Every security incident I have helped clean up in a small organisation had the same shape. Not a brilliant attacker defeating clever defences — a busy Tuesday, someone doing three things at once, and one ordinary decision that nobody would have made on a quiet day. Security advice that only works when everyone is careful is not security advice. It has to survive the week when nobody is.
Most of the risk is procedural
When I review a company’s security, I spend less time on firewalls than people expect. The technical layer matters, but the breaches that actually happen to businesses of twenty, fifty or two hundred people are mostly about process: a password reused from a site that was breached years ago; an invoice email that looked right and was paid; a former employee whose account was never disabled; a laptop with everything on it and no encryption; a backup that existed but had never been restored.
None of these are solved by buying a product. They are solved by deciding, once, how things are done — and then making the secure way the easy way, so it still happens on a busy day.
The measures that return the most
If you have limited time and no security department, this is where I would spend it, roughly in order:
- Multi-factor authentication on everything that matters — email first, then your accounting, CRM and file storage. Passwords alone are a 2010 solution. With MFA, a stolen password is an inconvenience instead of an incident.
- A password manager for the whole team, so that a unique password per service is the path of least resistance rather than a heroic effort.
- Backups you have actually restored. A backup is a theory until you have restored from it. Once a quarter, pick a file, a mailbox or a whole system and bring it back. Keep at least one copy somewhere an attacker on your network cannot reach.
- Updates that install themselves. Most successful attacks use vulnerabilities that were patched months earlier. Turn on automatic updates for operating systems, browsers and the handful of applications you rely on, and let them run.
- A leaver checklist. The day someone leaves, their accounts are disabled and their access is removed — on the same day, from one list, not from memory.
- Fewer administrators. Most people do not need administrator rights on their own computer, and almost nobody needs them all day. Every account that has them is an account that can install ransomware.
- A four-eyes rule for payments and changes to bank details. No single person, however senior, changes a supplier’s bank account or approves an unusual payment alone. This one rule stops most invoice fraud.
Everything on this list is either free or cheap, and none of it requires a security team to operate.
Making it survive
The difference between a company that is secure on paper and one that is secure on a Tuesday afternoon is friction. If the secure path is slower, people will route around it, and they will be right to — they have work to do. So:
- Choose tools that make the right thing the default (single sign-on, automatic updates, a password manager that fills things in).
- Write the checklist down in one place, keep it short, and review it twice a year.
- Tell people why. A team that understands that invoice fraud looks like a normal email from a normal supplier will catch it. A team that has been told “be careful” will not.
What I do not recommend
Buying a security product before fixing the procedural basics. Running an expensive penetration test on a company that does not yet have MFA. Annual awareness training that everyone clicks through. Long password rules that guarantee the password ends up on a sticky note. Anything that assumes people will be careful when they are busy.
When to get help
If you cannot answer, from memory, how many administrator accounts you have, when a backup was last restored, and which former employees still have access to something — that is a good moment to spend a day on it, with or without me. A day now is cheap. A week of downtime, or a quiet transfer of forty thousand euros to the wrong account, is not.
