We’re recruiting!
21st August 2025
Windows 10: The curtain call
10th October 2025
Show all

Things for SMEs to think about…

Given recent IT-related breaches and Cyber Security issues, let’s run through some ideas, thoughts and what you can do as an SME to help protect your business.

“It Won’t Happen to Us”

This thinking is null and void. If the likes of JLR and M&S can be impacted — with all their scale, internal teams, outsourcing and big budgets, then so can you. The moment you think “we’re too small to be interesting,” you open yourself to risk. Attackers often see small firms as soft targets (less detection, fewer layers). Be humble, be cautious and plan for the worst.

Know Your Dependencies — And Map Them

What we’re getting at here is knowing and documenting entry points into your systems, and how they are connected to other services. For example, do you have access to your system from a software provider, which means it can access data to pull it out and report on it for you? That’s great, but it’s also a potential weakness. We’re not saying don’t do that, we’re saying proceed with the maximum amount of security and have it documented. Ideally, you want to be able to shut down parts of your systems if they’re impacted by a security issue, leaving you with some functionality while you resolve the problems.

Network Segmentation & Zero Trust Principles

By default, you’re position should be to enforce a least privilege level of access, meaning people start with no access at all, and are given just what they need to perform their duties. This is not to be done the other way around! Where possible, you should segment your network into separate areas or departments. For example, the finance team should be on their own network, which is independent of the production team. This is very easy to implement and provides a decent level of security.

Incident Planning & Rapid Shutdown Capability

You should have a plan in place, which outlines who does what, when they do and how they do it. This allows a process to be calmly followed, when the temptation will be to panic. If you’ve planned out your computer network and systems, you should be able to turn off the affected parts of it, leaving you with a partially functioning business, which is better than not being able to operate at all! Have templates ready to communicate with staff, customers and third parties as needed.

Backup & Recovery Strategy: Going beyond “we have a backup”

Backups shouldn’t be slow to restore. They certainly shouldn’t be corrupted when you come to use them. Your backups should be outside of the live environment and easily accessible when they are called upon. Ideally, you’re testing out the backups every month.

Cyber Insurance

Even as a small business, it’s worth exploring cyber insurance — but read the fine print. Ensure your policies cover incident response, ransom, business interruption, and data breach costs. You need insurance in place directly for your own business: you’re not insured via a third-party provider.

Final thoughts…

Don’t do nothing. Don’t assume anything. Ask questions. Invest in your computer systems. Get your plans in place. Start small, it’s OK. 

If you’d like to discuss any aspect of Cyber Security with us, please contact us at hello@lucidcomputersolutions.co.uk or 01527 908646.

Gavin Moorhouse is the owner of Lucid Computer Solutions, based in Redditch, Worcestershire. They have been helping businesses with Cyber Security since 2008.

Comments are closed.