Think Your Business Is Too Small for a Cyberattack? Think Again.
“We’re a small business. Why would a hacker care about us?”
We hear this one a lot, and honestly, we understand why business owners think that way. If you’re running a company with 20, 50, or even 100 employees, it’s easy to assume cybercriminals have much bigger fish to fry. Why bother with your business when there are huge corporations with thousands of employees and millions of dollars?
Here’s the problem: they don’t necessarily have to choose you.
A lot of cybercrime is opportunistic. Attackers are looking for an opening, and sometimes that opening happens to be your business. A compromised password, a convincing phishing email, an account without MFA, an unpatched computer, or an old account that still has access can be enough to get started.
Most Cyberattacks Are Surprisingly Ordinary
Forget the movie version of a hacker sitting in a dark room specifically targeting your company. A real cybersecurity incident can start with something incredibly boring: an employee receives an email that looks like it came from Microsoft, clicks the link, sees a completely normal-looking login page, and enters their password.
Or maybe someone receives an unexpected MFA notification and taps “Approve” without thinking about it. Maybe they’ve been using the same password across several accounts for years. Maybe a former employee still has access to something nobody remembered to remove.
None of those things sound particularly dramatic, until someone gets in.
Once an attacker has access to an email account, they may also have access to contacts, invoices, customer conversations, vendor information and clues about how your company operates. Suddenly, they aren’t guessing anymore.
They’re inside.
“But We Have Antivirus.”
Good. You should.
But antivirus alone isn’t a cybersecurity strategy.
We sometimes explain cybersecurity by comparing it to your house. You wouldn’t lock the front door and then leave every window wide open. Your endpoint protection may secure one entrance, but what about your email, passwords, employees, Microsoft 365 accounts, backups and devices?
That’s why good cybersecurity is built in layers. If one layer fails, another one should be there to help stop the attack.
SO WHAT SHOULD A SMALL BUSINESS ACTUALLY HAVE?
This is usually where cybersecurity starts to feel overwhelming. There are hundreds of products, acronyms and services out there, and every company seems to have a different opinion about what you absolutely “need.”
The answer really depends on your business. A 15-person accounting firm, a construction company and a 500-person manufacturer aren't going to have identical security needs. But there are some basic layers we believe almost every business should be thinking about.
Multi-factor authentication (MFA) is one of them. A password by itself shouldn't be enough to access important company accounts. If that password is compromised, MFA creates another barrier between the attacker and your business.
Endpoint protection is another. Traditional antivirus still has a purpose, but modern businesses should be looking at stronger endpoint protection that can detect suspicious activity and respond to threats, not simply scan for known viruses.
Then there's email security, because email continues to be one of the easiest ways to get in front of your employees. Phishing emails have also gotten much better. We're long past the days when every scam email came from a prince promising you $10 million with twelve spelling mistakes in the first sentence. Some of them look incredibly legitimate.
YOUR EMPLOYEES ARE PART OF YOUR SECURITY, TOO
We don't say that to scare employees or make them feel like they're the problem. They're actually one of your most important lines of defense.
Someone who recognizes that an email feels a little off and asks before clicking can stop an incident before it ever starts.
That's why security awareness training matters. Employees don't need to become cybersecurity experts. They need to understand the common things they're likely to encounter and, more importantly, know what to do when something doesn't feel right.
At CNR, we'd much rather get the call that says, “Hey, this looks weird. Can you check it?” than the call five minutes later that says, “Soooo...I clicked it.” 😂
Seriously. Bother your IT company. That's what we're here for.
Creating a culture where employees feel comfortable asking questions is far more useful than making everyone terrified they'll get in trouble for making a mistake.
DON'T FORGET ABOUT THE BORING STUFF
Some of the most important parts of cybersecurity aren't exciting enough to make headlines.
Computers need to be patched and updated. Old accounts need to be disabled. Employees shouldn't have more access than they actually need. Devices need to be managed. Security alerts need to be monitored.
And then there are backups.
We cannot say this enough: simply having a backup isn't the same thing as having a recovery plan.
Is the backup actually running? Is somebody monitoring it? Is the information you think you're protecting actually included? Could you restore that information if you needed it tomorrow?
The absolute worst time to discover that something wasn't being backed up properly is when you're trying to recover it.
A good IT provider shouldn't simply sell you backup software and forget about it. Someone needs to be paying attention.
YOU PROBABLY DON'T NEED EVERY SECURITY PRODUCT SOMEONE TRIES TO SELL YOU
Cybersecurity can get expensive very quickly if the answer to every risk is “buy another product.”
That's not how we think it should work.
Your cybersecurity strategy should make sense for your business, your risks and your budget. That means understanding what information you're protecting, how your employees work, what regulations may apply to your industry, what your insurance company requires and what would happen if certain systems became unavailable.
A medical office may have different concerns than a manufacturer. A company with employees working remotely across the country may need different controls than a business where everyone works from one location.
There isn't one magic cybersecurity package that's perfect for every company.
There should be a reason behind what you're paying for.
And your IT provider should be able to explain that reason without burying you in technical jargon.
ASK YOUR IT COMPANY THESE QUESTIONS
Since October is Cybersecurity Awareness Month, here's something useful you can actually do this week.'
Ask your IT provider:
Do all of our employees have MFA enabled?
What is protecting our computers beyond traditional antivirus?
How is our email protected against phishing and malicious links?
How are our computers being patched and updated?
What happens to access when an employee leaves the company?
Are our backups monitored, and do we know we can actually restore from them?
Are our employees receiving cybersecurity awareness training?
And here's a big one:
If one of our employees clicks something malicious tomorrow, what happens next?
You don't need to know all of the technical answers yourself. That's why you have an IT company.
But someone should know the answers.
And they should be able to explain them to you in plain English.
SMALL BUSINESS DOESN'T MEAN SMALL RISK
We work with small and midsized businesses every day, and we know cybersecurity is probably not the first thing most business owners want to think about when they wake up in the morning.
You already have employees, customers, payroll, sales, vendors and about 100 other things competing for your attention.
You shouldn't have to become a cybersecurity expert on top of everything else.
But your business also shouldn't wait until something happens to find out whether the right protections were in place.
That's a big part of what a good technology partner should be doing behind the scenes: understanding your business, watching the technology, managing the layers and thinking about the risks you don't have time to think about.
Because we'd much rather have a conversation with you about cybersecurity on a normal Monday morning than at 2:00 AM after someone has gained access to your systems.
So, is your business too small to be a target?
Unfortunately, no.
But you're also not too small to protect.
And you don't have to figure it out alone.
Let US worry about IT, so you don't have to.