Most breaches at small and mid-sized companies involve nothing clever. Automated scanners find an unpatched system, a reused password, or a mailbox with no second factor, and the rest follows.
In order of value returned per hour spent:
1. Multi-factor authentication on email
Email is the master key: every password reset in your organisation arrives there. Enable MFA on business email before anything else on this list, starting with finance and the directors. Use an authenticator app rather than SMS where the option exists.
2. Patch on a schedule, not on alarm
Operating systems, CMS installations, plugins, and libraries. A monthly window with a written owner beats reacting to whichever vulnerability made the news. Unpatched plugins are the most common way a Bangladeshi SME website gets compromised, and it is rarely personal — a scanner found a known version number.
3. Configure SPF, DKIM, and DMARC
Without these records, anyone can send email claiming to be your domain, and invoice fraud against your customers becomes trivial. The records take an afternoon to set up correctly. Start DMARC in monitoring mode, read the reports for a month, then enforce.
4. Remove accounts when people leave
Keep a list of every system with logins — email, hosting, CMS, payment gateway, bank portal, social accounts. Work through it on someone’s last day, not the following quarter. Ex-staff accounts are a standing risk that costs nothing to close.
5. Test your restore
Ransomware turns into an outage rather than a catastrophe if, and only if, you can restore. An untested backup is not a control. Restore one twice a year and time it.
What this deliberately leaves out
No penetration test, no security appliance, no monitoring platform. Those have their place once the five above are genuinely in place. Buying them first is paying for a lock while the window is open.
- Security
- Infrastructure