SNM Support

Cybersecurity for small business — 10 essential measures

A common belief is: "We're a small company — hackers aren't interested in us." The reality is exactly the opposite. Small businesses are a preferred target precisely because they rarely have adequate protection.

The statistics speak for themselves: over 43% of cyberattacks target small businesses. The average cost after a successful attack exceeds $200,000 — enough to close most small companies.

The good news: most of this risk can be eliminated with relatively simple measures. Here are the 10 you should start with.

Measure 1: Strong passwords and a password manager

Weak passwords are behind over 80% of breaches. "123456" and "password1" protect nothing.

What to do:

  • Use at least 12 characters, mixing upper/lowercase letters, numbers, and symbols
  • Use a different password for every service
  • Use a password manager (Bitwarden, 1Password) — free or cheap, and it saves a huge amount of trouble

Measure 2: Two-factor authentication (2FA) everywhere

Even if your password is stolen, 2FA blocks access. Turn it on for:

  • Email (Google Workspace, Outlook)
  • Financial systems and banking
  • Cloud services (OneDrive, Google Drive, Dropbox)
  • Social media and ad accounts

Apps like Google Authenticator or Authy make the process easy.

Measure 3: Regular data backups

In a ransomware attack, a backup is the only thing that saves you without having to pay the ransom.

  • Back up daily to at least two types of media (local + cloud)
  • Regularly test that the backup can actually be restored
  • Keep at least one copy offline (without a permanent internet connection)

Measure 4: Update everything — regularly

Outdated software is full of vulnerabilities that hackers know about. Updates patch them.

  • Enable automatic updates on Windows/macOS
  • Regularly update all applications (browsers, Office, accounting software)
  • Don't forget the firmware on routers, printers, and cameras

Measure 5: Antivirus and endpoint protection

Free antivirus software offers basic protection. For a business environment we recommend more serious solutions:

  • Bitdefender Business, ESET Endpoint Security, Malwarebytes for Teams
  • Centralized management — monitor all devices from one place
  • Scan periodically, not just in real time

Measure 6: Employee training

The human factor is the weakest link. Over 90% of successful cyberattacks start with phishing — a fraudulent email that tricks an employee into clicking.

Train your team to recognize:

  • Suspicious emails demanding urgent action
  • Links leading to unfamiliar sites
  • Unexpected attachments
  • Fake invoices or payment requests

Measure 7: Network segmentation

Split your network into segments (VLANs). If one device is compromised, segmentation limits how far the threat can spread:

  • Workstations on their own segment
  • IoT devices (cameras, printers) on a separate one
  • Guest Wi-Fi — with no access to internal resources

Measure 8: Access control for data

Not every employee needs to see everything. The principle of "least privilege" means: grant access only to what's necessary for the job.

  • Define roles and permissions in Windows via Active Directory or local user accounts
  • When an employee leaves — immediately disable the account
  • Regularly review who has access to what

Measure 9: Secure email communication

Email is the primary attack vector. Protective measures:

  • Enable SPF, DKIM, and DMARC for your domain (reduces the risk of spoofing)
  • Use spam and anti-phishing filters
  • If you use Microsoft 365 or Google Workspace — turn on advanced protection
  • Don't open attachments from unknown senders

Measure 10: Have an incident response plan

Even with excellent protection, an incident can still happen. It's important to know what to do:

  • Who needs to be notified immediately (IT, management)?
  • How do you isolate the affected device?
  • When and how do you notify customers (if their data is affected — GDPR requires it)?
  • How do you restore from backup?

Have a written plan — even a one-page one.

Cybersecurity is not a one-time task

Security is a process, not a product. Threats change, systems get updated, employees come and go. Regular review is essential.

SNM Support offers cybersecurity consulting for small and medium businesses — assessing your current level, giving recommendations, and rolling out measures step by step. Get in touch with us for a free initial consultation.