
Published on: February 28, 2025 Updated 2 times since publishing
Cybersecurity is full of myths, misunderstandings, and outright dangerous advice.
But what if we could clear up the confusion once and for all?
In this new interview series by SafetyDetectives, I invite cybersecurity experts to expose the biggest yet overlooked misconceptions affecting our online security, and give us practical tips to avoid them.
Jennifer King is a prominent figure in the decentralized technology sector, particularly known for her role as the Co-Founder and CEO of DeStor, a company focused on making decentralized storage scalable and profitable for businesses.
If you could erase one cybersecurity myth from people’s minds forever, what would it be, and why?
“Ransomware only targets large corporations.”
Ransomware attacks often target small businesses, schools, healthcare facilities, and individuals, as they may lack the resources to defend against or recover from an attack.
One reason why this myth is still so common is the media, which often focus on the larger, more celiacous attacks. Many people assume hackers only want to go after “big fish” with deep pockets. In reality, attackers often prefer easy targets, and small businesses, schools, and individuals typically have weaker security, making them low-hanging fruit.
Can you share a real-world example of what happens when people believe this myth?
As a stark reminder that no organization is immune to cyber threats, a very recent example local to me was the January 2025 cyberattack on the Toronto District School Board (TDSB). The attack compromised sensitive data dating back to 1985, targeting PowerSchool, a widely used student information system.
Between December 22 and 28, 2024, unauthorized access exposed names, dates of birth, health card numbers, home addresses, and medical records of current and former students, as well as staff.
This incident highlights just how vulnerable educational institutions are—especially when cybersecurity is underfunded or overlooked. Schools, like businesses, store highly sensitive personal data, making them prime targets for cybercriminals. This breach reinforces the need for proactive security measures, including encrypted, decentralized technologies like Filecoin, to help protect critical data from being stolen or held hostage.
EDITOR’S NOTE
In 2024, the average ransom payment increased to $2.73 million, up from $1.82 million in 2023. However, if we include expenses for restoring systems, hiring external consultants, legal fees, etc., the total amount can be significantly higher. Some reports suggest an average total cost that can go up to $10 million.
On top of that, companies victim of ransomware must also face a series of troubles, like loss of reputation, temporary or permanent shutdowns of their systems, data losses, identity theft, and more.
Is anyone profiting from keeping this myth alive, and how exactly?
Yes, cybercriminals continue to exploit vulnerabilities in small and medium-sized businesses (SMBs), and underfunded organizations, leading to significant financial gains.
Recent statistics from 2024 highlight this ongoing threat:
- Prevalence of Attacks on SMBs: Approximately 43% of cyberattacks now target small businesses.
- Financial Impact: On average, SMBs lose $25,000 per cyberattack, with some incidents resulting in much higher losses.
- Insurance and Preparedness: Only 17% of small businesses have cyber insurance, and 64% are not familiar with it. Additionally, 47% of businesses with fewer than 50 employees have no cybersecurity budget.
- Public Sector Breaches Due to Social Engineering: In 2024, Services Australia reported 49 data breaches resulting from social engineering attacks, a significant increase from previous years. Scammers utilized stolen information from prior hacks to access customer accounts, leading to unauthorized disclosures of sensitive data.
What does reality look like, and what’s the best way for people to accept and act on it?
The reality is that cybercriminals increasingly target small businesses and individuals, exploiting weak security and lack of preparedness. Ransomware, data breaches, and phishing attacks are now automated and scalable, making no organization too small to be at risk.
Businesses should combine proactive security measures, like multi-factor authentication, employee training, and robust backup strategies, with decentralized storage solutions like Filecoins that provide added protection by eliminating single points of failure, ensuring data integrity, and offering tamper-proof, cost-effective backups. This mix of strong cybersecurity practices and blockchain-based storage, allows businesses to reduce their exposure to attacks and enhance resilience.
What role does the media, governments, and other organizations play in fixing this issue?
The media can play a crucial role in raising awareness by reporting on cyberattacks, educating businesses on emerging threats, and debunking cybersecurity myths.
However, sensationalizing only high-profile breaches can reinforce misconceptions that cybercrime targets only large corporations, leaving small businesses unprepared.
The media must focus on consistent cybersecurity education and highlighting REAL-world attacks on SMBs to encourage proactive defenses.
Governments should influence cybersecurity readiness through regulations, incentives, and law enforcement actions against cybercriminals. Policies like GDPR (Europe) and CCPA (California) enforce strict data protection standards, while cyber grants and funding help SMBs improve their security posture. Agencies like CISA (U.S.) and NCSC (U.K.) provide security frameworks and response protocols, but more investment is needed in public-private partnerships to combat ransomware and cyber threats at scale.
Tech Companies and Cybersecurity Organizations also play a critical role by developing accessible, affordable security solutions and offering training for businesses with limited resources. Web3 and blockchain-based storage technologies, like Filecoin, contribute by enabling decentralized, tamper-proof backups that prevent ransomware by encrypting critical data. Partnerships between cybersecurity firms, blockchain projects, and enterprises can enhance cyber resilience through decentralized solutions, secure cloud alternatives, and zero-trust frameworks.
Ultimately, collaboration among media, governments, and private sector organizations is key—raising awareness, enforcing better security standards, and promoting technologies that reduce cyber risk.
To wrap up, If there’s one takeaway you wish people to bring home from this conversation, what would it be?
No one is too small to be targeted, and data is your most important asset.
Cyber threats are automated, relentless, and increasingly aimed at those with weaker defenses.
Businesses, organizations and individuals must take proactive steps—from strong passwords and backups to leveraging decentralized storage like Filecoin for added security. Cyber resilience isn’t just for big corporations; it’s essential for everyone.
How can our readers connect with you?
LinkedIn: https://www.linkedin.com/in/jenniedking
X: https://x.com/_de_jen_king_
Data sources:
- https://www.packetlabs.net/posts/the-top-cybersecurity-statistics-for-2024/?utm_source=chatgpt.com
- https://cpf-coaching.com/blogs/small-business-cyber-attack-statistics-2024-a-wake-up-call-for-smbs?utm_source=chatgpt.com
- https://www.strongdm.com/blog/small-business-cyber-security-statistics?utm_source=chatgpt.com
- https://www.theguardian.com/australia-news/2024/sep/29/services-australia-hacks-data-breach-scam?utm_source=chatgpt.com