Before firewalls and advanced tooling, most small businesses are missing a handful of basics. Here's where to start.
Cybersecurity conversations with small businesses often jump straight to advanced tooling, when the actual risk usually sits in a handful of basics that were never set up properly in the first place. We start every security audit in the same place.
The most common gap we find isn't a sophisticated attack vector — it's a shared login still being used by three former employees, or an admin account with a password that hasn't changed since setup. Fixing who has access to what is usually the single highest-impact first step.
Plenty of businesses have backups configured and have never once tried restoring from them. A backup nobody has tested is a backup you're hoping works, not one you know works. We treat a restore test as part of the setup, not an optional extra.
Most breaches we see start with a person, not a system — a convincing phishing email, a password reused across five tools. A short, practical training session does more for most small businesses than another piece of security software.
Unpatched software is one of the most common entry points, and it's also one of the most boring to fix — which is exactly why it gets neglected. Setting updates to run automatically where possible closes a surprising amount of exposure with almost no ongoing effort.
None of this is glamorous, and that's the point — the basics quietly close most of the risk before you ever need to think about anything more advanced.