Most small business owners we speak with assume cybersecurity is a complicated, vendor-driven topic best left to whoever currently holds the contract. It's not. The baseline that protects a thirty-person business from the realistic threats they will face is narrow and well understood. It comes down to whether the controls are actually in place and tested. What we tend to find during independent assessments is rarely a missing exotic tool. It's one or two of the basics quietly absent, with no one inside the business positioned to notice.
Why small businesses are the target
The assumption that attackers are focused on enterprises is one of the more durable myths in this space. The economics of modern attacks favor volume. Phishing kits, credential-stuffing lists, ransomware-as-a-service, and initial-access brokers are all priced for scale, and small businesses sit in the soft middle: enough valuable data to be worth a few hours of an attacker's time, rarely enough security investment to make those hours unprofitable. The numbers bear this out: in Verizon's 2025 data, ransomware showed up in 88% of small-business breaches1, against roughly 39% at large companies. The threat isn't that a nation-state has decided to focus on a regional accounting firm. It's that the regional accounting firm is one of ten thousand mailboxes a credential stuffer ran through yesterday.
The recovery cost is what makes this category disproportionate. A serious incident at a small business is rarely the headline number you see in industry reports. It's downtime, lost client trust, the cost of forensic work, and the months of leadership attention that should have been spent running the business. The average breach now takes 241 days to identify and contain2, and 86% of organizations report real operational disruption, from delayed sales to lost customers. Most owners don't budget for that scenario because it sits outside the operating P&L until it doesn't.
The seven controls that carry most of the weight
None of this is groundbreaking. But in our experience, these are the controls that decide how most businesses under $30M in revenue actually hold up. If your provider has these set up correctly and actually tested, you're doing better than most.
1. Multi-factor authentication on everything that matters
Stolen passwords are still one of the most common ways attackers get in, and multi-factor authentication neutralizes most of what they can do with them. Microsoft has found it blocks over 99% of account-compromise attacks3. Coverage is what separates a useful MFA program from a checkbox. Email accounts are the priority because email is what attackers use to pivot. Beyond that, MFA needs to be enforced on remote access, banking and financial systems, administrator accounts in any business application, and anywhere customer data lives. Partial coverage isn't coverage. If MFA is on email but off the VPN, the VPN is the way in.
2. Backup and recovery that has been tested
Automated daily backups, stored both on-site and off-site, are the floor. The ceiling is whether anyone has actually restored from them in the last quarter. Ransomware events are where untested backups fail loudly, and recovery is expensive even when it works: Sophos puts the average ransomware recovery, before any ransom, at $1.53 million4. The more common scenario, though, is a corrupted database or a deleted folder where the restore turns out to take two days instead of two hours because the runbook was never written. The question that surfaces this quickly is straightforward: when was the last successful restore test, and how long did it take from request to working data.
3. Email security beyond spam filtering
Email is still one of the most common ways attacks reach small businesses. Basic spam filtering catches the obvious, but phishing and business email compromise look enough like legitimate mail to make it through. A serious email security layer adds attachment sandboxing, link rewriting that checks URLs at click time, and impersonation protection that flags messages spoofing executive senders. The single highest-leverage configuration here is impersonation protection on senior leadership, which is where the meaningful wire-transfer fraud attempts land. The FBI's complaint center logged over $3 billion in business email compromise losses5 in 2025 alone.
4. Modern endpoint protection
Traditional antivirus has been inadequate for years. The current standard is endpoint detection and response, which watches process behavior on the device and can isolate a machine when it starts doing something that looks like ransomware, which now figures in 48% of breaches6. The details that matter are centralized monitoring (so the provider sees alerts in real time), automatic updates, and explicit ransomware rollback capability. A capable provider can name the exact product and tell you the last time it caught something in your environment.
