Ask a vendor and the answer is "everything, immediately." Ask a busy owner and the answer is "later." Both are wrong. Small businesses get breached constantly — not by masterminds, but by automated attacks that scan the whole internet for the same few weak points. The right question is not whether you need security; it is how much, and in what order.

What attackers actually try against SMEs

  • Stolen or guessed passwords — still the number-one entry point.
  • Phishing emails that steal logins or push fake payments.
  • Unpatched websites and plugins with public exploits.
  • Exposed services (remote desktop, databases) left open to the internet.
  • Ransomware that encrypts everything and prices the demand at what a business your size might pay.

Level 1 — the non-negotiables

This level costs mostly discipline, not money: two-factor authentication everywhere, a password manager, updates applied on schedule, off-site backups you have actually restored once, and access removed the day someone leaves. Most incidents I have responded to would have been prevented right here.

Level 2 — worth real budget

Once the basics hold: an external security assessment of your cloud and applications, endpoint protection (EDR) on staff devices, email filtering, and a short incident plan that names who to call and where the backups live. This is where a security engineer earns their fee — finding the two or three weaknesses specific to your setup.

Level 3 — when you scale or handle sensitive data

Clinics, fintechs, and companies with real customer data need more: monitoring (SOC), secure development practices if you build software, compliance work, and periodic testing. Not because regulators say so — because a breach at this level can end the company.

The honest answer

Match the defense to what you have to lose. A security assessment tells you exactly where you stand and what to fix first — usually one focused engagement, not a retainer. If you want that straight answer for your business, book a review or read the cybersecurity checklist for SMEs.