Cybersecurity for SMBs: 7 Actions You Can Take Today
Protect your SMB from ransomware and phishing without an IT team. 7 practical steps you can implement this week.
Mexican SMEs are frequent targets for cyberattacks. Not because they're particularly valuable, but because they're abundant, often vulnerable, and attackers know they have low security budgets. Here's how to protect your company without unlimited resources.
Why SMEs Are Targets
1. Valuable assets, low attack cost: An SME with 100 customers has data that attackers can monetize. The cost of performing an attack is the same for an SME as for a large company, but the payoff is sufficient to justify it.
2. Supply chain: Many cybercriminals attack SMEs not to steal from them, but to access their larger clients. If you're a supplier to a multinational, you're an attack vector.
3. Limited security personnel: Most SMEs don't have an IT team dedicated to security. A general IT person is busy supporting users, not strengthening defenses.
4. Low budget, high vulnerabilities: Without professional tools, many systems are weakly configured.
The Three Main Attack Vectors
1. Email (Phishing)
90% of breaches start with email. An attacker:
- Sends you an email that looks like it's from your bank, supplier, or client
- Contains a link or file you "need to open"
- When you click, your credential or malware is captured
How to protect:
- Training: Teach your team to recognize phishing (looks subtly wrong, artificial urgency, requests credentials)
- Email filtering: Use filters that detect known phishing
- Multi-factor authentication (MFA): Even if they steal your password, they can't get in without a second factor
- Don't trust email links: Navigate manually to the known URL instead of clicking
2. Weak Remote Access
Many SMEs have:
- VPN with weak passwords
- RDP (Remote Desktop) exposed to the internet without MFA
- Shared credentials between users
Attackers often get this information from publicly leaked data, then try to access. If you're lucky, you see logs of failed attempts. If not, one succeeds.
How to protect:
- MFA on all remote access: If someone gets your password, they can't get in without the second factor
- Modern VPN: Instead of traditional VPN, consider zero-trust VPN (Microsoft Defender for Cloud, etc.)
- Credential rotation: Change passwords regularly
- Access monitoring: Review logs of who accesses, from where, when
3. Ransomware
Ransomware encrypts your data and demands money for the decryption key. It often arrives via phishing, credential brute force, or exploits of outdated software.
Once it's in:
- It encrypts all your data
- It deletes your backups
- It leaves a note demanding money
How to protect:
- Offline backups: Data copied to a place with no network connection. Even if ransomware encrypts your server, you can restore from backup
- Network segmentation: If ransomware infects one machine, it can't reach everything. Isolate sensitive data
- Patching: Regularly update software. Many exploits use known vulnerabilities in old software
- EDR (Endpoint Detection and Response): Software on each machine that detects suspicious behavior
Microsoft 365: An Underestimated Security Fortress
Many SMEs use Microsoft 365 (Office 365) but don't use its built-in security. Microsoft 365 includes:
Defender for Office 365:
- Advanced email filtering
- Sophisticated phishing detection
- Sandboxing of suspicious files
Defender for Cloud Apps:
- Monitoring of who accesses what
- Detection of anomalous behavior (access from impossible location, multiple failed attempts, etc.)
- Automatic blocking of suspicious access
Conditional Access:
- Requires MFA when you access from unknown location
- Blocks access from devices without updated passwords
The cost: You already paid for it. You just need to enable and configure it.
Incident Response: When Something Goes Wrong
Even with excellent defense, breaches sometimes occur. Here's how to respond:
Phase 1: Detection
How do you find out? Ideally from your own monitoring (EDR alerts, suspicious logs). But often it's a customer or bank notifying you they see suspicious activity.
Phase 2: Containment
Act quickly:
- Isolate the compromised device/account
- Change passwords for critical accounts
- Review logs to see what the attacker accessed
Important: Don't panic. Don't shut everything down. You need to preserve evidence for investigation.
Phase 3: Investigation
Determine:
- What data was accessed
- When the access started
- How long the attacker was inside
Phase 4: Notification
If customer data was exposed, you must notify under LFPDPPP.
Phase 5: Recovery
Restore from backup, patch the vulnerability, implement additional defenses so it doesn't happen again.
24/7 Monitoring: Detect Before You Lose
Most attacks happen outside business hours because attackers know nobody's watching. A SOC (Security Operations Center) or managed service monitors your systems 24/7:
- Real-time log analysis
- Automatic alerts on suspicious activity
- Quick incident response
For an SME, this was prohibitively expensive years ago. Now there are affordable managed services that provide this.
Security Checklist for SMEs
- [ ] Strong, unique passwords for each service
- [ ] MFA on all remote access and critical accounts
- [ ] Regular and tested backups (ideally offline)
- [ ] Updated software on all devices
- [ ] Email filtering and malware protection
- [ ] Access control based on need (principle of least privilege)
- [ ] Access auditing (who saw what, when)
- [ ] Documented incident response plan
- [ ] Security training for employees
- [ ] 24/7 monitoring or automatic alerts on suspicious behavior
At Simiriki, we implement these controls with our Operation so they work together. It's not something you do once and forget. It's an ongoing process of monitoring, updating, and responding. Start with a free diagnostic to assess your current security posture.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.