms do not have an information security professional and only 41% have documented cybersecurity policies.
The consequences can be devastating. In addition to the financial impact, the reputational damage caused by an attack can be significant. Business services firms are trusted with highly confidential client data, the loss of which can literally be costly, particularly in the light of new regulations like GDPR. Furthermore, these firms are trusted vendors to organizations all over the world, and must maintain vigorous security performance.
A deeper dive into the cyber risk facing business services organizations
In light of these threats, Bitsight’s Data Science team took a closer look at the security performance of organizations in the business services sector. The team collected data as of June 1, 2019 for a range of business services companies, including accounting firms; management consultancies; marketing and advertising agencies; staffing and recruiting firms; professional training and coaching organizations; graphic design companies; organizations specializing in security and investigations; and more.
The first key takeaway is that improvement is required. Bitsight finds that almost half of all Business Services companies do not have Advanced Ratings—meaning they are at a much higher likelihood of breach. Our security ratings range from 250 to 900, with a higher rating equating to a better security posture. Anything above 740 is considered “Advanced”. However, companies with a security rating of 500 or lower are nearly five times more likely to experience a publicly disclosed data breach.
Forty-five percent of these companies were found to have out-of-date systems or unsupported devices. These systems and devices can be difficult to patch and track, making them primary targets for enterprising hackers.

Furthermore, the metrics (below) show that the ports of 44% of business services companies are inherently insecure or vulnerable to cyberattack.

Less than 4% of business services companies had one or more botnet infections within the last three months. This number may seem low, but even one botnet infection can be devastating because it extends beyond a single machine. These infections occur when networks of computers have been compromised or infected with malware.
Bitsight research identified a solid correlation between botnet infections and data breaches. More specifically, companies with a Bitsight botnet grade of B or lower were more than twice as likely to experience a publicly disclosed data breach.

