Skip to content
Cybersecurity6 min read

Cyber readiness: defending against the attacks you will actually see

Most breaches at small businesses are opportunistic, not targeted. That is good news, because it means ordinary controls stop them.

E3 IT Services·
A network operations display showing security monitoring data

There is a persistent belief among small business owners that they are too small to be worth attacking. It is half right. Most are too small to be worth targeting deliberately, which is precisely why the attacks that reach them are automated, indiscriminate, and stoppable.

Automated attacks scan the entire internet for a condition: an unpatched service, a mailbox without multi-factor authentication, a password that appeared in a prior breach. They do not care whose business is behind the condition. Remove the condition and you disappear from that set.

The four conditions worth removing first

  • Mailboxes without multi-factor authentication. Credential stuffing against email is the single most common entry point we see, and MFA closes it almost entirely.
  • Unpatched internet-facing systems. Firewalls, VPN appliances, and remote access tools get exploited within days of a disclosed vulnerability.
  • Local administrator rights on everyday user accounts. Most ransomware needs elevation to do real damage; standard user accounts deny it.
  • Backups that have never been restored. An untested backup is an assumption. Roughly a third of the untested backups we inherit have a problem.

Readiness is a rehearsal, not a document

Plenty of businesses have an incident response plan in a binder nobody has opened. Readiness means someone has actually performed a restore, someone knows who to call at 2 a.m., and someone has verified the backup is not encrypted alongside everything else.

We run restore tests on a schedule for exactly this reason. The first time you restore a server should never be the day you need it.

Where to start

Start with an honest inventory. You cannot protect systems you have forgotten you run, and almost every assessment we perform surfaces at least one forgotten machine still connected to the network. Once you know what exists, the controls above are straightforward to apply.

Free consultation

Questions about any of this?

We are happy to look at your environment and tell you where you actually stand. No obligation.