Guide · SME cybersecurity

SME cybersecurity essentials: practical controls that matter

An SME does not need to reproduce a large enterprise security programme. It does need to know its critical systems and data, assign ownership and apply a practical baseline consistently.

1. Build a phishing procedure, not a blame exercise

Phishing uses email, messages, calls or imitated websites to obtain credentials, money or execution of a file. Convincing messages often exploit urgency, authority and familiarity.

Use a simple procedure: pause, avoid links or contact details in the suspicious request, verify through a known channel, report internally and preserve useful evidence.

  • Unexpected login, payment or download request
  • Pressure to bypass normal controls
  • A slightly altered domain
  • Sudden payment-detail change
  • Requests for passwords, codes or MFA approval

Fast reporting helps. A punitive culture can make people hide mistakes and delay containment.

2. Make account theft harder

Enable MFA first for email, administrators, remote access, cloud storage, business systems, domain administration, hosting and backups. Use phishing-resistant methods where available and appropriate.

Use unique passwords through an approved password manager, remove unused accounts and separate standard and administrative identities. Remove access promptly when roles change or people leave.

  • MFA on priority accounts
  • No shared accounts where avoidable
  • Least privilege
  • Prompt access revocation
  • Reject and report unexpected MFA prompts

3. Reduce ransomware entry, spread and impact

Ransomware can encrypt information, disrupt operations and include data theft. Initial access may involve phishing, compromised credentials, vulnerable software, exposed remote services or connected suppliers.

  • Update systems, applications and network devices
  • Restrict administrative privileges
  • Protect remote access with MFA and supported configurations
  • Inventory third-party services and supplier access
  • Configure endpoint protection and useful logs
  • Segment critical systems where appropriate
  • Prepare backup and restoration

4. Build backups you can actually restore

A backup connected with the same privileges as production may be deleted or encrypted with the original. Define which data and configurations matter, how much work the business can lose and how quickly it must recover.

Do not rely on a “backup completed” message. Restore samples periodically and test recovery of the most important systems at a frequency appropriate to risk. Record who performs the test, where data is restored and how integrity is checked.

  • At least one copy separate from production
  • Protected backup accounts and consoles
  • Previous versions and offline or immutable copies where appropriate
  • Monitoring of failed jobs
  • Documented restoration tests

5. Ten essential controls in a practical order

  1. Assign an owner and maintain an inventory of devices, accounts, software, data and suppliers.
  2. Enable MFA and separate standard and administrative identities.
  3. Define routine updates and an urgent route for critical vulnerabilities.
  4. Maintain separate, tested backups.
  5. Apply least privilege and review external sharing.
  6. Configure email and endpoint protection.
  7. Train people and make reporting easy.
  8. Retain useful logs and assign alert handling.
  9. Prepare and exercise an incident plan.
  10. Record supplier dependencies and access.

6. Responding to a suspected incident

Exact actions depend on the circumstances. Avoid improvised changes that may destroy evidence or make disruption worse. Involve assigned IT and specialist support quickly.

  1. Activate the incident owner and plan.
  2. Use an unaffected communication channel if required.
  3. Contain affected systems using a safe procedure.
  4. Record times, accounts, systems and actions.
  5. Manage compromised credentials and sessions from a trusted device.
  6. Verify backup integrity before restoration.
  7. Assess reporting and notification with legal/privacy contacts and competent authorities.
  8. Restore by priority and monitor for recurrence.
  9. Run a lessons-learned review and address identified causes.

This is not a personalised incident-response plan. During a real event, engage appropriate specialists and local authorities promptly.

A practical 30-day priority plan

  1. Week 1 — assign ownership, inventory critical systems and record suppliers and emergency contacts.
  2. Week 2 — enable MFA, remove unused access and review remote access.
  3. Week 3 — check updates and backups; complete one documented restoration test.
  4. Week 4 — share the anti-phishing procedure and run a tabletop exercise.

Kreluna Cyber is in active development. No scan or technical activity is carried out without explicit scope and authorisation.

Project method

Mini-runbook for a suspicious message or activity

Agreeing first actions before an incident reduces improvisation and lost evidence. Adapt contacts and responsibilities to your organisation.

  1. Stop interacting

    Do not reply, open more files or enter credentials. Where appropriate, disconnect the device from the network without powering it down.

  2. Report quickly

    Use the defined internal channel and state the time, sender, action taken and device involved.

  3. Protect accounts

    The responsible team assesses session revocation, credential reset and access review rather than taking uncoordinated action.

  4. Preserve and assess

    Keep the message and useful evidence; involve support, management and competent authorities as the situation requires.

Before you begin

Common questions about essential controls

Is antivirus enough?

No. Identity, updates, privileges, backups, awareness and incident response address different, complementary risks.

Is a cloud backup enough for ransomware?

Not always. Copies need separation, protection against unauthorised change and restore tests that reflect real systems.

Does the checklist prove compliance?

No. It is a general prioritisation tool; the organisation’s duties, contracts and risks require a specific assessment.

Institutional sources and further reading

Start with one defined use case

Describe the objective, current workflow and general type of information involved. Do not send credentials, personal data or confidential documents in an initial message.

Continue exploring