Category: Cybersecurity
Most small businesses that get breached weren’t targeted by a genius. They were targeted by a script that scanned thousands of companies looking for one of a handful of common gaps — and found it. The FBI’s 2024 Internet Crime Report put total reported cybercrime losses at $16.6 billion, a 33% jump over the prior year, and ransomware remained the most pervasive threat to critical infrastructure. Small businesses aren’t spared because they’re small. They’re chosen because they’re softer.
After years of cleaning up after these incidents, we see the same five gaps over and over. None of them are exotic. All of them are fixable in an afternoon or two.
Mistake 1: No multi-factor authentication on email and remote access
If we could fix one thing across every business in Phoenix, it would be this. A stolen or guessed password is worthless to an attacker who also needs a code from your phone. Yet we still walk into offices where Microsoft 365, the VPN, and the remote-desktop gateway all accept a password alone.
The fix: Turn on MFA everywhere it’s offered, starting with email, remote access, and any admin account. In Microsoft 365, that means enforcing it through Conditional Access (or Security Defaults at minimum) and blocking legacy authentication protocols that quietly bypass MFA entirely. Use an authenticator app or hardware key rather than SMS where you can.
Mistake 2: Treating the firewall and antivirus as “set and forget”
A firewall you bought in 2019 with a lapsed subscription is a doorstop with a login page. The same goes for the free antivirus that came with the machine. Threats change monthly; a security product that isn’t updating and isn’t being watched is providing comfort, not protection.
The fix: Confirm your firewall’s security subscription is active and its firmware is current. Replace consumer-grade antivirus with a managed endpoint detection and response (EDR) tool that actually alerts someone when something is wrong. The alert is the point — software that catches a problem at 2 a.m. and tells no one hasn’t done much.
Mistake 3: Everyone’s a local administrator
It’s convenient to give staff full admin rights so they can install what they need. It’s also how a single click on a malicious attachment turns into an infection that spreads across the whole network instead of staying trapped in one user’s account. Most ransomware needs administrative privileges to do real damage.
The fix: Give day-to-day accounts standard-user rights. Keep admin credentials separate and use them only when installing or changing software. This one change dramatically limits how far an attacker or a bad download can travel.
Mistake 4: Assuming the backup works because it exists
This deserves its own article (and has one), but it belongs on this list. A backup you have never restored from is a hypothesis, not a safety net. We have watched businesses discover — mid-crisis — that their backup had been silently failing for months, or that it was sitting on a drive the ransomware also encrypted.
The fix: Keep at least one backup copy offline or immutable, so it can’t be reached and encrypted. Then test a restore on a schedule. If you can’t produce a working file from last night’s backup in a few minutes, you don’t yet have a backup you can trust.
Mistake 5: No plan for the human in the chair
Nearly every serious incident starts the same way — a person receives a convincing message and does what it asks. No firewall stops an employee from wiring money to a fake vendor or typing their password into a lookalike login page. The people are the perimeter now.
The fix: Run short, regular security awareness training — not an annual lecture, but ongoing, plain-language examples of what current scams look like. Pair it with a simple rule for anything involving money or credentials: verify out of band. A phone call to a known number beats a reply to a suspicious email every time.
The common thread
None of these fixes require a big budget or a security team. They require someone to own them and keep them current. That’s the actual gap in most small businesses — not a lack of tools, but a lack of anyone whose job it is to make sure the tools are turned on, updated, and watched.
If you’re not sure which of these five apply to you, that uncertainty is worth resolving before an attacker resolves it for you.
Want a straight answer on where you stand? Book a free 30-minute consult and we’ll walk through these five with your actual setup — no sales pitch, just where the gaps are