If you are an SME leader looking to strengthen your company's cybersecurity quickly and, more importantly, effectively, you have come to the right place. When running a business, it is common to prioritize other areas over cybersecurity—this is especially true for SMEs.

However, in the event of an attack,SMEs are the most vulnerable and have fewer resources to recover. The consequences can be financial, operational, and even damaging to the company's reputation , to the point of leading to closure just months after the incident.

An alarming report from the National Cyber Security Alliance reveals that 60% of small businesses close within six months of a cyberattack, particularly in the event of a data breach.

Implementing a solid cybersecurity strategy takes time, and it can be months before it is fully operational. That is why we have put together a list of simple best practices that you can apply right now to protect your business.

I. Password Management Policy

Strong passwords are the first step toward securing your business. It is essential that all your employees choose complex and unique passwords every time a new one is required.
A good password should be difficult to guess:

  • Contain at least 12 characters
  • Include a mix of uppercase and lowercase letters, numbers, and special characters

To generate these types of passwords without having to memorize them, use password managers that will create them automatically and store them securely.

II. Two-Factor Authentication (2FA)

To secure access to your company's sensitive information and systems, implement two-factor authentication (2FA) wherever possible. This will strengthen your company's security by requiring two forms of identification when logging in via:

  • A code received by SMS
  • An authentication app such as Microsoft Authenticator or Google Authenticator

Ideally, this second factor should not be a personal phone but a work phone, in order to limit risks. Indeed, smartphones can be a security vulnerability, especially if they are used for both personal and professional purposes.

III. Regular Backups

Implement a backup policy within your company. Your teams should back up data daily and store it in a secure location. This measure may seem simple, but it is one of the fastest ways to protect yourself against ransomware.
In fact, some companies back up their data exclusively in the cloud. However, cloud services can also be vulnerable to cyberattacks.
Ransomware represents the second greatest threat to SMEs.

It is common to see companies go bankrupt after an attack of this type. For example, a 150-year-old SME closed down in just three months following a ransomware attack, according to a recent article in The Times.
Frequent backups significantly reduce the risks, as you will be able to recover your data in the event of lost access.

IV. Limiting access (physical and digital)

Only a restricted and authorized number of employees should have access to:

  • Your company's critical infrastructure
  • Your backups
  • Your sensitive systems
    Regarding digital access:
  • The administrator privileges must be limited to trusted individuals, ideally the IT team
  • Employees should only have access to the information necessary for their work

V. Regular updates

Ensure all your software is always up to date. Updates and patches are released to fix detected security vulnerabilities.
Enable automatic updates to save time, but check regularly to ensure they are running correctly.

Example of a preventable attack:
 In 2017, the WannaCry ransomware infected over 200,000 computers across 156 countries. Yet, Microsoft had released a patch a year before the attack. Companies that had not installed it were the primary victims.

VI. Business continuity and disaster recovery plan

To secure your business, you must also prepare for the worst-case scenario.

How would your company continue to operate in the event of a cyberattack? We have listed the main threats to SMEs. Each one can have different consequences; what would you do in each case to ensure your business continuity? Following the WannaCry attack, for example, the National Health Service British firm has reviewed its business continuity plan and updated it to better anticipate the impact such an attack could have on its operations.

In addition, implement a disaster recovery plan. What steps must you take to restore your systems and recover your data in the event of an attack? Ensure that the entire company is aware of these steps so that operations can resume as quickly as possible.

VII. Employee awareness and training

A study conducted by IBM revealed that 95% of security breaches involve human error.
Phishing attacks are the number one threat to SMEs, and they rely on one thing: human error.
To strengthen your employees' vigilance, you can:

  • Regularly explain cybersecurity best practices
  • Organize training sessions on secure passwords, web browsing, etc.
  • Simulate phishing attacks to test their reactions
  • Set up workshops on cybersecurity incident management

VIII. Verify that everything is secure

Finally, ensure that every part of your company's infrastructure is protected. This involves regularly verifying the effectiveness of your cybersecurity measures:are backups being performed daily? Is your business continuity plan up to date? Are your employees aware of phishing attempts?

In addition to these best practices, it is essential to secure your computers, smartphones, and tablets against cyberattacks. An End Point Detection & Response (EDR) solution will protect you against all the threats that SMEs face, including those generated by AI that are not yet known. We offer the most affordable EDR on the market, specifically designed for SMEs.
Discover it here: https://tehtris.com/en/platform/edr-endpoint-detection-response/

To secure the rest of your infrastructure (your smartphones and mobile devices), a Mobile Threat Detection (MTD) solution will help you manage them while protecting them from threats.
All the information here: https://tehtris.com/en/platform/mtd-mobile-threat-defense/

Continue reading
Blog
Contactez Tehtris
Nos équipes vous recontacteront au plus vite afin d'échanger sur vos challenges cyber et évaluer comment nous pouvons vous accompagner pour les adresser.
Tehtris EDR : conçu, développé et opéré en Europe
Voir nos preuves
Derniers articles
See all