Most small organisations do not get compromised through sophisticated attacks. They get compromised through ordinary gaps that were known, unglamorous and unfunded.
None of the following requires a security team. All of it requires a decision and somebody accountable for keeping it working.
1. Multi-factor authentication everywhere it is supported
The single highest-return control available. Credential stuffing and phishing both become dramatically less effective when a password alone is insufficient.
Priority order: email first, because email compromise cascades into password resets everywhere else. Then financial systems, cloud tenancies, VPN, and any administrative access.
Use an authenticator app or hardware key in preference to SMS where the choice exists.
2. Tested backups, including one offline copy
Backups are your only reliable recovery from ransomware. "We back up nightly" is not a control; "we restored successfully last quarter" is.
Minimum standard:
- backups run automatically, not by somebody remembering
- at least one copy is off-site or in a separate cloud tenancy
- at least one copy is immutable or offline, so ransomware cannot encrypt it
- a full restore is tested quarterly and the result is written down
- you know your recovery time in hours, and it is acceptable to the business
3. Patching on a schedule, with a deadline for critical fixes
Most exploited vulnerabilities have a published patch available well before the attack.
Set a written standard: critical patches applied within seven days, everything else within thirty. Enable automatic updates where they are safe, and track exceptions rather than letting them accumulate silently.
Include the things people forget: routers, firewalls, network equipment, printers, and any software running on a server that nobody logs into.
4. Access that matches the job, reviewed twice a year
Most organisations have far more standing access than anyone needs. Ex-employees retain access, contractors keep credentials after projects end, and everyone ends up an administrator because it was easier than working out the right permission.
Do this:
- remove administrative rights from accounts that do not need them
- run a joiner-mover-leaver process with same-day revocation
- review all access twice a year, with a named approver per system
- delete or disable dormant accounts
- use shared mailboxes and generic logins nowhere except where genuinely unavoidable
5. Endpoint protection on every device
Not the free consumer antivirus that came with the laptop. Modern endpoint protection with centralised visibility, so somebody can see when a device stops reporting.
Include the devices people bring. If you cannot protect it, do not let it hold company data.
6. A written incident response plan, and one rehearsal
The plan does not need to be long. It needs to answer, before anything happens:
- who is contacted first, with phone numbers, including out of hours
- who has authority to take a system offline
- who decides whether to notify clients, regulators or law enforcement
- where the backup restoration procedure lives and who has performed it
- what the external support arrangement is, if you have one
Print it. Store a copy somewhere accessible when your network is down — which is exactly when you will need it.
Then rehearse it once. A two-hour tabletop exercise finds more gaps than a year of planning documents.
7. Staff awareness that reflects how people actually get caught
Annual compliance videos with a multiple-choice test do not change behaviour.
More effective and barely more expensive:
- short, specific briefings on the attacks actually targeting your sector
- simulated phishing with coaching rather than punishment for those who click
- a clear, blame-free route to report something suspicious quickly
- explicit rules on payment changes, since invoice fraud is where the money actually goes
The payment-change rule deserves emphasis. A verbal or written confirmation to a known contact before any change of bank details prevents a category of loss that no technical control catches.
8. Know what you have
You cannot secure an inventory you do not have. Most organisations are surprised by what turns up.
Record: every device, every server, every cloud service, every SaaS subscription with company data in it, every domain and DNS record, every administrator account, and every third party with access to your systems.
Review it quarterly. Shadow IT is normal and mostly harmless — until it holds your customer data and nobody knows it exists.
Sequencing if you can only do three
If budget allows only three this quarter, do them in this order:
- Multi-factor authentication on email and financial systems
- Tested, immutable backups with a documented restore
- The payment-change confirmation rule, communicated to everyone who can authorise a transfer
Those three address the majority of realistic loss scenarios for a small organisation, and none of them costs significant money.
What good looks like a year from now
Not a certificate on the wall. Rather: MFA coverage at 100% of accounts that support it, a restore test completed in the last quarter with a written result, patching within your stated deadlines, an access review completed in the last six months, and every member of staff able to tell you what to do if they think something is wrong.
That is an achievable baseline, and it puts you ahead of most organisations your size.
Applying this to your own organisation?
We would rather diagnose your situation than sell you a product. Book a call and we will tell you honestly whether this is worth doing now, later, or not at all.