Security · 5 min read

Security posture for small businesses that actually take it seriously

Key takeaway

Most small business security failures are attributable to known, unfixed vulnerabilities — not sophisticated attacks. Three controls (MFA everywhere, a patching schedule, and basic monitoring) address the majority of realistic threat scenarios. The complexity the security industry sells is real, but it is not where you should start.

Small businesses are not less interesting to attackers than large ones. In several respects, they are more interesting — less likely to have detection in place, less likely to have incident response capability, and less likely to act on a known vulnerability until after it becomes a problem.

The threat model most small businesses have wrong

The common assumption is that sophisticated attackers target large organisations and small businesses can fly under the radar. This was more true in 2010 than it is now. The majority of attacks against small businesses today are automated: credential stuffing against exposed login pages, exploitation of unpatched software, and phishing at scale. None of these require a sophisticated attacker. They require a vulnerable target.

The realistic threat model for a small business is not "a nation-state APT is targeting us specifically." It is "automated tooling is scanning the internet for known vulnerabilities, and we are on the internet." That is a different problem, and it has a different solution.

IDENTITY ENDPOINT NETWORK DATA encryption, backup, access control Outermost: MFA, SSO, least privilege → innermost: the data itself
Figure 1.Defense in depth — each layer assumes the one outside it can fail.

Three controls that actually matter

The security industry has a financial incentive to make this feel more complex than it is. Enterprise security programmes are genuinely complex. Security for a 20-person business with a cloud environment is not. The starting point is three controls that, applied consistently, address the majority of realistic attack scenarios.

The three controls

  • Multi-factor authentication on everything. Every account that can access your business systems — email, cloud consoles, SaaS tools, VPN — should require MFA. This single control eliminates credential-based attacks as a viable path for most attackers.
  • A patching schedule that is actually followed. Not a patching policy. A schedule with named accountability and evidence of completion. Operating systems, applications, and network devices. Monthly for most things; immediately for critical vulnerabilities.
  • Monitoring that tells you when something unusual happens. You do not need a SOC. You need to know when a user account is logging in from an unusual location, when a large volume of data is being exported, or when a service is making unexpected outbound connections.
"Most small business security failures are attributable to things that were known, understood, and not fixed — not to sophisticated attacks that bypassed detection."

What actually costs you

Unpatched software is responsible for a disproportionate share of small business breaches. The patches are available. The remediation is understood. The reason it does not happen is that nobody owns it. Patching is unglamorous work that does not feel urgent until something is compromised.

The same is true of access management. Accounts that should have been deactivated when someone left the organisation six months ago. Shared credentials for services that should have individual accounts. Permissions that were granted for a specific project and never revoked. These are not failures of technology. They are failures of process.

Where to start

The honest answer to "what should we do first?" is an assessment of the current state — not a purchase. Before buying tools, know what you have: what accounts exist and who has access to them, what software is running and when it was last patched, and what your current monitoring coverage is.

If you have Microsoft 365, you already have access to Entra ID identity protection, Defender for Business, and basic audit logging. These are not the most sophisticated tools available. Used properly, they address the realistic threat model for most small businesses without additional spend.

Security spending that comes before a clear picture of what you are trying to protect against is a pattern the security industry benefits from. Your business does not.

Need a security assessment?

We assess your current state honestly and tell you what to fix first — before recommending any specific tool or service.

Book a conversation