Ten years ago, when a small-business owner told me, “Why would anyone hack us? We’re too small,” I could at least understand the logic.
The picture most people had of a hacker was someone highly technical sitting at a computer, choosing a target, researching the company, finding a weakness, and spending considerable time trying to break in. If an attack required that much expertise and effort, why go after a 40-person engineering company, accounting firm, manufacturer, or distributor when much larger companies had more money and more valuable information?
Cybercrime has always been a business. What has changed, particularly over the last five to ten years, is who can participate and the scale at which they can operate. Capabilities that once required significant technical knowledge can now be bought, rented, or accessed as a service. Phishing kits, stolen credentials, malicious infrastructure, and ransomware operations are available to people who don't necessarily have the expertise to build any of them themselves. Automation makes it possible to search for weaknesses and send attacks across enormous numbers of potential victims, while AI is making convincing emails, impersonation, research, and social engineering easier and faster.
That changes the economics of attacking a small business. An attacker doesn't necessarily have to research your company and decide that you are worth the effort. The cost of casting a very large net has become low enough that they can simply see what they catch.
You don't have to be important enough to be specifically targeted. You just have to be reachable.
That doesn't necessarily mean small businesses are the preferred target. It is more useful to think about their exposure to danger. A small company uses many of the same technologies as a large enterprise—Microsoft 365, cloud applications, laptops, mobile phones, remote access—but usually doesn't have the security staff and resources of a Fortune 500 company. When an automated attack casts a wide net, the smaller company may therefore have fewer layers between the attacker and the business.
The data supports the concern. Verizon's 2025 Data Breach Investigations Report found ransomware involved in 88% of breaches among SMBs in its dataset, compared with 39% among larger organizations. Across organizations of all sizes, stolen credentials, exploitation of vulnerabilities, and phishing remained among the leading known ways attackers initially gained access.
So the old question, “Why would someone attack us?” isn't very useful anymore.
A better question is:
If they try, how difficult have we made it for them to succeed—and what happens if they do?
What Does a Small Business Actually Need for Cybersecurity?
A small business needs more than antivirus, a firewall and MFA. A practical cybersecurity program should protect the main ways attackers can reach the business—email, identities, computers, browsers, cloud applications and employees working outside the office—while also providing security monitoring, employee education, incident response and tested recovery.
For most small and midsize businesses, the CIS Controls provide a practical way to organize those protections. CIS Implementation Group 1, or IG1, is specifically designed as a starting point for essential cyber hygiene and includes 56 foundational safeguards intended to defend against common attacks. As a company's risks and complexity increase, additional CIS safeguards can be added.
The easiest way to understand why all of those pieces matter is to think about Swiss cheese.
Cybersecurity Is Like Swiss Cheese
There is no security product I can install that makes a business secure.
There is no firewall that stops everything. No email filter catches every malicious message. Employee training doesn't prevent every mistake. Multifactor authentication can be defeated in some circumstances. Endpoint protection doesn't detect or block every threat. Monitoring doesn't prevent someone from attempting an attack; it helps us recognize when suspicious activity is occurring so we can investigate, contain and respond.
Think of cybersecurity as a stack of Swiss cheese. Every slice has holes.
The objective isn't to find the magical slice without holes. It doesn't exist. The objective is to stack different layers so that a hole in one is covered by another.
A malicious email gets through the email filter, but the employee recognizes it. The employee doesn't recognize it and clicks, but the website is blocked. The site isn't blocked and the employee enters a password, but the attacker can't satisfy the second authentication requirement. The attacker finds a way around that, but unusual activity is detected and the account is shut down before significant damage occurs.
Each layer makes the attack more difficult or gives us another opportunity to recognize and stop what is happening.
That is why I prefer talking about a security program rather than a security product or even a “security stack.” Products matter, but they are only pieces of a layered approach to cybersecurity.
The easiest way for a business owner to understand those pieces is to look at the places where attacks actually reach the business.
Email: Still One of the Most Important Doors
Email remains an obvious place to start because it gives criminals something extremely valuable: direct access to your employees.
A malicious email doesn't necessarily look malicious anymore. It may appear to come from a vendor, a client, Microsoft, a bank, or even another employee whose real email account has already been compromised.
