There’s a persistent myth that small businesses are too small to be targeted. The reality is the opposite: attacks are automated, they probe everyone, and smaller companies are attractive precisely because their defences tend to be thinner. The good news — the overwhelming majority of successful attacks exploit basic gaps, and closing those gaps is neither complicated nor expensive.
1. Multi-factor authentication everywhere
If you implement only one thing from this list, make it this. MFA on email, banking, accounting software, remote access and admin accounts blocks the vast majority of account-takeover attempts, even when a password has been stolen. Prioritise email first — a compromised mailbox is the launchpad for invoice fraud and further attacks.
2. A password manager (and no reuse)
Password reuse is how one leaked database becomes a compromise of your business accounts. A password manager makes unique, strong passwords practical for every service, for every staff member.
3. Patching — automatic and universal
Attackers exploit known vulnerabilities in outdated software far more often than they discover new ones. Operating systems, browsers, routers, firewalls and — critically — website platforms like WordPress all need updates applied promptly. Automate wherever possible.
4. Modern endpoint protection
Traditional antivirus isn’t enough anymore. Modern endpoint protection watches for suspicious behaviour — a Word document spawning PowerShell, files being encrypted en masse — and stops it, rather than only matching known virus signatures.
5. Backups that ransomware can’t reach
Ransomware operators actively hunt and encrypt backups before triggering their payload. At least one backup copy must be offsite and disconnected or immutable — beyond the reach of anything on your network. And backups must be test-restored regularly; an unverified backup is a hope, not a plan.
6. Staff awareness
Phishing remains the number one entry point. Staff who know to slow down on urgent payment requests, verify banking-detail changes by phone, and report suspicious emails without fear of blame are a genuine security layer. Short, regular reminders beat an annual lecture.
7. Least privilege and offboarding
Staff should have access to what their job requires — no more. Nobody should do daily work from an administrator account. And when someone leaves, their access must be revoked the same day: email, VPN, cloud apps, shared passwords. Dormant accounts are a favourite way in.
Bonus: know your obligations
Under POPIA, South African businesses are legally required to secure the personal information they hold and to report breaches. Security isn’t only self-preservation — it’s compliance.
Where to start
Don’t try to do everything at once. MFA on email this week. Backup verification next week. A patching routine after that. Steady, boring consistency beats a grand security project that never finishes.
We provide managed cybersecurity for SMEs — endpoint protection, patching, backup management and email security — as part of our managed IT services. Ask us for a no-obligation security review.
