Skip to content
Cyber Experts

Three cybersecurity actions that actually move the needle for SMBs

Over 80% of cyber attacks against small businesses exploit three well-known gaps. Here is how to close them in a week.

Published on 3 min read

Most SMB owners I meet ask the same question: "where do we start?". The honest answer is that 80% of cyber attacks that hit businesses under 50 staff exploit three well-known gaps. You don't need a comprehensive strategy. You need to close those three doors.

1. Enable two-factor authentication (2FA) on the 5 critical accounts

Stolen passwords are still the number-one cause of incidents at French SMBs. The fix is free, immediate, and blocks almost all credential-based attacks: 2FA.

The 5 accounts to protect first:

  1. Business email (Microsoft 365, Google Workspace, etc.)
  2. Online banking
  3. Payroll provider
  4. Payment provider (Stripe, etc.)
  5. Hosting / cloud (OVH, Vercel, AWS, etc.)

Time required: 30 minutes. Risk reduction: massive.

2. Set up a real 3-2-1 backup

"We have a backup" is one of the most dangerous sentences in cybersecurity. The 3-2-1 rule says:

  • 3 copies of your data
  • on 2 different media
  • with 1 off-site

Most SMBs I audit have one copy on the office NAS. If ransomware lands, the NAS is encrypted too. Your backup isn't a backup.

Recommended starting tools:

  • For Microsoft 365 / Google Workspace files: a third-party backup service (Datto, Synology Active Backup, Acronis…)
  • For servers: Veeam Community Edition (free up to 10 instances)
  • For a solo-entrepreneur: Backblaze (~€7/mo) + Time Machine on Mac

And test restoration once per quarter. An untested backup is an imaginary backup.

3. Configure DMARC, SPF, and DKIM on your domain

If your domain has no DMARC in quarantine or reject mode, anyone can send email pretending to be you. Your customers receive faked invoices "from you". You pay the damages.

To configure DMARC:

  1. Check your current status at mxtoolbox.com
  2. If you're in none or absent, ask your IT provider (or do it yourself at your registrar) to move to p=quarantine then p=reject over 30 days
  3. Also verify SPF (which servers are allowed to send on your behalf) and DKIM (cryptographic signature of messages)

Time required if you know where to look: 2 hours. If you don't: that's exactly what module 3 of Essentials walks you through, step by step.


These three actions = 80% of the value

Do these three things this week. You'll have closed the majority of attack vectors that actually hit SMBs. The rest, password policy, endpoint management, incident response plan, is important, but marginal in comparison.

If you want the structured version, with templates, scoring, and a certificate to show your insurer, Essentials does it in 7 days, for €297.

Related articles