How can you protect your business from the main online threats?
SME cybersecurity starts with a few solid habits. Accounts, updates, backups, phishing and an incident plan: here are the measures to implement in the right order.

A cyberattack is not only aimed at large companies, but also a small structure that has data, bank accounts, messaging, customer files and tools that are essential to its business. For an attacker, a less prepared organization can even represent an easier target.
The good news is that cybersecurity does not start with a collection of expensive solutions. The most effective measures are often known: protecting accounts, keeping software up to date, having recoverable backups, limiting access and learning to recognize fraud attempts.
The aim of this guide is not to promise zero risk. No system can offer it. It is to greatly reduce the probability of an incident, to limit its impact and to allow the company to resume its business more quickly.
1. Identify what is absolutely necessary to continue to function
Before selecting tools, list the items that would not be available to block the company:
- professional messaging;
- client files and contracts;
- Invoicing or cashier software;
- the website and its domain name;
- bank accounts and means of payment;
- cloud platforms;
- access by administrators and providers.
For each element, note who is responsible for it, where the data are, who can access it and how long the company could operate without it. This simple mapping allows you to focus on the risks that directly threaten business continuity.
Also think about invisible dependencies. The site may belong to the company, but the domain is sometimes registered in a former employee's personal account. Backups may exist, but they may be stored on the same server as the data. Mail can be protected, while the recovery address uses an old and unsecured account.
2. Activate Multifactor Authentication
A password can be stolen by phishing, reused after a data leak or recovered by malicious software. Multifactor authentication, called MFA or 2FA, adds a second proof of identity.
Activate it as a priority on:
- messaging;
- Accommodation and administration of the site;
- the domain name registrar;
- cloud services;
- accounting and payments;
- social networks;
- the administrative accounts;
- remote and VPN accesses.
The Centre for Cybersecurity Belgium recommends the MFA for external connections. In 2025, the CCB indicated that only 46.4% of the Belgian organisations surveyed had set up it, while a large part of the incidents observed could have been avoided by this measure.
Prefer an authentication application or a physical key when the service allows. SMS remains preferable to the absence of a second factor, but it is generally less robust. Keep recovery codes in a secure location and document the procedure to follow if a phone is lost.
3. Use unique passwords and a manager
The main danger is not just a password that is too short. It is its reuse. If the same password protects the messaging, a social network and a billing tool, compromise of a single service can open several doors.
A password manager allows you to create and store long and unique passwords. The company must define:
- the authorised tool;
- persons who can access shared safes;
- the procedure for the arrival and departure of an employee;
- the person responsible for emergency access;
- MFA's main account protection.
Avoid sending IDs in e-mails, shared documents or instant conversations. When a provider is required to intervene, create a registered and temporary account if possible instead of sharing the main administrator account.
4. Quickly install updates
Updates often address known vulnerabilities. When a site, extension, router or computer uses an older version, an attacker can exploit an already documented flaw.
Create a minimum inventory: computers, professional phones, servers, routers, cloud applications, CMS, extensions and essential software. Identify a person responsible for tracking. Enable automatic updates when they are reliable and plan regular control for components that require manual intervention.
For a website, check at least:
- version of CMS and its extensions;
- the validity of the HTTPS certificate;
- still active administrator accounts;
- anti-spam forms and mechanisms;
- the dependencies of the code;
- the host's access logs and alerts.
Remove unused extensions and accounts. A component that is disabled but still installed may sometimes remain vulnerable.
5. Prepare really recoverable backups
A backup is useful only if it can be restored. Copying files automatically is not enough if no one checks their integrity or knows the recovery procedure.
The Safeonweb guide for SMEs recommends several copies on separate media, including an off-site copy and an offline copy. This separation is important because ransomware often seeks to encrypt or delete accessible backups as well.
Your strategy must specify:
- what data is saved;
- how often;
- for how long the versions are kept;
- who receives alerts in case of failure;
- where the isolated copy is located;
- how and how often a restoration is tested.
Organize a restoration test at least periodically. Choose a file, mailbox, database or a copy of the site and check that it can be re-established. Document the time required: this will give a realistic estimate of the possible interruption.
6. Learn to recognize phishing
Phishing seeks to push a person to act too quickly: click on a link, open an attachment, communicate a code, change an account number or log on to a false page.
Frequent signals are:
- an unusual emergency;
- a request for confidentiality;
- a sudden change in bank details;
- a slightly different sender address;
- an unexpected document;
- a login page opened from a link;
- a request for MFA code or password.
The most useful rule is to check through a second channel. If a provider requests a bank change, call the usual contact with a previously registered number. If a manager requests an urgent payment, confirm orally. If a platform announces an account problem, open its application directly or enter its known address instead of using the received link.
Annual training is not always enough. Integrate short reminders, share examples received by the company and create a simple way to report a suspicious message without fear of being blamed.
7. Limit Access Rights
Each account with high fees increases the possible impact of compromise. Apply the principle of least privilege: a person must have access to only what is necessary for his or her work.
Some concrete measures:
- separate daily accounts from administrator accounts;
- avoid shared accounts;
- quickly remove access when leaving;
- review permissions every three to six months;
- limit access to backups;
- keep track of providers having access;
- use temporary accounts for ad hoc interventions.
This organization reduces the risk and also facilitates investigations in the event of an incident: it becomes possible to know which account has carried out an action.
8. Secure messaging, domain and site
Email and domain name are two particularly sensitive assets. Email control often allows you to reset other accounts. Domain control can be used to divert the site or emails.
Check that:
- the domain is registered in the name of the company;
- the recovery coordinates are current;
- automatic renewal is active with a valid payment method;
- the Registrar's account uses the MFA;
- DNS records can only be modified by the right people;
- SPF, DKIM and DMARC protections are properly configured for messaging;
- the site is saved independently of its main hosting.
Ask your provider to explain clearly who has every access and how the company will recover its assets if the collaboration stops.
9. Prepare a one-page incident plan
When an incident occurs, improvisation costs time. A short, printed and accessible offline plan is more useful than a very long document that no one knows.
It shall contain:
- persons to be prevented;
- the contact details of the computer provider and the insurer;
- procedure to isolate a device without destroying the evidence;
- Location of backups and recovery codes;
- Critical services to be restored first;
- the applicable notification obligations;
- a method of communication if the mail is no longer working.
In case of suspicion, avoid deleting files or immediately reinstalling a device. Isolate it from the network if it can be done safely and contact a competent person. Keep the messages, hours, captures and information available.
A 30-Day Action Plan
First week
- activate the MFA on messaging and admin accounts;
- inventory essential tools;
- remove unknown or unused accesses;
- check the property of the domain.
Second week
- install priority updates;
- deploy a password manager;
- verify recovery accounts;
- control existing backups.
Third week
- perform a restoration test;
- train the team in anti-phishing checks;
- review access rights;
- secure access for providers.
Fourth week
- draft the incident plan;
- designate the responsible persons;
- test a simple scenario;
- planning quarterly checks.
Conclusion
Cybersecurity is not a project that is completed once and for all. It is a regular discipline comparable to accounting, insurance or maintenance of essential equipment.
Start with measures that block the largest number of attacks: MFA, unique passwords, updates, isolated backups and vigilance against phishing. Then add clear access management and a response plan. A prepared company does not become invulnerable, but it becomes much more difficult to compromise and much more able to recover.