You do not need a big budget or an in-house IT department to close the most common gaps — you need a clear order of priorities and a little discipline.
Most small businesses are convinced that "we have nothing worth stealing." In practice, attacks are rarely aimed at a specific company — automated scripts scan the internet for exposed services, weak passwords and unpatched software, and email campaigns go out to thousands of addresses at once. A small office is an easy target precisely because it usually has no security specialist, and the same person is the accountant, the computer administrator and "the one who deals with the internet."
The good news is that much of the risk can be closed with a few inexpensive but consistently applied measures. This guide is a practical plan: what threatens you, ten steps, and finally a priority table.
The threats are far more mundane than movie hackers. Almost everything comes down to a handful of recurring scenarios:
| Threat | How it most often happens | First defence |
|---|---|---|
| Phishing | A message imitating a courier, bank, supplier or boss that urges a click, a login to an "account" or a payment | Trained people and MFA |
| Ransomware | A malicious file encrypts documents on the computer and on reachable network folders, then demands a ransom | Backups the attacker cannot reach |
| Weak and reused passwords | One password is used everywhere; after a leak from one site it is tried on the others | Password manager and MFA |
| Unpatched devices | A known vulnerability in a computer, router or camera stays open for months | Regular updates |
| Exposed remote access | A remote desktop service is reachable directly from the internet | Access only through a VPN |
None of these threats requires a sophisticated attack. That is why protection starts not with the most expensive product, but with discipline around the basics.
If you do only one thing from this article, make it this. A backup is the only defence that still works when everything else has failed — ransomware, a failed disk, human error, theft or fire. The 3-2-1 rule is a proven and easy-to-remember guideline:
An often-overlooked detail: at least one copy must be unreachable from an infected computer — offline, behind separate credentials, or with an immutability feature. Ransomware encrypts everything the computer can access, including permanently connected network folders and external drives.
Multi-factor authentication (MFA) adds a second check on top of the password. Even if the password has leaked or been typed into a fake page, the attacker cannot get in without the second factor. Turn it on first where the damage would be greatest: business email, cloud storage, accounting and banking systems, router panels, hosting and domain. When you have a choice, prefer an authenticator app or a hardware key over SMS — text messages are easier to intercept and redirect.
People cannot remember dozens of long, different passwords, so they start reusing them or writing them under the keyboard. A password manager solves this: it remembers everything, generates long random passwords and fills them in only on the genuine site address, which also protects against fake pages. One strong master password plus MFA on the manager itself is far better than any "clever" scheme.
Most successful attacks exploit vulnerabilities for which the vendor has already released a fix. Turn on automatic updates for the operating system and applications. Do not forget devices that do not look like computers: routers, switches, access points, NAS units and printers — they get firmware updates rarely and often stay unpatched for years. Make a simple list of everything on the network — model, location, who maintains it, when it was last updated. A device that no longer receives fixes is a candidate for replacement, or at least for strict isolation.
Every computer and server should run modern protection against malicious code that updates itself and is managed centrally, rather than left to each user. Enable disk encryption on laptops — a lost or stolen laptop is then an inconvenience, not a data leak. If employees do not work with administrator rights, a large share of malware simply cannot install.
Use WPA3 for wireless, and where the equipment does not support it, WPA2 with AES encryption and a long password. Abandon legacy modes (WEP, the original WPA, TKIP) and turn off WPS — the quick-connect feature using a button or PIN that has long been known as a weak point. Change the Wi-Fi password when someone who knew it leaves.
Guests and personal phones should not share a network with the accounting computer and the server. Set up a separate guest network that provides internet only and has no route to internal devices — most modern routers and access points support this with a few settings.
The next level is segmentation. Instead of one flat network where every device sees every other, the network is split into zones — for work computers, for servers and storage, for guests, for cameras and printers. This is done with VLANs on a managed switch, while the rules about who may talk to whom are set on the firewall. That way, if one zone is compromised, the attacker does not automatically get access to everything else.