Sometimes the goal is to get someone to open a file or click a link. Sometimes it is to steal a password. Sometimes there is no malware involved at all. The criminal simply wants someone in accounting to change banking information or send money somewhere it shouldn't go.
The first layer should happen before the employee ever sees the message. Modern email protection can examine messages, links, attachments, sender behavior, and other characteristics and stop a significant amount of malicious email. Some messages will still get through, and that's where the employee becomes another security layer.
Security education shouldn't attempt to turn employees into cybersecurity professionals. They need to understand patterns: unusual urgency, unexpected changes to payment instructions, requests for credentials, unexpected attachments, requests to bypass a normal procedure, or something that simply doesn't fit the way the supposed sender normally communicates.
There also needs to be an easy way to ask for help. If an employee isn't sure whether an email is legitimate, you want them asking IT rather than making a judgment because they're worried about bothering somebody.
The same applies after a mistake. If someone clicks something and then thinks it might have been malicious, the best outcome is an immediate phone call. A company where employees hide mistakes because they fear being blamed has created a cybersecurity problem for itself.
Fast reporting should be encouraged, not punished.
Security culture is one of the layers too.
The Browser: Where Much of the Business Now Lives
Think about how much of your company employees access through a browser: Microsoft 365, banking, payroll, CRM, ERP, accounting applications, SharePoint, file storage, vendor portals, AI services, insurance and benefits.
The browser has effectively become a doorway to much of the business, and that creates opportunities for criminals. A user may click a link and arrive at a website that looks almost identical to Microsoft's login page. They enter their email address and password, and the attacker now has both.
This is one reason multifactor authentication, or MFA, became so important. A stolen password alone shouldn't be enough to access an account. Attackers, however, adapted.
Some attacks try to convince employees to approve an authentication request they didn't initiate. Others attempt to intercept an already authenticated browser session. Instead of simply stealing your password and trying to log in later, the attacker tries to steal the digital information that tells a website, in effect, “this person already logged in successfully.”
This is often called session-token theft.
The business owner doesn't need to understand the mechanics. The important lesson is that having MFA does not mean identity security is finished.
Some forms of MFA are also more resistant to phishing than others. SMS codes and simple approval prompts can be manipulated in ways that stronger authentication methods are specifically designed to resist. The security industry is increasingly moving toward these phishing-resistant approaches.
The browser therefore needs multiple layers too: protection against known malicious websites, properly secured devices, strong identity protection, appropriate access controls, and employees who recognize when something doesn't look right.
A password plus MFA is much better than a password alone. It still isn't a force field.
Chat and Collaboration: A Message Feels Safer When It Comes From a Coworker
Email isn't the only inbox anymore.
Teams, Slack and other collaboration platforms have become part of everyday business communication, and that creates another path to employees.
People may be suspicious of an unexpected email but much less suspicious of a message that appears inside a company collaboration system. If a coworker's account has been compromised and a message arrives saying, “Can you look at this?” followed by a link, the recipient has a reason to trust it.
The same principles therefore have to extend beyond email. Employees shouldn't be taught simply to “watch out for phishing emails.” They should understand suspicious behavior and requests, regardless of whether those arrive through email, Teams, text message, a shared document, or another application.
Security awareness has to evolve with the way people actually communicate.
Phone and Text Attacks Often Require a Business Process
A criminal doesn't have to attack your computer. They can call you. They can send a text. They can pretend to be your bank, your IT provider, your CEO, a vendor, or Microsoft support.
AI makes this problem more difficult because the quality of impersonation is improving. The lesson for employees can't simply be, “Listen for something strange in the person's voice.”
Business procedures become a security layer.
If someone asks you to change banking instructions, send money, provide credentials, disclose sensitive information, or bypass an established process, there should be a verification procedure. And the verification needs to use a channel you already trust.
If someone sends a text saying, “I'm the CEO, here's my new number, please wire this money,” calling that new number isn't verification.
Call the number you already have.
A useful rule is:
When a request involves money, credentials, sensitive information, or changing an established process, verify it through a second trusted channel.
This is one of the places where a good business process can provide better security than another product.
The Computer: Where All of This Comes Together
The laptop or desktop is where employees open email, browse the web, use cloud applications, join meetings, access files and do their work. That makes the device another important layer.
