Back to all articles

    Cybersecurity for Small Businesses: 10 Concrete Steps for 2026

    SkySysNet TeamMarch 30, 20268 min read
    Cybersecurity for Small Businesses: 10 Concrete Steps for 2026

    Small businesses are still target #1

    Attackers love SMBs because the security budget is small but the payday is reasonable: payroll, M&A documents, customer data, supplier ACH details. In 2026, the question for a company under 50 people isn't whether you'll be targeted — it's whether the basics catch the attempt before it becomes an incident.

    This guide is a sequenced list. Don't pick the items that sound interesting; implement them in order. Each item assumes the previous ones are in place. Budget ranges at the end assume a 25–50 person company.

    Outline

    1. Enforce MFA everywhere
    2. Password manager + passkeys
    3. EDR on endpoints, not just antivirus
    4. Patch management policy
    5. Immutable, off-site, tested backups (3-2-1-1-0)
    6. Least privilege and clean offboarding
    7. Email security and anti-phishing training
    8. Network segmentation
    9. Incident response runbook and cyber insurance
    10. NIS2 and DORA awareness for EU SMBs

    1. Enforce MFA everywhere

    Email, identity provider, banking, admin panels, RMM tools, code repositories, VPN. Phishing-resistant MFA (FIDO2 / passkeys) where supported; TOTP elsewhere; SMS as a last resort. Block legacy authentication entirely on Microsoft 365 and Google Workspace. Audit who still has MFA exemptions and remove them.

    2. Password manager + passkeys

    A team password manager (1Password, Bitwarden, Keeper) shared by everyone, with breached-password alerting and SSO where possible. Adopt passkeys for any service that supports them — they remove phishing entirely for that login. Don't let passwords live in spreadsheets or browser keychains.

    3. EDR on endpoints, not just antivirus

    Classic AV catches commodity malware. EDR (endpoint detection and response) catches living-off-the-land techniques, ransomware staging, credential theft. Pick one with managed detection (MDR) if you don't have a 24/7 SOC. Budget 4–8 EUR per endpoint per month all-in. Coverage must include personal devices accessing company data.

    4. Patch management policy

    A written policy that says: critical patches inside 7 days, high inside 14, others inside 30. Apply to OS, browsers, productivity suites, business applications, firmware and routers. Automate where possible, but verify deployment rates monthly. Most ransomware in 2026 still rides on year-old unpatched vulnerabilities.

    5. Immutable, off-site, tested backups (3-2-1-1-0)

    The modern version of the old 3-2-1 rule:

    • 3 copies of important data
    • 2 different media
    • 1 copy off-site
    • 1 copy immutable (object-lock or air-gapped)
    • 0 errors after the most recent restore test

    That last digit matters most. Untested backups are theatre. Schedule a quarterly restore drill of a real workload, not just a file.

    6. Least privilege and clean offboarding

    Two flavours of the same hygiene. Every account — human or service — gets only the permissions it needs, reviewed quarterly. Offboarding has a checklist: disable accounts within an hour, revoke MFA tokens, rotate shared credentials, collect devices, transfer file ownership. Most data exfiltration by ex-employees happens because step three was skipped.

    7. Email security and anti-phishing training

    Configure SPF, DKIM and DMARC with p=reject on your domain. Run quarterly phishing simulations with brief, non-shaming follow-up training. Block executable attachments at the gateway. Mark external senders visibly in every inbox. Train finance on payment-change requests specifically — that's where the seven-figure losses happen.

    8. Network segmentation

    Guests on their own SSID and VLAN. IoT (cameras, printers, smart TVs) isolated from production. Servers separate from user workstations. East-west firewall rules to stop one infected laptop from reaching the file server. This costs little if planned in advance and a fortune to retrofit after a breach.

    9. Incident response runbook and cyber insurance

    A one-page runbook: who declares an incident, who calls the lawyer, who notifies customers, who isolates systems, where the backups are, who the insurer is, where the policy lives. Pair it with a cyber insurance policy you've actually read — including the conditions (MFA, EDR, backups) the insurer requires for payout.

