Skip to content
Informechs
Security7 min read

The Future of Cybersecurity for Small Businesses

Enterprise-grade threats are now hitting 20-person companies. Here is a proportionate defence.

Informechs Security Practice

The assumption that small companies are too small to target has not been true for several years. Attacks are automated, and automation does not care how many employees you have — it cares whether a credential works. A twenty-person firm now faces roughly the same tooling as a two-thousand-person one, with none of the security staff.

Firewalls and antivirus answer the wrong question

Both are necessary and both are matching against what is already known to be bad. Neither tells you that a valid account is behaving in a way that account has never behaved before — which is what most real intrusions actually look like. The missing layer is visibility, not another blocking product.

A proportionate stack

Small does not mean thin. It means picking the controls with the highest ratio of risk removed to effort spent, and skipping the rest without pretending otherwise.

  • Phishing-resistant MFA on email, finance and remote access. Credentials are the modern attack surface; this is the single highest-value control available.
  • Centralised logging. Detection across silos is not detection. You cannot correlate what you cannot see in one place.
  • Identity-behaviour alerting — an admin account authenticating from a new geography at 03:00 is on no signature list and is exactly the event you want.
  • Tested backups, with at least one copy the production credentials cannot reach or delete.
  • A written escalation path: who is called, who can authorise taking a system offline, who talks to customers.

“Containment decisions made during an incident are worse than the same decisions made six weeks earlier over coffee.”

Compliance is a by-product, not the goal

HIPAA and GDPR obligations reach far below the enterprise line, and small firms often meet them by accident and cannot prove it. Access records, encryption posture, retention policy and incident logs are the same artefacts good security produces anyway. Build the controls; the evidence pack falls out of them.

Rehearse once a year

Run the tabletop exercise. It takes an afternoon and it reliably surfaces two or three assumptions that would have cost hours during a real event — usually about who has authority to act, and where the backups actually are.

More from Informechs

Next step

Bring us the version of this problem you actually have

Articles generalise. A twenty-minute call about your systems does not.