Skip to main content

Ikenegbu Extension, Owerri, Imo State, Nigeria

+234 905 403 1378 [email protected] Mon – Fri · 8:30am – 5:30pm (WAT)

The cybersecurity baseline every small organisation should have this quarter

You do not need a security team or a six-figure budget. You need eight controls implemented properly, and the discipline to keep them working.

Most small organisations do not get compromised through sophisticated attacks. They get compromised through ordinary gaps that were known, unglamorous and unfunded.

None of the following requires a security team. All of it requires a decision and somebody accountable for keeping it working.

1. Multi-factor authentication everywhere it is supported

The single highest-return control available. Credential stuffing and phishing both become dramatically less effective when a password alone is insufficient.

Priority order: email first, because email compromise cascades into password resets everywhere else. Then financial systems, cloud tenancies, VPN, and any administrative access.

Use an authenticator app or hardware key in preference to SMS where the choice exists.

2. Tested backups, including one offline copy

Backups are your only reliable recovery from ransomware. "We back up nightly" is not a control; "we restored successfully last quarter" is.

Minimum standard:

  • backups run automatically, not by somebody remembering
  • at least one copy is off-site or in a separate cloud tenancy
  • at least one copy is immutable or offline, so ransomware cannot encrypt it
  • a full restore is tested quarterly and the result is written down
  • you know your recovery time in hours, and it is acceptable to the business

3. Patching on a schedule, with a deadline for critical fixes

Most exploited vulnerabilities have a published patch available well before the attack.

Set a written standard: critical patches applied within seven days, everything else within thirty. Enable automatic updates where they are safe, and track exceptions rather than letting them accumulate silently.

Include the things people forget: routers, firewalls, network equipment, printers, and any software running on a server that nobody logs into.

4. Access that matches the job, reviewed twice a year

Most organisations have far more standing access than anyone needs. Ex-employees retain access, contractors keep credentials after projects end, and everyone ends up an administrator because it was easier than working out the right permission.

Do this:

  • remove administrative rights from accounts that do not need them
  • run a joiner-mover-leaver process with same-day revocation
  • review all access twice a year, with a named approver per system
  • delete or disable dormant accounts
  • use shared mailboxes and generic logins nowhere except where genuinely unavoidable

5. Endpoint protection on every device

Not the free consumer antivirus that came with the laptop. Modern endpoint protection with centralised visibility, so somebody can see when a device stops reporting.

Include the devices people bring. If you cannot protect it, do not let it hold company data.

6. A written incident response plan, and one rehearsal

The plan does not need to be long. It needs to answer, before anything happens:

  • who is contacted first, with phone numbers, including out of hours
  • who has authority to take a system offline
  • who decides whether to notify clients, regulators or law enforcement
  • where the backup restoration procedure lives and who has performed it
  • what the external support arrangement is, if you have one

Print it. Store a copy somewhere accessible when your network is down — which is exactly when you will need it.

Then rehearse it once. A two-hour tabletop exercise finds more gaps than a year of planning documents.

7. Staff awareness that reflects how people actually get caught

Annual compliance videos with a multiple-choice test do not change behaviour.

More effective and barely more expensive:

  • short, specific briefings on the attacks actually targeting your sector
  • simulated phishing with coaching rather than punishment for those who click
  • a clear, blame-free route to report something suspicious quickly
  • explicit rules on payment changes, since invoice fraud is where the money actually goes

The payment-change rule deserves emphasis. A verbal or written confirmation to a known contact before any change of bank details prevents a category of loss that no technical control catches.

8. Know what you have

You cannot secure an inventory you do not have. Most organisations are surprised by what turns up.

Record: every device, every server, every cloud service, every SaaS subscription with company data in it, every domain and DNS record, every administrator account, and every third party with access to your systems.

Review it quarterly. Shadow IT is normal and mostly harmless — until it holds your customer data and nobody knows it exists.

Sequencing if you can only do three

If budget allows only three this quarter, do them in this order:

  1. Multi-factor authentication on email and financial systems
  2. Tested, immutable backups with a documented restore
  3. The payment-change confirmation rule, communicated to everyone who can authorise a transfer

Those three address the majority of realistic loss scenarios for a small organisation, and none of them costs significant money.

What good looks like a year from now

Not a certificate on the wall. Rather: MFA coverage at 100% of accounts that support it, a restore test completed in the last quarter with a written result, patching within your stated deadlines, an access review completed in the last six months, and every member of staff able to tell you what to do if they think something is wrong.

That is an achievable baseline, and it puts you ahead of most organisations your size.

Chidi Okonkwo Head of Infrastructure

Chidi leads infrastructure and managed IT delivery at Vida ICT. He has spent over a decade running multi-site IT estates across energy, healthcare and education, and is responsible for the SLAs, security baselines and monitoring standards the whole delivery team works to.

Full profile
Vida Technologies

Applying this to your own organisation?

We would rather diagnose your situation than sell you a product. Book a call and we will tell you honestly whether this is worth doing now, later, or not at all.

Keep reading

Related insights