The Future of Cybersecurity for Small Businesses
Enterprise-grade threats are now hitting 20-person companies. Here is a proportionate defence.
Informechs Security Practice
The assumption that small companies are too small to target has not been true for several years. Attacks are automated, and automation does not care how many employees you have — it cares whether a credential works. A twenty-person firm now faces roughly the same tooling as a two-thousand-person one, with none of the security staff.
Firewalls and antivirus answer the wrong question
Both are necessary and both are matching against what is already known to be bad. Neither tells you that a valid account is behaving in a way that account has never behaved before — which is what most real intrusions actually look like. The missing layer is visibility, not another blocking product.
A proportionate stack
Small does not mean thin. It means picking the controls with the highest ratio of risk removed to effort spent, and skipping the rest without pretending otherwise.
- Phishing-resistant MFA on email, finance and remote access. Credentials are the modern attack surface; this is the single highest-value control available.
- Centralised logging. Detection across silos is not detection. You cannot correlate what you cannot see in one place.
- Identity-behaviour alerting — an admin account authenticating from a new geography at 03:00 is on no signature list and is exactly the event you want.
- Tested backups, with at least one copy the production credentials cannot reach or delete.
- A written escalation path: who is called, who can authorise taking a system offline, who talks to customers.
“Containment decisions made during an incident are worse than the same decisions made six weeks earlier over coffee.”
Compliance is a by-product, not the goal
HIPAA and GDPR obligations reach far below the enterprise line, and small firms often meet them by accident and cannot prove it. Access records, encryption posture, retention policy and incident logs are the same artefacts good security produces anyway. Build the controls; the evidence pack falls out of them.
Rehearse once a year
Run the tabletop exercise. It takes an afternoon and it reliably surfaces two or three assumptions that would have cost hours during a real event — usually about who has authority to act, and where the backups actually are.
More from Informechs
6 min read
Top 5 Benefits of AI in Healthcare
Where AI is already earning its keep in clinical and administrative workflows — and where it is still hype.
5 min read
How Medical Billing Errors Impact Your Bottom Line
The real cost of a 2% claim error rate, and the controls that bring it down without adding headcount.
6 min read
Why Your Business Needs a Custom ERP Solution
When off-the-shelf stops paying for itself, and how to scope a custom build that does not sprawl.