A small business does not need a large-corporation setup. It needs the few measures that genuinely count to be genuinely in place.
IT security has a presentation problem: it is often sold as a stack of expensive tools, which discourages small organizations and leaves them with nothing. Yet most of the real risk is covered by five or six measures, several of them free. Here is what we put in place for small and medium businesses and professional practices in Lyon and the Rhône.
Not sophisticated attacks. In the vast majority of cases:
None of these is dealt with by a more expensive antivirus. They are dealt with by organization.
Two-factor authentication on email. By far the most worthwhile measure: it makes a stolen password practically useless. It is free, can be rolled out across a whole fleet in half a day, and blocks most account hijacking.
An offline backup, tested. Not a backup that runs: a backup you have verified will restore. The question on the day of an incident is not “do we have a backup” but “how long until work resumes”. See business backup.
Named accounts and limited rights. An account shared between three people makes it impossible to know who did what, and it survives their departure. A user working as an administrator gives any malicious program full powers.
Updates applied. A significant share of attacks exploit flaws fixed months ago. This also means knowing which machines no longer receive fixes at all.
Remote access under control. A remote-control service open to the internet with a weak password is attacked continuously, automatically. It is one of the first things we check, and it is often found wanting.
Encryption on laptops. Free and built into Windows: a stolen computer then becomes unusable. Without it, the thief reads everything, your customer data included.
A written internal rule: no change of bank details is acted on without a verification call to a number already known. That one sentence, applied, blocks payment redirection fraud - the heaviest financial loss small businesses suffer, and one that involves no hacking at all.
We start with a review, with no jargon: which machines, which accounts, which data, which backups, which remote access. Many owners discover on that occasion forgotten access rights or a backup that stopped months ago.
We then draw up a list of measures ranked by effort against risk avoided, not in catalog order. You choose what to put in place, and in what order. Some measures are free, others are not, and we make the distinction clearly.
We implement what you settle on, then train your people on the points that concern them: recognizing a fraudulent message, reacting to a doubt, knowing who to turn to. See training.
This is where most of it is decided. Almost every incident starts with something a user did, not with a technical flaw - and that action is almost always prompted by urgency. A team that knows it can flag a doubt without being told off for being naive spots attempts far earlier than any software.
We stress this point with owners: the person who tells you they clicked on something suspicious is doing you an enormous favor.
If you handle personal data - and any business with customers does - certain obligations apply, particularly in the event of a breach. We are not lawyers and do not stand in for specialist advice, but we flag what falls under this heading, in particular the deadlines for notification after an incident.
With two-factor authentication on email and a tested offline backup. Those two cover most of the real risk, and the first is free.
For a small or medium business, rarely. Most of it is handled as part of routine maintenance, provided someone regularly checks that the measures are still in place.
The question no longer works that way: the attacks are automated and do not choose their targets. A badly protected organization is hit because it is reachable, not because it was singled out.
Isolate the machine from the network, change the passwords from another device starting with email, and check the account's automatic forwarding rules. Then have the machine examined.
Can't find your question? It may be in our full FAQ.
Everything worth knowing before you hand over your equipment.
278 questions on breakdowns, security, networking and backup.
What the households and businesses we work with have to say.
Lyon, Villeurbanne, Caluire, Tassin, Écully and the whole Rhône.
Describe your problem: we reply with an initial assessment.
No jargon and no overselling: we distinguish what is free from what is not.
Automatic assistant: it can make mistakes. Never share a password or a card number.