Whenever cybersecurity guidelines and protocols are mentioned, you know they’re targeted
at businesses with enterprise-level budgets.
The companies with dedicated teams and specialist tools that SMEs can only dream of. It’s not only unattainable, it’s unrealistic, and smaller companies know this, which tends to lead to inertia. But that doesn’t have to be the case.
The reality is that SMEs don’t need to do everything. The six-figure tooling and complex
governance frameworks, they’re irrelevant. What they actually need is to implement a small
number of well-implemented controls, and ensure that they’re adhered to consistently.
The small set of security measures that support SMEs the most
Most cyber security breaches that impact SMEs don’t come down to deliberately targeted
attacks inspired by any particular grievance, but rather opportunity. And those opportunities
come because simple security processes are overlooked. From weak passwords and
unpatched systems, to phishing emails and poor backups. Fixing these issues can
significantly reduce the security threats faced by SMEs.
Multi-factor authentication (MFA) is one of the most effective measures that most SMEs
can deploy when seeking to improve cybersecurity. But it needs to be applied consistently
across platforms, and have protocols put in place to ensure regular password updates.
Compromised login details remain the primary entry point for cyber attackers.
In fact, nearly 68% of confirmed breaches in the 2025 Verizon Data Breach Investigations Report (DBIR) were linked to a surge in stolen usernames and passwords. When you implement MFA, and combine it with role related access, it becomes harder for those breaches to happen.
Patch management is another high-risk area. Unless you have a dedicated IT team, it’s
easy to fall behind on software updates and fixes. And that’s what attackers target. When
you take steps to ensure that operating systems, applications, firewalls, and network devices
are kept up to date, you make it considerably harder for unauthorised access to take place.
Then there’s the matter regular system and data backups. System and data backups
support resilience better than almost anything else.
There were an estimated 7,400 recorded ransomware attacks globally in 2025. But they’re only successful when a company has no way of restoring the stolen data. When you have automated backup systems, protected from tampering, these attacks become far easier to recover from.
The last problem relates to people. You don’t need your entire team to become security
experts, but they should have basic knowledge. How to spot phishing attempts, why
password reuse is dangerous, and how to report suspicious activity. When you train your
team, you build your first line of defence.
These are all simple things that businesses can do to improve their security, but SMEs
continue to waste money without generating noticeable security improvements.
Where SMEs commonly overspend on security
The problem with cybersecurity is that it’s drummed into every business that they have to
spend a lot of money to protect their assets. So, many SMEs end up investing in areas that
provide little real protection.
One common mistake is purchasing advanced security tools without the capacity to manage them. While SIEM systems and complex monitoring tools can work incredibly well, if you don’t have the skilled staff to work with them, they can easily become an expensive annoyance.
There’s also an over-reliance on perimeter security, such as firewalls and secure gateways.
These do matter, and they do have a place, but they don’t do everything. Even the most
expensive tools won’t protect your cloud services, email, or remote workers if you’re not
taking steps to protect access.
Many businesses also come unstuck through a reliance on one-hit security. They invest in
high-end products, but fail to introduce sustainable practices or stay on top of updates.
Cybersecurity must be an ongoing priority, simply because cybercrime is constantly
evolving.
So, what needs to be the focus for SMEs?
The small set of controls that matter most. When you have limited funds available, you always have to prioritise, so start with the question: what would cause the most damage if it failed?
For most businesses, that includes email, core systems, customer data, and the ability to operate day-to-day. And that gives you your list of priorities.
From there, you can work on incremental improvements:
● Start by securing access. That means introducing MFA, strengthening passwords,
and removing unnecessary admin rights.
● Then reduce risk. So, patch systems, remove unused accounts, and simplify
processes where possible.
● The next step is to introduce a business continuity plan. This means ensuring
backups work, incidents can be detected, and your teams understand what they
need to do.
● Work on iteration. When you embed simple processes that can be maintained, you
build security into your company’s core.
Cybersecurity for SMEs is entirely different to enterprise level infrastructure. It has to be. But
when you understand the common threats, and implement simple but consistent and
cohesive controls, you can protect your company without overstretching your budget,
building resilience as you go.
William Thackray, Operations Director, of Manchester based AGT Computer Services