Software contains vulnerabilities. When vendors discover those weaknesses, they release updates. Consistently installing those updates isn't exciting, but it remains one of the fundamentals of cybersecurity. Vulnerability exploitation accounted for 20% of known initial access in Verizon's 2025 breach data and had increased 34% from the prior year's report.
The computer should also have security software watching for suspicious activity. Sensitive information on laptops should be protected if the device is lost or stolen. Employees generally shouldn't have more administrative power over the computer than they need to do their jobs. Businesses should have some control over what software can run.
None of these is perfect individually. The value comes from layering them.
And simply installing security software doesn't answer another important question:
What happens when it detects something?
The Cloud Is Another Environment That Has to Be Secured
There is a common misconception about cloud services:
Microsoft runs Microsoft 365, so Microsoft secures it.
Microsoft has responsibility for securing the enormous infrastructure on which the service operates. But that doesn't mean your company's particular Microsoft environment is automatically configured securely.
Who has administrator access? Are former employees still present? What applications have been granted access to company information? How is external sharing configured? What happens when someone logs in under unusual circumstances? Which employees can access sensitive information? Are the security features you're paying for actually configured? Who reviews security alerts?
The same questions apply to many cloud systems.
Moving an application to the cloud transfers some responsibilities to the cloud provider. It doesn't transfer every security decision.
Buying security capabilities and operating them properly are two different things.
The cloud is another environment that needs deliberate configuration, access control, monitoring and maintenance.
The Office Firewall Doesn't Follow You Home
There was a time when the physical office created a convenient security boundary. Employees were in the building. Computers were in the building. Servers were often in the building. Internet traffic passed through the company's firewall.
The firewall was effectively the front gate.
That's no longer how most businesses work.
An employee takes a laptop home. Tomorrow they're at a client's office. Next week they're in a hotel. They connect to Microsoft 365 directly. They use cloud applications from a coffee shop. They join Teams from an airport.
The firewall sitting in the office can't inspect traffic that never goes through the office.
That doesn't mean firewalls are obsolete. It means the office can no longer be the only place where security exists.
The protection has to follow the employee and the device. Internet access can still be filtered. Malicious destinations can still be blocked. Access to business systems can still be controlled. The computer can still be protected and monitored. Security policies can continue to apply regardless of whether the employee is sitting at headquarters or in a hotel room.
The industry commonly refers to this broader approach as SASE—Secure Access Service Edge.
Business owners don't need to remember the acronym. Remember the principle:
If your employees can work from anywhere, your security needs to work there too.
Your Employees Aren't the Weakest Link
I don't particularly like the common cybersecurity phrase that employees are “the weakest link.”
Employees are part of the security system.
Technology can filter an email, but an employee may recognize that a request from a real vendor is unusual. Software may allow a transaction, but an accounting employee may notice that the banking instructions suddenly changed. A security product may not know that the CEO never asks employees to buy gift cards. The receptionist might.
Good training teaches people to recognize patterns and gives them simple rules for situations where the potential consequences are significant. But training alone isn't enough. Culture determines what happens next.
People need to feel comfortable saying, “I think I made a mistake,” “I clicked this,” “This request seems strange,” or “Can somebody check this before I proceed?”
The sooner the technology team knows, the sooner it can investigate.
Your employees will occasionally make mistakes because they're human. That's one of the holes in the cheese. Build other layers around them rather than pretending you can train the holes away.
Eventually, Assume the Holes Will Line Up
Imagine the layers fail.
A convincing email reaches an employee. They click. The fake site isn't blocked. They enter their credentials. The attacker manages to get around another authentication layer.
At 2:13 Saturday morning, the account starts doing something unusual.
Now we get to one of the most important—and most overlooked—parts of cybersecurity.
Who is watching?
A security product generating an alert is not the same thing as a security program responding to an incident.
Someone has to receive the alert, determine whether it is legitimate and have enough information and expertise to investigate. If the activity is malicious, someone may need to disable an account, isolate a computer, block access, preserve information for investigation, or escalate the incident.
Some of this can happen automatically. Security systems can block a malicious connection, isolate a computer, restrict an account, or trigger other predefined actions. Increasingly, AI and automation can also help analyze alerts, correlate information from different systems, and determine which events deserve immediate attention. SOC analysts can investigate further and take actions that have already been authorized.
Automation has limits, however. Eventually there are situations where somebody has to make a decision based on knowledge of the environment and the business.
