Cyber Security

Security for SMBs: What It Is and How to Do It Right

Photo: Operate, Defend, Attack, Influence! (PDM 1.0)
In this article5 sections

The short answer

Security for SMBs comes down to four controls that stop the attacks small businesses actually face: multifactor authentication on email and remote access, managed and patched devices, hardened email, and backups that have been restored at least once under test conditions. Small companies rarely fall to exotic exploits. They fall because one of those four was missing, unmanaged, or owned by nobody.

Everything else, from logging pipelines to threat hunting to zero trust rollouts, is an amplifier. Amplifiers make a working program better; they do not substitute for the fundamentals. A practical SMB security program fits on one page, names an owner for each item, and gets re-verified on a calendar. It also has to survive the week your only IT person is on vacation.

How it works

Think in layers, but only the layers a small business can actually operate. Each layer exists to make one specific attack path expensive or noisy for the attacker.

  • Identity. Multifactor authentication on email, VPN, remote desktop, admin consoles, and banking or finance systems. Keep administrator accounts separate from daily-use accounts. Deploy a password manager so staff stop reusing credentials across work and personal logins. Most SMB compromises begin with a valid login, not with malware.
  • Endpoints. Every laptop, desktop, and phone that touches work data belongs in a managed inventory with disk encryption, automatic patching, and endpoint protection that reports somewhere a human looks. Personal devices checking work email are the norm in small firms; make the rule explicit, then enforce it.
  • Email and browser. This is the primary delivery channel for invoice fraud, malicious links, and credential phishing. Publish SPF, DKIM, and DMARC records, tag external senders, filter links and attachments, and keep browsers current. The goal is not zero phishing attempts; it is stopping a click from becoming a compromise.
  • Data and recovery. Backups in more than one location, with at least one copy offline or immutable so ransomware on the network cannot encrypt it, and with backup credentials separate from the main domain. Then restore-test on a schedule and write down the result: date, what was restored, how long it took.
  • Network and remote access. Never expose a desktop protocol directly to the internet; put MFA and a gateway in front of remote access. Separate guest Wi-Fi from business systems, review firewall rules at least annually, and give each role only the access the job requires.

These layers work together as a chain of obstacles: steal a password, then defeat MFA, then land on an endpoint that is patched, then find a mailbox that will not quietly accept a new forwarding rule. You will not block every attempt. You will make cheap, automated attacks fail and force the rest onto paths you can see.

For SMBs specifically, the binding constraint is staffing, not technology. Controls have to be default-on, low-touch, and observable from a single report. That is where a managed service provider or managed security service provider earns its fee: you are buying an outcome such as devices patched, alerts triaged, and restores proven, rather than a pile of licenses. If nobody on staff can read and act on a tool’s output, it belongs on next year’s list. For more on sizing controls to a small-business budget and risk profile, read our guide to tailoring digital security solutions for small and medium-sized businesses.

Why it matters operationally

For a small business, a cyber incident is a business-continuity event before it is a security event. The people who would run the recovery are usually the same people who close the books, approve payments, and keep customers served. Every hour spent in response is an hour not spent on revenue, and the disruption outlasts the technical fix.

Consider a 25-person professional services firm. An employee enters credentials on a lookalike sign-in page. The attacker logs in, reads mail for a week, adds a hidden forwarding rule, and then replies inside a real client thread with updated payment instructions. The client pays the wrong account. Nobody notices until the vendor chases the invoice. The technical cleanup, revoking sessions, resetting the password, and removing the rule, takes an afternoon. The financial and relationship damage takes months, and no backup can undo a payment the firm authorized.

Compare that with ransomware on a shared file server. Even where backups exist, they are often a mapped drive on the same network, encrypted alongside the data that mattered most. Recovery then depends on whether anyone ever verified that the offline copy restores, and on how quickly the business can work without its order system, scheduling, or client records.

The operational consequences follow a predictable pattern: invoicing and cash flow stop or get diverted; payroll and benefits deadlines do not move; contractual uptime and data protection clauses come due; insurers ask about controls at renewal; customers ask questions you may not be able to answer. This is also why security spending should be framed around recovery objectives, meaning how much data you can afford to lose and how long you can be down, rather than around a software shopping list.

What to do about it

Work in priority order. Each step makes the next one easier, and the first four cover the majority of realistic SMB risk.

  1. Turn on MFA for email, remote access, and every administrator account. Use an authenticator app or a hardware key rather than SMS where the system allows it. This single change defeats most credential-based intrusions and returns the most per dollar and per hour of effort.
  2. Fix backups before anything else. Keep at least one copy offline or immutable, restrict who can delete backups, store backup credentials separately from the domain, and put a recurring restore test on the calendar with a written result.
  3. Get every device into a managed inventory. Know what you own, patch automatically, encrypt disks, and retire or isolate machines that fall out of support. You cannot protect hardware you have forgotten about.
  4. Harden email. Publish SPF, DKIM, and DMARC, enable external-sender warnings, block risky attachment types, and require out-of-band verification for any change to bank details or payment instructions.
  5. Separate privileges. Nobody does daily work in an admin account, financial approvals need a second person, and joiner and leaver checklists actually get followed. Forgotten accounts are a standing invitation.
  6. Write down what you would do. A one-page incident card listing who calls whom, who can shut systems down, your legal and insurance contacts, and how to reach your IT provider after hours. Practicing it once is worth more than a shelf of policy documents.
  7. Train people on the attacks they will actually see. Business email compromise, MFA prompts they did not initiate, and helpdesk impersonation calls. Short, specific briefings beat annual slide decks.
  8. Review access and insurance together. Confirm what your policy requires, what it excludes, and whether your current controls would satisfy a claim.
  9. Verify, do not assume. Once a quarter, confirm that MFA is enforced, patches are installing, the last restore test passed, and alerts are being triaged. A control that quietly stopped working looks exactly like one that was never deployed.

A 30-day starting sequence

If little is in place today, week one is MFA on email and administrator accounts plus an inventory of devices and cloud services. Week two is backups: confirm the offline copy exists, restrict access to it, and restore one system end to end. Week three is patching and endpoint protection with a named owner for each device group. Week four is the one-page incident card, an email authentication review, and a short staff briefing on verifying payment changes by phone.

What to skip for now: anything you cannot operate, monitor, or explain. A tool that generates alerts nobody triages adds risk, because it creates the impression of coverage without the reality. Budget spent on fundamentals, such as MFA, patching, tested backups, and email authentication, protects a small business far more reliably than the same money spent on advanced detection it has no capacity to use.

Nathan Cole

Vulnerability management research, Dominion Cyber

Nathan Cole writes about vulnerability management and emerging threat research — why CVSS score alone is a poor prioritisation input, how patch operations actually get run, the mechanics of adversary-in-the-middle phishing, and the security model of AI assistants and browser extensions.

Get the weekly security brief

One email a week: what is worth patching, what is worth watching, and what is worth reading. No spam, unsubscribe any time.