Saltar al contenido principal
Cybersecurity

Cybersecurity for small businesses: where to start when you have no idea

7 min readiDeo Networks technical team

If you have to start somewhere, start with tested backups and multi-factor authentication on email. Together those two measures prevent or contain most of the incidents we see in small businesses, and neither is expensive. Everything else follows in a logical order: first what reduces damage, then what reduces likelihood, and last what gives visibility.

The first six steps, in order

This is the order we follow when we take on a company starting from scratch. It is not the only valid one, but it delivers the most protection per euro spent in the first weeks.

  • Automated backups, with one copy off site and regular restore tests
  • Multi-factor authentication on email and on anything reachable from the internet
  • Patching kept current across systems, applications and network device firmware
  • A managed firewall and endpoint protection with a central console, not the antivirus the laptop shipped with
  • Reviewed permissions: everyone with access to what they need, and leavers closed the same day
  • Short, regular staff training, above all on fraudulent emails

Why backups come first

Because they are the only thing that turns a disaster into a bad day. Ransomware encryption, accidental deletion, a failed disk, or someone leaving in a hurry: in every one of those cases, the outcome is decided by whether a recent copy can be restored.

The key words are "can be restored". We regularly find backups that had been failing silently for months, or that sat on the same network as the encrypted server and were encrypted too. A backup with no restore test is not a backup, it is a folder.

MFA is the best value measure there is

Most serious incidents we respond to start with a stolen password, almost always for email. With MFA enabled, that stolen password stops being useful for nearly everything. It costs very little, it is included in most subscriptions companies already pay for, and it can be switched on in an afternoon.

Enable it on email first, then on remote access and admin panels, and finally on any business application published to the internet.

What you do not need at the start

Some measures sound impressive in a proposal but add almost nothing to a company that still lacks the basics: a security operations centre for twenty workstations, disk encryption with no key management, or tools that generate alerts nobody will read. An alert nobody reads is worse than none, because it creates a false sense of control.

Get the basics right and verified first. Once those work, it makes sense to talk about advanced detection, network segmentation or periodic audits.

How we handle it at iDeo Networks

We start with a review of the real situation: which backups exist and whether they restore, where MFA is missing, what is exposed to the internet without anyone knowing, and which machines have gone unpatched. That produces a phased plan, with the urgent separated from the desirable.

We cover the whole of Spain, including the Canary and Balearic Islands, Ceuta and Melilla, and we work both with small companies and with the Spanish branches of international groups that must comply with head office security policy.

Related services

Want to know where to start in your case?

We review the real state of your security and give you a phased plan, separating the urgent from the desirable.

Request a review

More articles