Should we disable the CEO's account in the middle of an important transaction? Is an unusual login actually an employee traveling? Can we isolate a production server without stopping the business? Does this activity indicate one compromised computer or something affecting the entire environment?
Those aren't simply technical questions. Someone needs to understand the environment, the potential business impact, and who has the authority to make the decision.
This also has to work when your IT person is sick, on vacation, asleep, or sitting on an airplane.
This is one reason modern IT has become difficult for one person to cover alone.
This is the business purpose behind continuous security monitoring and a Security Operations Center, or SOC.
An SMB doesn't necessarily need to build its own SOC. In most cases that would make little economic sense. An MSP may use specialized SOC services and security partners as part of providing that coverage.
What matters to the business is the outcome.
What can the SOC do automatically? What can its analysts do? When does something get escalated? Who knows your environment well enough to make the decisions the SOC cannot make? And who is ultimately responsible for making sure something happens?
Those are much more useful questions than asking which monitoring product your company owns.
Detecting an Attack Is Only Useful If Someone Knows What to Do
Suppose we confirm that an employee's account has been compromised.
Some immediate actions may already have been taken by security software, automation, AI-assisted systems, or SOC personnel. Perhaps a device has been isolated or an account temporarily restricted.
But that isn't necessarily the end of the incident.
Who determines what the attacker actually did? Did they access email? Did they create forwarding rules? Did they access files? Did they impersonate the employee? Are any other accounts involved? Does the account need to remain disabled? Is there evidence that another system has been compromised?
At some point, the people responding need knowledge of the company's environment. They need to understand what systems are important, what normal activity looks like, which actions could disrupt the business, and who has the authority to make those decisions.
Then there are business questions. Who informs company leadership? Does the cyber-insurance company need to be contacted? Does legal counsel need to become involved? Do clients need to be informed?
The middle of an incident is a terrible time to have the first conversation about those questions.
That's why businesses need an incident-response plan. It doesn't have to be a giant binder nobody reads. It needs to establish responsibilities, escalation, authority and communication before people are making decisions under pressure.
And occasionally it should be tested.
A tabletop exercise can be as simple as sitting around a table and saying:
It's 9:00 Tuesday morning. We believe an employee's Microsoft account was compromised and a fraudulent payment request was sent to a client. What do we do?
You learn very quickly where the unanswered questions are.
Backups Aren't the Goal. Recovery Is.
Most business owners know they need backups. But backups are often discussed almost entirely in terms of data: Are our files backed up? How often are they backed up? How many copies do we have?
Those are important questions, but they aren't the same as asking whether the business can recover.
Imagine a server is destroyed or encrypted by ransomware. You may have a perfectly good backup of the company's data.
Where are you going to restore it?
You may first need a functioning server or cloud environment. The operating system may need to be restored or rebuilt. Applications may need to be installed and configured. Security and network settings may have to be recreated. Users and permissions have to work. Databases and applications may depend on other systems. Only then does restoring the data necessarily make the application usable again.
In some environments, backup technology can protect an entire server or virtual machine rather than just its files, which can dramatically change the recovery process. Some systems can even be temporarily brought online from backup infrastructure while the primary environment is being repaired. But those capabilities have to be designed and configured before the incident occurs.
Cloud services create similar questions. Having a backup of Microsoft 365 data, for example, isn't necessarily the same thing as having a plan for how the business will operate if identities, configurations, applications, or other parts of the environment are affected.
So the better question isn't simply “Do we have backups?”
Ask what would actually have to be rebuilt after a serious incident. Are you protecting just the data, or can you recover the systems and applications that use it? Where would those systems run if the existing environment were unavailable? Which systems have to be restored first? What depends on what? How long would the complete process take? When was it last tested?
This is where backup planning becomes business-continuity and disaster-recovery planning.
A backup tells you that you have another copy of something.
A recovery plan tells you how you are going to get the business working again.
How Do You Know You Haven't Forgotten Something?
At this point, cybersecurity starts sounding like a lot: email, browsers, accounts, computers, phones, cloud services, remote employees, training, monitoring, incident response, backups and recovery.
How is a 50-person business supposed to know whether it has remembered everything?
Fortunately, you don't have to invent cybersecurity from scratch. That's what established security frameworks are for.