5. A business-grade firewall, configured and patched
The firewall built into a consumer-grade internet modem isn't security infrastructure. A business firewall, kept current with firmware updates, with logging enabled and remote access locked down to specific identities, is. The configuration matters more than the brand. We've seen expensive firewalls deployed with default credentials and management interfaces exposed to the public internet, which is worse than not having one at all because it creates the illusion of protection.
6. Patch management that actually runs
A growing share of breaches start with a known vulnerability that was never patched. In Verizon's 2026 report it became the single most common way breaches begin6, passing stolen passwords for the first time in the nineteen years they've tracked it. Patch management is the least interesting item on this list and the one most often quietly broken. A healthy program covers operating systems, business applications, browsers, and server software. It runs on a documented cadence and produces a monthly report showing what was patched and what was deferred. If your provider can't show you a recent patch report, the program isn't running the way it should be.
7. Security awareness training for the team
People are the layer that catches what the tools miss. The goal isn't turning every employee into a security professional. It's teaching them to recognize the bait, like the wire request that lands from "the CEO" at 4:55 on a Friday, and to know who to call when something looks off. Quarterly short-format training combined with periodic phishing simulations is the format we see produce real behavior change. Annual hour-long videos are a compliance checkbox.
Where tools stop and operations begin
The controls above are necessary, but they aren't sufficient on their own. The difference between a business that recovers from an incident in hours and one that recovers in weeks is usually not the tooling. It's whether someone is actually watching the alerts those tools throw off and responding when they fire. A managed detection and response capability, even a modest one, is what turns a stack of products into security operations.
A reasonable cadence is monthly reporting on incidents detected and resolved, quarterly reviews of the configuration of each control, and an annual conversation about whether the baseline still fits the business. Our year-end provider review guide walks through what that conversation should produce.
Where the baseline stops being enough
The seven controls above cover most small businesses well. Two situations push past them.
- Businesses with significant remote work need a VPN with identity-aware access, mobile device management for any device that touches company data, and a documented policy for personal devices.
- Businesses in regulated industries like healthcare or financial services need encryption at rest and in transit, formal access controls with audit logging, and compliance documentation that can stand up to an external review.
The framework name matters less than whether the artifacts exist when an auditor or insurer asks for them.
Five questions to ask your IT provider this week
These are the questions that surface gaps fastest. The answers should be specific. Vague reassurance ("you're fully protected") is itself the signal worth paying attention to.
- Is MFA enforced on every email account in our organization, including shared and service accounts?
- When was the last successful restore test, and how long did it take from request to working data?
- What endpoint detection and response product are we running, and when did it last contain a real threat in our environment?
- Can you send me the last monthly patch report, including what was deferred and why?
- Do we have a written incident response plan, and who is the named decision-maker on our side if something happens at 2 a.m.?
If those answers come back hesitant or marketing-flavored, the most useful next step is an independent read. Our guide to the patterns that signal a failing provider relationship covers what to do when the answers aren't what they should be.
What this should cost
Most of the baseline above should be included in a managed services agreement at a reasonable price point. The honest version of the cost conversation is that endpoint protection, email security, patch management, and backup are commodity layers any competent provider includes. Awareness training and managed detection and response are sometimes priced separately, depending on coverage and response SLAs. What managed IT services should actually cost covers the broader pricing landscape.
The way to think about the budget is simple. A year of a competent security baseline costs a fraction of what a single serious incident does. IBM puts the global average breach at $4.44 million2. The businesses that resist the spend are almost always the ones that learn this the expensive way.
Want a structured read on your current security posture?
The MSP Performance Scorecard includes a security section that walks through the controls above and surfaces where the gaps are. It takes about ten minutes and produces a written summary you can take into your next provider conversation.
Take the ScorecardSources
- Verizon, 2025 Data Breach Investigations Report (small-business findings).
- IBM, Cost of a Data Breach Report 2025.
- Microsoft, on multi-factor authentication effectiveness.
- Sophos, The State of Ransomware 2025.
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report.
- Verizon, 2026 Data Breach Investigations Report.