Most attacks on mid-sized businesses are not sophisticated. They use a stolen password, a missing update or a convincing email. A short list of basics, done properly and kept in place, stops most of them.
Multi-factor authentication on everything
Turn on multi-factor authentication for email, remote access, finance systems and every admin account. A stolen password on its own then isn't enough to get in. Prefer an authenticator app or a passkey over text messages.
Keep devices and software up to date
Attackers use flaws that already have a fix available. Automatic updates for Windows, browsers and business applications, checked by someone who can see which machines are behind, close most of those doors.
Limit admin rights
Staff shouldn't be administrators on their own computers, and the people who do need admin rights should use a separate account for it. This one change limits how far an attacker gets from a single compromised account.
Back up, and test the restore
Keep backups of servers, Microsoft 365 and anything the business can't rebuild, with at least one copy that ransomware can't reach. Then restore something on a schedule. A backup you have never restored is only a hope.
Protect email and endpoints
Email filtering that catches impersonation and malicious links, plus modern endpoint protection on every laptop and server, catches a large share of what gets past people. Someone needs to look at the alerts these tools raise.
Train people and make reporting easy
Staff are the ones who see the odd invoice or the strange login prompt first. Short, regular training and a simple way to report something suspicious turn them into an early warning.
Know who to call
Decide now who makes decisions in an incident, who your IT and security contacts are, and where the insurance policy is. Write it on one page and keep a copy outside your systems.
Want security handled as part of your IT? Managed cybersecurity
All resources
