Ask a vendor and the answer is "everything, immediately." Ask a busy owner and the answer is "later." Both are wrong. Small businesses get breached constantly — not by masterminds, but by automated attacks that scan the whole internet for the same few weak points. The right question is not whether you need security; it is how much, and in what order.
What attackers actually try against SMEs
- Stolen or guessed passwords — still the number-one entry point.
- Phishing emails that steal logins or push fake payments.
- Unpatched websites and plugins with public exploits.
- Exposed services (remote desktop, databases) left open to the internet.
- Ransomware that encrypts everything and prices the demand at what a business your size might pay.
Level 1 — the non-negotiables
This level costs mostly discipline, not money: two-factor authentication everywhere, a password manager, updates applied on schedule, off-site backups you have actually restored once, and access removed the day someone leaves. Most incidents I have responded to would have been prevented right here.
Level 2 — worth real budget
Once the basics hold: an external security assessment of your cloud and applications, endpoint protection (EDR) on staff devices, email filtering, and a short incident plan that names who to call and where the backups live. This is where a security engineer earns their fee — finding the two or three weaknesses specific to your setup.
Level 3 — when you scale or handle sensitive data
Clinics, fintechs, and companies with real customer data need more: monitoring (SOC), secure development practices if you build software, compliance work, and periodic testing. Not because regulators say so — because a breach at this level can end the company.
The honest answer
Match the defense to what you have to lose. A security assessment tells you exactly where you stand and what to fix first — usually one focused engagement, not a retainer. If you want that straight answer for your business, book a review or read the cybersecurity checklist for SMEs.