Small businesses face the same threats as enterprises, without the budget, without the specialized knowledge, and without the time. The problem: according to Mastercard's 2025 SME Cybersecurity Report, 46% of small businesses have experienced a cyberattack, and of those attacked, 18% ended up filing for bankruptcy. So what can they do to try and mitigate some of this risk?
Below is a plan of action that could be followed, but always know that despite having strong security controls in place, attackers can still find a way into systems. No control is perfect, which is why cyber insurance is the final step in the plan, and if you can prove you have strong controls you may get a better deal from your insurers.
Don't just take our word for it: the FCC provides its own guidance for small businesses as well, so make sure you have a plan in place.
Step 1: Understand what you have to protect
Understanding that you face cybersecurity risk, even as a small business, is critically important. The amount of risk you face depends on a few things, including the few most important to consider below:
- What kind of customer data do you handle? (Are you managing credit card data, PII, or other sensitive data). Does your company work in a regulated environment where there are data handling expectations? For example, financial businesses or healthcare businesses.
- Get visibility into you what devices you own and should be protecting. What is the internet "surface area" of your business? For example, are you a majority-online business, or do you have a physical plant? Do you allow employees to work remotely? While online businesses with cloud deployments have more internet surface area to cover, physical businesses will need to protect their devices and email to ensure their security hygiene is good enough to prevent a possible attack.
Step 2: Understand your most likely risk types
As a small business, phishing is your #1 risk as it can kick off the chain of events that leads to data exposure, ransomware, and data theft once an attacker gets access to your systems. The key ones for a small business to focus on are below:
- Phishing
- Weak passwords
- Unpatched software
- Third party vendors
- Malware/Ransomware
- Physical theft
- Employee errors
Step 3: Plan out how you can reduce risks with proper controls
| Controls reducing risk | Risk(s) reduced |
|---|---|
| Leverage an email security tool | Phishing |
| Train users on the security risks they may face | Phishing, passwords, malware |
| Encourage users to leverage password managers and passkeys | Weak passwords |
| Ensure all users leverage MFA (enforcement should be a priority here) | Phishing, weak passwords |
| Leverage a patch management tool | Unpatched software |
| Develop a third party management and review plan that checks how third party vendors treat their own security | Third party vendors |
| Use an antivirus tool company-wide | Malware/Ransomware |
| Ensure you use device management software (MDM), especially useful to wipe devices if one gets lost | Unpatched software, physical theft |
| Backup your critical data | Ransomware (reduces the impact), employee errors |
Step 4: Implement your controls, starting with your priorities
Based on your risks and the data you're protecting, decide which controls need to be implemented right away and which can be phased in over time. If you're not sure where to start, MFA enforcement and backups give you the most protection for the least cost and effort. Email security and patch management are good next steps since they cut off the most common ways attackers get in. Controls like third party vendor reviews can be phased in once the basics are covered.
Step 5: Consider cyber insurance
Many insurance providers require proof of controls in place before they are willing to underwrite your risk profile. Once you have the controls in place you'll likely need to provide evidence, even just screenshots, before they'll give you a quote. Cyber insurance can help your company stay afloat in the event your in-place controls don't capture an advanced threat and you still suffer from data loss or exposure.
Where Blue Lantern Security can help
Blue Lantern Security provides tooling at bluelanternsecurity.io to help implement controls and attest that your controls are in place when discussing getting coverage with an insurance provider. Blue Lantern Security can:
- Prevent phishing attacks through its Gmail and Outlook integrations
- Help users understand what is risky about websites they visit or mail they receive that gets through native filters
- Check that users are leveraging MFA
- Provide visibility into device security posture
- Check that backups are being leveraged for your company data
All this from one centralized console giving you a view into your company's risk with minimal setup and configuration.