For most small and midsize businesses, I like the CIS Controls as a practical starting point. CIS organizes cybersecurity into specific safeguards that can be assessed and implemented rather than leaving a company to decide on its own what “good security” means.
Its first Implementation Group, IG1, is described by CIS as essential cyber hygiene and includes 56 foundational safeguards. CIS describes the typical IG1 organization as small or midsize with limited IT and cybersecurity expertise, and the safeguards are intended to address common, non-targeted attacks—the same wide-net problem discussed at the beginning of this article.
As a business becomes more complex, handles more sensitive information, or faces greater risk, additional CIS safeguards can be added through Implementation Groups 2 and 3.
The NIST Cybersecurity Framework is another widely respected framework and organizes cybersecurity risk around six broad functions: Govern, Identify, Protect, Detect, Respond and Recover. It can be particularly useful when an organization has regulatory, contractual or other requirements that point it toward NIST. But for an SMB asking, “What should we actually be doing?”, I generally find CIS easier to translate into a practical security program.
You don't need to become an expert in either framework. The important idea is that your security program should be based on something more systematic than:
“We bought a firewall, antivirus and MFA, so I think we're okay.”
A framework provides a way to ask: What are we doing? What are we missing? What is most important for our particular business? What should we improve next?
Following CIS isn't a one-time project. The environment changes. Threats change. The business changes. New applications are introduced, employees come and go, configurations drift, vulnerabilities are discovered, and exceptions that were supposed to be temporary have a way of becoming permanent.
The practical work is ongoing: assess the environment, identify gaps, prioritize improvements based on risk, implement safeguards, document necessary exceptions, and periodically go back through the process to make sure what was put in place is still working.
That ongoing process is ultimately more important than being able to say that your company “follows a framework.”
Compliance Isn't the Same as Security
Some businesses have another reason to pay attention to cybersecurity: regulations, client requirements, cyber insurance, or industry standards.
Those can be useful because they force organizations to ask questions they might otherwise ignore. But passing an audit, completing a questionnaire, or qualifying for cyber insurance doesn't automatically mean the business is secure.
And good security doesn't mean implementing every security control that exists.
A 25-person professional-services company doesn't necessarily have the same risk as a financial institution, healthcare organization, manufacturer, or company handling regulated information.
The goal is to understand the risks that matter to your business, use an established framework so important areas aren't forgotten, and make reasonable decisions about what should be addressed first.
Compliance can support that process. It shouldn't replace it.
Your IT Provider Should Follow the Same Rules
There is one more place where business owners should apply this thinking: their vendors.
Some vendors may have access to sensitive company information. Others may connect directly to your systems. An MSP can have particularly significant access because it may administer computers, cloud systems, networks, backups and security tools.
That means the security of the company protecting you matters too.
Ask your IT provider:
What security framework do you follow inside your own company?
Not just what they recommend that you follow.
How do they protect privileged access? How do they monitor their own environment? How do they prepare for incidents? Are their security practices independently evaluated?
Third-party validation doesn't guarantee that an organization will never have an incident—nothing does—but it can provide evidence that security is being treated as a structured, ongoing program rather than a collection of claims.
This is why independent cybersecurity validation of an MSP matters, and it is one of the reasons we have written separately about Xvand's experience with the GTIA Cybersecurity Trustmark.
The larger point isn't the particular certification.
The company you trust to protect your systems should be willing to subject itself to the same kind of security discipline it recommends to you.
Eight Questions to Ask Whoever Manages Your Cybersecurity
If you're a business owner and don't want to become a cybersecurity expert, you shouldn't have to. But you should be able to get straightforward answers to these questions:
- What established security framework are we using to determine what we need?
- How are we protecting email, identities, computers, cloud systems and employees working outside the office?
- Who monitors our security when nobody from our company is working?
- If something suspicious happens tonight, what can happen automatically, who investigates it, and who is responsible for responding?
- If our systems were seriously damaged, could we recover the environment and not just the data? How long would that take?
- When did we last test our incident-response and recovery plans?
- How do you evaluate our security over time and decide what needs to improve next?
- If an outside IT provider has significant access to our environment, what framework does that provider follow internally and how is that independently validated?
If the answers are mostly product names, keep asking questions.
Products are important.
But products are slices of cheese.