The firewall is the boundary between your network and the internet. Check three things: its firmware is current, its admin panel is not reachable from outside, and inbound connections are reduced to what is truly necessary. Turn off UPnP unless you know exactly why you need it — it lets devices open ports to the internet on their own.
The most common mistake in remote work is forwarding a port directly to a computer or service "so we can connect from home." A remote desktop exposed to the internet is constantly scanned and attacked with automated password guessing. The better solution is a VPN to the office firewall, with individual accounts and MFA. An outside vendor who supports one of your systems gets access only for the period needed and through a separate account that is then disabled.
Every user should have only the access they need. Daily work is not done with an administrator account — that is separate and used only when needed. That way, if an employee opens a malicious file, the damage is limited to what they can access, not the whole company. Keep shared folders at department level rather than "everyone sees everything." When someone leaves or changes role, review their permissions the same day. Avoid shared accounts — in an incident you will not know who did what.
Cameras, video recorders (NVR/DVR), access control, smart TVs and printers are full computers on the network, but they are rarely treated as such. The problems repeat:
Isolation is one of the most effective things you can do: if a camera is breached, it stays in a "cage" and is not a bridge to the rest of the network. Video recordings contain personal data, so access to them should be restricted and use individual accounts.
Technology closes some of the risks, but the final decision is often made by the person at the screen. You do not need a heavy presentation — short, regular conversations and a few clear rules are enough: check the real sender address; do not open unexpected attachments; do not enter a password through a link in a message, open the site yourself; for a request for an urgent transfer or a change of bank account, call a known phone number, not the one in the email. Culture matters most: an employee who clicked and reported it immediately deserves thanks, not blame.
When something happens, there is no time to invent a procedure. The plan is one page, in a visible place and with a copy outside the company network, containing:
Review the plan once a year and rehearse it with a short drill: "what do we do if all files are encrypted tomorrow morning?"
Even the smallest company processes personal data — of customers, employees, job applicants, and camera recordings count too. Without going into legal detail (consult a specialist for that), sensible practices are:
Not everything has to happen in one week. The order follows the principle of "the biggest risk reduction for the least effort" — start at the top.
| # | Measure | Effort |
|---|---|---|
| 1 | 3-2-1 backups with one unreachable copy and a restore test | Medium |
| 2 | MFA on email, cloud, bank and admin panels | Low |
| 3 | Password manager, an end to reused passwords | Low |
| 4 | Change default passwords on router, cameras and NVR | Low |
| 5 | Automatic updates and a device inventory | Low to medium |
| 6 | Close direct remote access, VPN with MFA | Medium |
| 7 | Endpoint protection, laptop encryption | Low to medium |
| 8 | Guest Wi-Fi network and WPA2/WPA3 | Low |
| 9 | Least privilege and separate admin accounts | Medium |
| 10 | Team awareness and a one-page incident plan | Low |
| 11 | VLAN segmentation, isolating cameras and IoT | Medium to high |
No. It is important, but it does not help against stolen passwords, phishing, an unpatched router or open remote access. That is why the plan combines several layers — backups, MFA, updates, network protection and awareness.
Not necessarily. Sync services keep the current state — if a file is deleted or encrypted, the change is carried over there too. You need a real backup with version history. Check the terms of the specific service and still test restoring.
It is strongly recommended. Cameras and recorders often have weak firmware and are rarely updated, and a separate network limits the damage if one device is breached. Even without VLANs, you can change the passwords and close access from the internet.
Many of the first steps — MFA, a password manager, changing passwords, awareness — can be done in-house. Segmentation, VPN, the firewall and the backup system are best designed by someone experienced and then maintained by a clear procedure. For a network or video surveillance assessment you can also turn to the Select IT team.
We will review your network, backups and video surveillance and propose a concrete plan that fits your budget.