Small Company, Same Attackers
"We're too small to be a target" is a statement about attention. Automated attacks don't pay attention- they scan, and they don't check your revenue first.

There is a comfortable belief among smaller organisations that they are beneath notice. It rests on an image of the attacker as a person choosing a victim- evaluating prestige, sizing the payoff, selecting a worthy target.
That image describes a small minority of attacks. The overwhelming majority are automated. Software scans address ranges continuously, looking for a known-vulnerable version, an exposed admin panel, a reused credential, a service left open. It finds these things without knowing or caring what your company does, how many staff you have, or what you earn. The scan is indiscriminate by design, because indiscriminate is cheap.
You are not too small to be found. You may only be too small to be interesting afterwards- and that is a very different kind of protection.
The unglamorous list does most of the work
Security marketing gravitates toward sophistication. The measures that actually prevent the majority of real incidents are far more boring, and most organisations have not finished them.
Multi-factor authentication, everywhere it is offered. The single highest-value control available to most businesses. A stolen password stops being sufficient. Enable it on email first- email is the recovery route for everything else, which makes it the master key.
Patching, on a schedule someone owns. The vulnerabilities in automated scans are known ones with published fixes. The window between a fix existing and you applying it is the window you are exposed. "Someone updates things when they notice" is not a schedule.
Backups that have actually been restored. A backup nobody has tested is a hypothesis. The first time you discover the job has been silently failing for five months should not be the day you need it. Restore something, on purpose, on a calendar.
Access that gets removed. Most organisations are diligent about granting access and negligent about revoking it. Contractors who finished last year, staff who changed roles, the shared login three people know. Review it quarterly and the list will surprise you.
People who know what a phishing message looks like. The most effective attacks don't defeat technology. They ask an employee politely, in a message that appears to come from a colleague, at a moment when they are busy. Training that shows real examples beats a policy document nobody opens.
Know what you would actually do
Ask a straightforward question inside your organisation: if a laptop with company data on it were stolen tonight, who would be told, in what order, and what would they do first?
In most companies this produces silence, then improvisation. That is an answer worth having early- because the improvisation happens anyway, only during the incident, badly, and at 11pm.
A workable incident response plan fits on one page. Who to call. What to disconnect. Where the backups are. Who talks to customers. Who talks to the regulator, if you have one. It does not need to be sophisticated. It needs to exist before it is needed.
Assessment is not accusation
Businesses often delay a security assessment because they anticipate being told they have been careless. In practice the finding is nearly always the same: a competent team, sensible decisions, and a handful of gaps that accumulated because the person who understood that system left, or because a temporary configuration became permanent.
Finding those is the whole point. A test that finds nothing has usually not looked hard enough.
Security is not a product you install. It is a set of habits with someone's name against them, and it is considerably cheaper to build those habits on an ordinary Tuesday than during an incident.


