IT Security schedule 6 min read calendar_today May 23, 2026

Cybersecurity for SMEs: 8 Essential Measures You Must Implement

Computer screen showing security alerts

The 8 essential cybersecurity measures for small and medium-sized businesses: 2FA, password managers, backups, and phishing awareness training.

SMEs are the favourite target of cyberattacks. Not only because they are often more vulnerable than large enterprises, but because they hold valuable data while typically lacking the security resources of a corporation. 43% of global cyberattacks target small and medium-sized businesses. This guide covers the essential security measures every SME should have in place.

Why SMEs Are an Easy Target

Attackers follow the logic of minimum effort for maximum gain. An SME with 10 employees and no security policies is far more profitable to attack than a multinational with a dedicated SOC. The most common attack vectors: phishing emails, reused passwords, unpatched software, and poorly configured remote access (RDP exposed to the internet).

The 8 Essential Security Measures

1. Two-Factor Authentication (2FA) on All Critical Accounts

Corporate email, VPN access, website admin panel, online banking. According to Microsoft, 2FA blocks 99.9% of credential-stuffing attacks. It is not optional.

2. Password Manager

Bitwarden (free for small teams), 1Password, or Dashlane. Without a password manager, employees reuse passwords. With one, every account gets a unique, strong password nobody needs to memorise.

3. Backups Following the 3-2-1 Rule

3 copies, on 2 different media, 1 offsite (cloud). Backups are the only real defence against ransomware. Without them, an attack can shut down your business for weeks.

4. Automatic OS and Application Updates

60% of breaches exploit known vulnerabilities for which a patch already existed. Enabling automatic updates on Windows, macOS, and all major applications eliminates this attack surface.

5. Firewall and Network Segmentation

Separate employee networks from guest/IoT networks. Configure the firewall to block unnecessary ports. RDP (port 3389) should never be exposed directly to the internet — use a VPN or Remote Desktop Gateway instead.

6. Antivirus/EDR on All Devices

A properly configured Windows Defender is sufficient for most SMEs. For greater protection, solutions like Malwarebytes for Teams or Microsoft Defender for Business offer centralised visibility at reasonable cost.

7. Basic Phishing Awareness Training

The weakest link is always human. A simulated phishing exercise and a 30-minute session on spotting suspicious emails dramatically reduces incident risk. KnowBe4 and Proofpoint offer free tiers for SMEs.

8. Incident Response Plan

It does not need to be a 50-page document. It just needs to cover: who calls whom if there is a ransomware attack, how to isolate an infected machine, how to restore from backup, and the contact number for your trusted IT technician.

What Does NOT Work

  • Relying on antivirus alone: it is necessary but not sufficient. Modern attacks evade traditional antivirus.
  • Security through obscurity: assuming nobody knows you exist does not protect you. Automated scans discover exposed systems within minutes.
  • Only protecting the server: 90% of attacks enter through endpoints (employee laptops), not the server.

Where to Start If You Are Starting from Scratch

Prioritise in this order: 2FA on email → backups → automatic updates → password manager. With these four measures in place, you will have eliminated 80% of the most common risks. The rest can follow gradually.

If you do not know where to begin or need a quick audit of your current situation, an IT security specialist can perform a diagnosis in a few hours and tell you exactly what to fix first.

More articles

mail

Stay up to date

Get the best articles about IT support, cybersecurity and productivity for SMEs delivered straight to your inbox.

add