Skip to content
Call

The three ways small businesses actually get breached

Tech323

Every few months a client forwards us an article about a sophisticated new attack technique and asks whether they are exposed. Almost always, the honest answer is: possibly, but it is not what is going to get you. What gets small businesses is boring and it has been boring for a decade.

Here are the three, in the order we see them.

1. A password that was reused somewhere else

Someone used their work email and a familiar password to sign up for a service that later got breached. That combination ends up in a list, and someone tries it against your Microsoft 365 tenant. It works, because nothing stopped it.

The fix costs almost nothing. Multi-factor authentication on email and remote access blocks essentially all of this. If you do one thing after reading this page, do that one. Add conditional access rules blocking sign-ins from countries you do not operate in, and the noise floor drops further.

2. An email that looked legitimate

Not the misspelled prince letter — an invoice from a vendor you actually use, or a message from your own domain because nobody configured SPF, DKIM, and DMARC. The most expensive version is business email compromise: an attacker sits quietly in a mailbox, learns how your company talks about money, and then sends a convincing request to change wire instructions.

The fix has three parts. Filtering ahead of the mailbox. Email authentication configured correctly so your domain cannot be trivially spoofed. And a rule your finance staff follow without exception: any change to payment details gets verified by phone, on a number you already had, not one in the email.

3. A system that missed a patch

A firewall running four-year-old firmware. A server nobody rebooted because nobody was sure what would break. A workstation whose updates have quietly failed for months and never told anyone.

The fix is process, not product. Patching on a tested schedule, monitoring that alerts when it fails, and someone whose job it is to notice. This is the least glamorous item on the list and the one most often skipped.

What this means for your budget

Notice what is not on this list: expensive appliances, a security operations center, or a consultant with a framework. The controls that stop the attacks that actually happen to businesses your size are inexpensive and mostly configuration.

Spend there first. Get MFA everywhere, get email authentication right, get patching under control, and get a backup you have actually restored from. Then, if you have regulatory requirements or a genuinely higher risk profile, talk about what comes next.

If you are not sure where you stand on these four, get in touch — we will walk through them with you.

Talk to someone who will actually pick up

Tell us what is slowing your team down. We will tell you plainly whether we can help, what it takes, and what it costs.