Cybersecurity Isn't About Eliminating Every Hole
There is no finish line where a business becomes completely secure.
That's uncomfortable, but it's also useful to understand because it changes how we make security decisions.
The objective isn't to buy enough technology to guarantee that nothing bad will ever happen. It is to make successful attacks significantly harder, reduce the damage if something gets through, recognize unusual activity quickly, have people and systems capable of responding, and give the business a tested path to recovery.
That is what a cybersecurity program does.
The products will change. The attacks will change. AI will make some attacks easier and will make security tools better at detecting and responding to others. Employees will work from new places and businesses will adopt applications that don't exist yet.
The principles are much more durable.
Know what you're protecting. Put multiple layers between the attacker and the business. Educate your people and create a culture where they report problems quickly. Assume no layer is perfect. Watch for the moment when the holes line up. Know what you'll do when they do. And make sure you can recover the environment the business depends on—not just its files.
Because the real test of your cybersecurity isn't how many security products you own.
It's what happens at 2:13 in the morning when one of them tells you something is wrong.
Frequently Asked Questions
A small business should have multiple layers of protection rather than rely on one security product. Those layers should include identity and MFA, email security, endpoint protection and patching, browser and internet protection, cloud security, employee education, backups and recovery, security monitoring, and an incident-response process. For most SMBs, the CIS Controls provide a practical framework for determining which safeguards should be implemented and what should be improved over time.
No. Antivirus and firewalls remain useful security layers, but much of today's business activity happens through email, browsers, cloud applications and user identities, including when employees are outside the office. A modern cybersecurity program also needs to protect those areas and provide detection, response and recovery rather than concentrating only on preventing attacks.
A small business doesn't necessarily have to be specifically selected as a target to be exposed to cyberattacks. Many attacks use automation, stolen credentials, phishing campaigns and other methods capable of reaching large numbers of organizations. SMBs often use many of the same technologies as large enterprises but have fewer security resources protecting them, which can make these broad attacks particularly dangerous.
MFA is one of the most important identity-security measures a business can implement, but it isn't perfect. Some authentication methods can be manipulated through phishing, and attackers may attempt to steal an already authenticated browser session. Businesses should use MFA broadly while considering stronger, phishing-resistant authentication for accounts and systems where the risk justifies it.
A small business doesn't necessarily need to build its own Security Operations Center, but it should know who receives and investigates important security alerts when its regular employees aren't working. That capability may come from an internal team, MSP, specialized SOC provider, automation and AI, or a combination of them. What matters is whether serious events can be recognized, investigated, acted upon and escalated to someone who understands the business environment.
Not necessarily. A company may have a good copy of its data and still face a lengthy recovery if servers, operating systems, applications, configurations, identities and other infrastructure also have to be rebuilt. Recovery planning should determine what needs to be restored, in what order, where the systems will run, what dependencies exist and how long the complete recovery is expected to take.
For many small and midsize businesses, the CIS Controls are a practical place to start. CIS Implementation Group 1 provides 56 foundational safeguards described as essential cyber hygiene and is designed to address common attacks. As risk and complexity increase, a business can progress into additional CIS safeguards. NIST CSF is another respected framework and may be appropriate where regulatory, contractual or other requirements point toward it, but CIS generally provides SMBs with a more direct path from identifying a need to implementing specific security practices.
Cybersecurity should be treated as an ongoing process rather than an annual project. Businesses should reassess their security periodically and whenever something significant changes, such as adopting a major application, moving systems to the cloud, adding locations, changing how employees work, experiencing an incident, or facing new regulatory or insurance requirements. Security controls should also be checked to make sure they continue to operate as originally intended.
Either model can work, but modern cybersecurity requires access to multiple disciplines, including endpoint and cloud security, identity, networking, monitoring, incident response and recovery. Smaller businesses often use a combination of internal business knowledge and outside specialists. The important issue is that responsibilities are clear, appropriate expertise is available when needed, and someone remains accountable for coordinating the response when something goes wrong.
Ask what established cybersecurity framework the MSP follows for its own company, not only what it recommends to clients. Ask how privileged access is protected, how its environment is monitored, how it prepares for incidents, and whether its security practices have been independently evaluated. Because an MSP can have significant administrative access to client systems, its own cybersecurity should be considered part of the client's vendor-risk program.
0 Comments