Cybersecurity
Your customer list is the asset. It's usually the least protected thing you own.
Not enterprise security theatre. The specific controls that stop how a business of your size actually gets breached: reused passwords, dormant accounts, and a backup nobody has ever restored.
Configuration before purchasing · Backups tested, not assumed · Written incident plan
How the bad Tuesday actually goes
08:14
An invoice email arrives
From a supplier you use, with the bank details changed.
08:16
Somebody signs in
On a page that looks exactly like the real one.
11:40
The mailbox is being read
Quietly, by somebody deciding which invoice to intercept.
Any of these
MFA ends it
The cheapest control in this list stops the most common attack.
How does a small business actually get breached?
Almost never by a sophisticated targeted attack. It is a password reused from a site that got breached, an account belonging to someone who left two years ago, a phishing email that looked like an invoice, or ransomware reaching a machine that had not been patched. All four are cheap to defend against.
That is the useful frame, because it changes what you should buy. Security marketing at this size sells sophisticated-sounding products against threats that are not the ones arriving. The controls that genuinely reduce risk for a fifteen-person contractor are unglamorous and mostly free: multi-factor authentication, closing old accounts, patching, and proving the backup restores.
So the sequence here is deliberate. Configuration first, because it removes most of the realistic risk in about two weeks. Products second, and only where they close a gap configuration cannot.
How the four realistic routes in get closed
- Reused passwordsMFA on every account, enforced, not offeredWeek 1
- Accounts of people who leftOffboarding that actually removes accessWeek 1
- Invoice-shaped phishingMail authentication, banners, one hour of trainingWeek 2
- Unpatched machinesManaged updates and endpoint monitoringOngoing
- RansomwareOffsite backup, restored on a schedule to prove it worksOngoing
What's included
The controls, in order of value
Multi-factor authentication, everywhere
On every account, including the admin ones people conveniently exempt. The single highest-value control available, and the one most often half-implemented.
Endpoint protection and monitoring
Managed detection on laptops, desktops and servers, with alerts that reach a person rather than accumulating in a console nobody opens.
Dormant account cleanup
Accounts belonging to former staff, shared logins nobody owns, and admin rights granted years ago for one task. This is how businesses this size actually get breached.
Backups that have been restored
Backup configured, and then a restore actually performed to prove it works. An untested backup is a belief, not a control, and plenty of them fail on first use.
Email security and phishing defence
Authentication records, external sender warnings, attachment and link scanning, and impersonation protection for the owner's name — which is what invoice fraud uses.
Device and patch management
Operating systems and browsers kept current, disk encryption on, and a way to wipe a phone or laptop remotely when one is left in a truck at a job site.
Access reviewed on a schedule
Who can see what, checked quarterly rather than assumed. Permissions accumulate; nobody ever removes them unless it is somebody's job.
An incident plan that names people
What to do in the first hour, who to call, where the backups are, and who talks to customers. Written before you need it, because nobody writes it well at 11pm.
How it works
Close the gaps, then deploy, then test
Find what is exposed
Week 1Accounts without MFA, dormant accounts still active, admin rights nobody reviewed, external sharing left open, and whether the backup has ever been restored.
Close the obvious gaps
Weeks 1–2MFA enforced, dormant accounts suspended, admin roles reduced, sharing brought under a rule. Cheap, fast, and it removes most of the realistic risk at this size.
Deploy protection and monitoring
Weeks 2–4Endpoint agents on every device, alerting routed to someone who will act, and patch management running on a schedule instead of when somebody notices.
Test the restore, then write the plan
Weeks 4–5A real restore from backup, and an incident response plan naming actual people. The test is the part that matters — it is where untested backups are found to have been failing quietly.
The one that catches people
Most backups have never been restored
Nearly every business has backups. Far fewer have ever restored from one, and the gap between those two facts is where the genuinely bad outcomes live. Backup jobs report success while silently excluding a folder that was moved. Retention windows turn out to be seven days when everyone assumed thirty. Cloud file sync gets mistaken for a backup, which it is not — it faithfully replicates the ransomware encryption to every device.
So a restore test is part of the engagement rather than an optional extra. It is the only way to know, and finding out during an incident is the most expensive possible moment to learn it.
Fit
Who this suits, and who it doesn't
This is a good fit if
- Your customer list, quotes and job history live in cloud accounts and on laptops.
- Not every account has multi-factor authentication switched on.
- You have never tested a restore from backup.
- Staff have left and nobody is certain their access was fully removed.
- Your cyber insurance renewal is asking questions you cannot currently answer.
This isn't the right fit if
- You need a formal certification — SOC 2, ISO 27001 — for a contract. That is a specialist engagement and we would refer you.
- You want penetration testing. Also specialist, and premature before the basics are in place.
- You want to buy a product and consider it handled. Configuration is the work; the product is a fraction of it.
- You already have a managed security provider doing this properly. Then this is duplicated spend.
Related
What security touches
Google Workspace & Microsoft 365
Accounts, shared drives, email deliverability, security and file storage — set up properly and administered daily.
Network & Wi-Fi installation
Structured cabling, Wi-Fi that reaches the shop and the yard, and camera runs — certified, labelled and documented.
Business phone & call tracking
Calls that reach a person, missed calls counted, and every call attributed to the campaign that produced it.
Questions about cybersecurity
What is endpoint protection?
Security software on every device that connects to your business — laptops, desktops, servers and often phones — that detects and blocks malicious activity and reports it centrally. It replaces consumer antivirus with something that can be monitored and managed across the whole business.
Is a small business really a target?
Not usually a specific one. Most attacks at this size are opportunistic and automated: credential stuffing against accounts with reused passwords, phishing sent to thousands of addresses, and ransomware that spreads to whoever is unpatched. Being small is not cover.
What is the single most valuable thing we can do?
Turn on multi-factor authentication for every account, including the admin ones. It is free, takes an afternoon, and closes off the attack that most commonly succeeds against businesses of this size — a password that was reused somewhere that got breached.
Do we need cyber insurance?
Increasingly, and read the conditions carefully — many policies now require MFA, tested backups and endpoint protection to be in place, and will decline a claim if they were not. Meeting those conditions is often a better reason to do this work than the risk itself.
How do we know our backups actually work?
By restoring from them. Not by checking that the job reported success. We perform a real restore as part of the engagement, and it is not unusual to find a backup that had been silently failing or excluding the folder that mattered most.
What about PIPEDA and customer data?
Under Canadian federal privacy law you are responsible for safeguarding personal information you hold and for reporting breaches that pose a real risk of significant harm. We build so those obligations are keepable and document where data lives. Your legal obligations remain yours.
What happens if we do get breached?
The incident plan gets used: isolate affected devices, assess what was reached, restore from a known-good backup, change credentials, and handle notification obligations. Having that written in advance is the difference between a bad week and a much worse month.
How is this priced?
Per device per month for endpoint protection and monitoring, plus a one-off project for the initial remediation. The initial security work — MFA, dormant accounts, admin roles — is fast and cheap, and it is where most of the risk reduction happens.
Find out what's currently exposed.
The technology audit checks every account for MFA, finds the ones still active for people who left, reviews admin rights, and establishes whether your backup would actually restore. Free, written, no obligation.
You talk to Mathew.Not an account manager, and not a sales team.