.netCore Sablon ENG

Seven Security Mistakes Small Businesses Keep Making

Attackers do not pick large companies, they pick easy targets. Here are the seven gaps we see most often in small businesses, each with a fix you can apply this week.

The belief that cyber attacks only target large institutions is still widespread. The reality is the opposite: attackers choose targets by weakness of defence, not size of company. Small businesses tend to repeat the same mistakes. These are the ones we encounter most.

1. The same password everywhere

A password leaked from one service also opens the mailbox where it was reused. One leak is enough for a chain collapse. The fix is simple: adopt a password manager and generate a distinct password per service. If the whole team is not using it, it is only half a fix.

2. Two-factor authentication left off

Even a stolen password stops at the second step. At minimum, enable it on email, accounting software, the domain registrar panel and your website admin. Those four are the shortest path to taking over a company.

3. Backups that have never been tested

Taking backups is not enough. Restores should be tested at least annually. In most ransomware cases a backup does exist — but it is either corrupted or was reached and deleted by the attacker. At least one copy should be offline or immutable.

4. Access left open after someone leaves

Departing employees often retain access for months. That is both a security and a compliance problem. Add a checklist to your offboarding process: email, admin panels, shared drives, VPN and any phone line.

5. Deferred updates

The most exploited vulnerabilities are the ones patched months ago. Set an update schedule for servers, site software, plugins and staff machines. One fixed day a month beats never.

6. No phishing awareness at all

Most incidents begin not with a technical flaw but with a link an employee clicked. Even a thirty-minute session once a year with concrete examples makes a measurable difference. Focus especially on urgent payment and your account will be closed themes.

7. Everyone running as administrator

Granting full rights to everyone for convenience turns a single compromised account into a full compromise. Give people enough access to do their job, and no more.

What you can do this week

  • Turn on two-factor authentication for the four critical accounts.
  • Try restoring one file from your backup.
  • Review accounts belonging to people who have left.
  • Install pending updates.

All four fit inside a single week and close a meaningful share of your risk. Security is won through consistency, not large budgets.

The First 24 Hours of a Ransomware Attack

In ransomware incidents, decisions taken in the first hours directly determine the size of the loss. Steps taken in panic frequently destroy the evidence as well.

Do this first

  • Disconnect affected systems from the network but do not power them off. Shutting down erases data held in memory that may be needed for recovery.
  • Check the state of your backups and immediately restrict access to the backup system. Preserving the possibility that the attacker has not reached it is critical.
  • Document the incident: when it was noticed, which systems are affected, what steps were taken. This record serves both the technical response and any legal process.
  • Check your notification obligations. If personal data is involved, mandatory reporting within defined periods may apply.

Do not do this

  • Pay immediately. Payment does not guarantee recovery and encourages further attacks.
  • Rebuild systems in haste. Reinstalling before understanding the entry point leaves the same door open.
  • Hide the incident from the team. Uninformed staff can unknowingly make things worse.

The best preparation is having these steps written down. Improvising during a crisis is no substitute for being ready.

How to Choose a Password Manager for a Team

A password manager is the single tool that raises a small business's security level fastest. When choosing one, look at these:

  • Team sharing: Shared accounts must be shareable securely. Otherwise staff will keep sending passwords over chat.
  • Permission control: Who can access which credential should be configurable. A vault where everyone sees everything opens entirely with one leak.
  • Offboarding: A departing employee's access must be revocable in a single action.
  • Recovery: What happens if the master password is lost must be clear. No recovery means losing the whole vault; recovery that is too easy weakens security.
  • Audit trail: You should be able to see which credential was accessed and when.

Choose not the most expensive product but the one your team will genuinely use. A security tool nobody uses may as well not have been bought. Run a short training session after rollout and allow a week for migrating existing passwords.

This Page 6 times are visited.
History: 02-04-2026