Home › Insights › Cybersecurity
Guide · Cybersecurity
Small business cybersecurity: what you actually need
Short answer: most small businesses don’t get breached by anything sophisticated. They get breached through a reused password, an unpatched computer, or an email someone believed. The protections that stop the overwhelming majority of real attacks are dull and mostly cheap. Multi-factor authentication. Patching things quickly. Modern endpoint protection. Email filtering. Backups that somebody has actually restored from. If those five are genuinely in place, you’re ahead of most businesses your size.
How attacks actually start
Forget the hoodie-in-a-dark-room image. For a business with ten or forty staff on the North Shore, the realistic threats are these:
- Phishing email. Someone receives a convincing message, often looking like it came from a supplier, a bank, or you, and enters their password on a fake login page.
- Reused or leaked passwords. A password used on a shopping site turns up in a breach, and the same one opens your email.
- Unpatched software. A known vulnerability sits unfixed for months while automated scanners look for exactly that.
- Exposed remote access. Remote desktop left open to the internet so someone could work from home three years ago.
- Invoice fraud. An attacker sits quietly in a mailbox, watches how you invoice, then sends a real-looking invoice with different bank details.
Notice how few of these involve breaking anything. Most involve logging in — which is exactly why MFA matters so much.
The seven protections that matter most
1. Multi-factor authentication, everywhere
If you do one thing from this page, do this. MFA means a stolen password isn’t enough on its own. Start with email, then anything financial, then remote access. It’s built into Microsoft 365 and Google Workspace at no extra cost.
2. Patching, on a schedule
Windows, macOS, browsers, and any line-of-business software. Not “when someone remembers” — automatically, verified, and reported on. This is standard in any real managed IT agreement.
3. Modern endpoint protection
Old-style antivirus works by recognising malware it has seen before, from a list of known signatures. You still want it, but on its own it is no longer enough. Modern endpoint tools watch for suspicious behavior , a process encrypting files rapidly, for instance, and can stop ransomware mid-run.
4. Email security and filtering
Since most attacks arrive by email, filtering that catches spoofing, malicious links and impersonation attempts removes a large share of risk before anyone sees it. Add SPF, DKIM and DMARC records so criminals can’t easily send mail pretending to be your domain.
5. Backups — on-site, off-site, and tested
Backups are the difference between a bad week and a closed business. Three rules: keep more than one copy, keep at least one off-site and offline enough that ransomware can’t encrypt it too, and test a restore regularly. An untested backup is a hope, not a plan. Plenty of businesses discover their backups have silently failed only at the worst possible moment.
6. Least privilege
Not everyone needs administrator rights. Staff should have the access their job requires and no more, and former employees should lose access the day they leave — a step that gets missed constantly.
7. Your people
The staff member who pauses and phones the supplier before paying a changed invoice is worth more than most software. Short, occasional, blame-free training works better than an annual lecture. Make it easy and safe to say “I think I clicked something.”
Four questions for your current IT provider
You don’t need to be technical to work out whether security is genuinely being handled. Ask these and listen for specifics:
- “When did we last test restoring from backup, and what were the results?” The right answer includes a date.
- “Is MFA enforced on every account, including admin accounts?” “It’s available” is not the same as “it’s enforced.”
- “How quickly are security patches applied, and how do you verify it?” There should be a defined window and a report.
- “What exactly happens if we’re hit with ransomware at 2am on a Saturday?” You want a plan, not a pause.
Vague answers to these questions are themselves the answer. A provider who can’t tell you when your backups were last tested almost certainly isn’t testing them.
What “good” looks like for a business your size
You don’t need an enterprise security operations center. For a typical North Shore business of ten to fifty people, a sound baseline looks like this. MFA turned on for everyone, with no exceptions. Automated patching, checked rather than assumed. Modern endpoint protection on every device. Filtered email with the right domain records behind it. Layered backups, tested on a schedule. A firewall someone actually configured. Admin rights held by the few people who need them. Offboarding that genuinely removes access the day someone leaves. And a written incident plan that somebody has read.
That’s achievable, and for most businesses it costs less than the downtime from a single serious incident.
A note on compliance
Do you handle financial records, health information, or client data under contract? Then you may have legal duties, not just good habits. Massachusetts also has its own rules covering personal information about residents. Accounting firms and practices in particular should treat retention, encryption and access control as requirements rather than nice-to-haves. If nobody has ever walked you through this, that’s worth a conversation.
How we handle it
Security isn’t a product we sell separately — it’s built into every managed IT agreement we run. Firewalls, endpoint protection, email security, MFA, dark web monitoring, and on-site plus off-site backups that get tested, not just scheduled. If you’re not certain what’s currently in place at your business, that uncertainty is the finding.
Ask us for a straight assessment and we’ll tell you what’s solid and what isn’t — including when the honest answer is that you’re already in decent shape.