Cyber attacks stopped targeting only banks and large corporations long ago. On the contrary, small and medium-sized businesses are often an easier target because they underestimate cyber security. The good news is that most attacks can be prevented by following a few basic principles.

1. Regular updates

An unpatched system is an open door. Install security updates for your operating system and applications as soon as they come out. Many attacks exploit exactly those vulnerabilities that are well known and were patched long ago. Where possible, turn on automatic updates so you do not have to think about them. Do not forget the firmware of the router and other devices either. A system the vendor no longer supports (for example an old Windows without patches) is best removed from the company entirely.

2. Strong and unique passwords

Use long, unique passwords and ideally a password manager. Wherever possible, turn on two-factor authentication (2FA) - even if someone obtains the password, they cannot get in without the second factor.

3. Backups following the 3-2-1 rule

Keep at least three copies of your data, on two different media, with one copy stored off-site. In a ransomware attack, a working backup is often the only way to get your data back without paying the ransom.

4. Watch out for phishing

The most common gateway for an attack is email. Teach your employees to recognise phishing - suspicious links, attachments and requests for passwords or payments. Warning signs are pressure to act fast, an impersonal greeting, grammar mistakes, and a sender address that at first glance looks like a known company but does not match once you inspect it. Invoice fraud is dangerous too, where an attacker writes from a spoofed address and asks to change the bank account number. When in doubt, verify the sender by phone on a known number, not the one from the email.

5. Antivirus and firewall

Quality antivirus protection and a properly configured firewall on both the router and end devices form the basic line of defence against malicious software.

6. Limit access rights

Every employee should have access only to what they really need. The fewer accounts with high privileges, the smaller the damage if they are compromised.

7. Have a plan and a partner

Even the best prevention may not be enough. Have a procedure ready in case of an incident, and a partner who can help you. A professional IT audit will uncover weak spots before an attacker finds them.

Two extra tips

Once you have the basic seven principles covered, take your protection a level higher:

  • Disk encryption. Turn on BitLocker (Windows) or FileVault (macOS). If a laptop or phone is lost or stolen, the data on an encrypted disk stays unreadable to a stranger. Without encryption, it is enough to pull the disk out and read everything on another computer.
  • Network segmentation. Separate devices into distinct networks, for example company computers, a public Wi-Fi for visitors, and smart home devices (IoT). When an attacker breaks into one device on the guest network, the sensitive ones are no longer easy to reach.

It applies to individuals too

These principles are not only for companies. Strong passwords, 2FA, updates, backups and caution against phishing protect family photos, email and online banking just as well. The difference is only in scale, not in principle.

Do you need to check your company’s security? We are happy to help you with an IT audit and with setting up tailored protection.

Is your business ready for cyber threats?

We check your company's security and advise on backups, passwords and phishing protection. For households and businesses across the Liptov region.

Book an audit

This article is part of our Cybersecurity overview.