    10. NIS2 and DORA awareness for EU SMBs

    NIS2 applies broadly to "essential and important entities" — many mid-market companies fall in scope, and supplier-chain clauses pull smaller companies in indirectly. DORA hits financial services and their IT suppliers. You don't need to memorise the texts; you need to know whether you're in scope, and if so, which articles drive your minimum controls.

    Realistic budget ranges (25–50 person company, 2026)

    LayerEUR / month all-in
    EDR + MDR200 – 500
    Email security gateway80 – 200
    Backup with immutability150 – 400
    Password manager50 – 150
    Phishing training platform80 – 200
    Cyber insurance (annualised)250 – 800

    That puts a baseline security stack in the 800–2,200 EUR/month range, plus partner time. Below that, you're probably uninsurable.

    One-page checklist

    • MFA everywhere, legacy auth blocked
    • Team password manager + passkeys
    • EDR + MDR on every endpoint
    • Patch policy with monthly review
    • 3-2-1-1-0 backups, quarterly restore drill
    • Quarterly access review and offboarding checklist
    • SPF / DKIM / DMARC at reject, phishing simulations
    • Network segmentation: guests, IoT, servers, users
    • One-page IR runbook + cyber insurance read
    • NIS2 / DORA scoping done

    Key takeaways

    • The order matters. MFA, password manager, EDR and backups dwarf everything else in payback per euro.
    • 3-2-1-1-0 is the modern backup standard. The "0" — tested restores — is non-negotiable.
    • Cyber insurance only pays if you actually meet its conditions. Read them.
    • NIS2 likely applies more broadly to your supplier chain than you think.

    If you'd like a fixed-scope security audit against this checklist, get in touch — you'll talk to an engineer, not a sales rep.

    Frequently asked questions

    What are the first cybersecurity steps a small business should take in 2026?+

    In order: enforce MFA everywhere with legacy auth blocked, deploy a team password manager and adopt passkeys, install EDR (not just antivirus) on every endpoint, write a patch policy with 7/14/30-day SLAs, and implement 3-2-1-1-0 backups with quarterly restore drills. These five together cover the vast majority of attacks aimed at SMBs and unlock most cyber insurance policies.

    What is the 3-2-1-1-0 backup rule?+

    It is the modern version of the classic 3-2-1: keep three copies of important data, on two different media types, with at least one off-site, one immutable (object-lock or air-gapped), and zero errors after the latest restore test. The "0" is the part most teams skip — untested backups are theatre. Schedule a quarterly drill restoring a real workload, not just a single file.

    Does cyber insurance actually pay out if we get breached?+

    Only if you meet the policy conditions. Modern policies require MFA on critical accounts, EDR on endpoints, tested backups and a written incident response plan. Read the small print before you need it. Many declined claims in 2025 came down to MFA gaps on a single admin account or untested backups. Match controls to the policy and document the evidence.

    Does NIS2 apply to small companies in the EU?+

    It applies directly to many "essential and important entities" defined by sector and size thresholds, and indirectly to smaller suppliers through supply-chain clauses imposed by larger in-scope customers. Practically, a 25-person company supplying a hospital, energy operator or large bank will face NIS2-derived contractual requirements even if not formally in scope. Map your exposure first, then implement.

    What is a realistic monthly cybersecurity budget for a 25–50 person company?+

    A baseline stack in 2026 lands around EUR 800–2,200 per month all-in: EDR + MDR (200–500), email security gateway (80–200), backup with immutability (150–400), team password manager (50–150), phishing training platform (80–200) and annualised cyber insurance (250–800). Add partner time on top. Below that you are likely uninsurable and operating on borrowed time.

    Related articles

    Zanim wyślesz zapytanie, sprawdź podstawy

    Checklista pomaga szybko ocenić monitoring, backup, dostępność usług i odpowiedzialność za krytyczne elementy IT.

    Pobierz checklistę

    Need help with your IT infrastructure?

    We will advise, design and deploy a solution tailored to your company.