Smaller organisations often assume they are too small to be worth an attacker’s attention. In practice, the opposite is frequently true. Automated attacks do not check the size of your turnover before they strike, and many criminals deliberately target smaller firms precisely because they expect the defences to be thinner. The encouraging news is that the measures that block the majority of everyday attacks are not expensive. Strong fundamentals, applied consistently, protect you far more than any single costly product. Below are eight practical, prioritised steps you can begin working through this week, with a note on where expert help adds the most leverage.
1. Turn on multi-factor authentication everywhere
If you do only one thing from this list, make it this. Multi-factor authentication (MFA) means a password alone is not enough to get into an account; a second factor, such as a code from an app on your phone, is also required. It stops the great majority of attacks that rely on stolen or guessed passwords. Enable it on email, remote access, banking, and any cloud services you rely on. Prefer an authenticator app over text messages where you have the choice, and make it mandatory rather than optional for staff.
2. Keep systems patched and updated
A large share of successful attacks exploit known weaknesses for which a fix already exists. Turning on automatic updates for operating systems, browsers, and applications closes those gaps before they can be used against you. Do not overlook the devices that are easy to forget: routers, firewalls, and anything else connected to your network. Keep a simple inventory of what you run so nothing quietly falls out of support and becomes a permanent hole in your defences.
3. Keep reliable, tested backups
Backups are your safety net against ransomware, hardware failure, and honest mistakes. A useful rule of thumb is the 3-2-1 approach: keep three copies of your important data, on two different types of media, with at least one copy kept off-site or offline. Crucially, a backup you have never restored from is only a hope, not a plan. Test a restore periodically so you know it works and how long it takes. An offline or immutable copy is particularly valuable because attackers often try to delete backups before they strike.
4. Train staff to spot phishing
Your people are on the front line, and most attacks begin with a convincing email or message. Short, regular security-awareness training helps staff recognise phishing, suspicious links, and requests that create false urgency, such as a fake message from a supplier or senior colleague asking for a payment. Make it easy and blame-free to report anything that looks odd. A team that feels comfortable raising the alarm quickly is one of the cheapest and most effective controls you can build.
5. Apply least-privilege access and prompt off-boarding
People should have access only to the systems and data they genuinely need for their role, and no more. This limits the damage if an account is compromised. Keep administrator accounts to a minimum and separate from everyday accounts. Just as important, remove access promptly when someone leaves or changes role. Dormant accounts that still work are a common and avoidable weakness, so a simple leavers checklist pays for itself many times over.
6. Protect your endpoints
Laptops, desktops, and servers are where much of the action happens, so they deserve proper protection. Modern endpoint protection, often described as endpoint detection and response (EDR), goes beyond traditional antivirus by watching for suspicious behaviour and helping you respond quickly when something is wrong. For many smaller teams, the real value comes from having that activity monitored and acted upon around the clock. A Managed SOC gives you experienced eyes on those alerts without the cost of building an in-house team.
7. Write a simple incident-response plan
When something goes wrong, calm and speed matter. A short written plan means you are not improvising under pressure. It need not be elaborate: who decides what to do, who to call, how to isolate affected systems, and how to keep the business running while you recover. Include key contacts such as your IT support, insurer, and any regulator you must notify, along with a way to communicate if your usual email is unavailable. Keep a copy offline, and walk through it once so everyone knows their part.
8. Manage third-party and supplier risk
Your security is only as strong as the partners connected to your systems and data. A weakness at a supplier can become your problem, so it is worth knowing who has access to what, and why. Ask key suppliers about their own security practices, limit the access you grant them to what is necessary, and review those arrangements when contracts change. This is an area where independent Cyber Advisory can help you ask the right questions and prioritise sensibly, without adding needless cost or complexity.
None of these steps requires a large budget. What they require is consistency and a clear sense of priority. Work through them in order, make each one a habit rather than a one-off, and you will close the gaps that attackers rely on most.
How Baknet can help
Getting the fundamentals right is well within reach for any smaller organisation, and you do not have to do it alone. Whether you want a clear-eyed review of where you stand today or ongoing monitoring to catch problems early, our team can help you focus effort where it counts. Book a consultation and we will help you build practical, affordable defences that fit your business.
