Start With Identity: Strong Sign-In and MFA
Most business systems now live behind a login page that anyone on the internet can reach: email, file storage, accounting, HR and banking portals. That makes user accounts the front door, and a stolen or guessed password the simplest way in.
Multi-factor authentication (MFA) adds a second proof of identity, such as an authenticator app prompt, on top of the password. If a password is stolen, the attacker still cannot sign in without the second factor. Turning on MFA for email and every other service that supports it is one of the most effective steps a business can take.
- Enable MFA for all users, starting with administrators, directors and finance staff
- Prefer an authenticator app or hardware key over SMS codes where possible
- Use a password manager so staff can have long, unique passwords for each service
- Disable accounts promptly when someone leaves, and review the user list regularly
- Block legacy sign-in methods that bypass MFA where your platform allows it
Keep Systems Patched and Supported
Software vendors release updates to fix security weaknesses. Once a fix is published, the weakness is public knowledge, and unpatched systems become easy targets. Patching is unglamorous, but it closes doors that attackers actively look for.
Cover everything, not only Windows: operating systems, browsers, office applications, servers, firewalls, Wi-Fi access points, network switches, CCTV recorders and any other device with firmware. Set a regular patching schedule, apply critical security updates sooner, and keep a record of what has been done.
Pay particular attention to software and hardware that the vendor no longer supports. Once updates stop, new weaknesses are never fixed. Plan to replace or isolate these systems rather than leaving them connected indefinitely.
Backups You Have Actually Tested
Backups are the last line of defence against ransomware, accidental deletion, hardware failure and fire. When everything else has failed, a working backup is what gets the business running again.
A widely used guideline is the 3-2-1 idea: keep at least three copies of important data, on two different types of storage, with one copy held off-site or in the cloud. The point is that no single event, whether a failed disk, a stolen server or an attack that encrypts the network, should be able to destroy every copy.
- Identify what actually needs backing up, including cloud services such as email and shared files, which are not automatically protected against every kind of loss
- Keep at least one copy that ransomware on the network cannot reach or alter
- Monitor backup jobs so failures are noticed the same day, not months later
- Test restores on a schedule. A backup that has never been restored is an assumption, not a safeguard
For help designing this, see our backup and data protection service.
Email and Phishing: A Common Way In
A great many security incidents begin with an email: a fake invoice, a message that appears to come from a director asking for an urgent transfer, a link to a login page that looks genuine, or a request to change a supplier's bank details. These attacks target people rather than technology, which is why they work.
Defence has two sides. On the technical side, use email filtering that scans links and attachments, configure your domain's sender authentication records (SPF, DKIM and DMARC) so others cannot easily impersonate you, and flag external emails clearly. Dedicated anti-phishing protection adds further checks.
On the process side, agree a simple rule for finance: any request to change bank details or make an unusual payment is verified by phone using a number you already hold, never one given in the email. That single habit prevents a large class of fraud.
Endpoints, Firewall and Network Basics
Every laptop, desktop and server should run reputable, centrally managed endpoint security, so that someone can see when protection is out of date or a threat has been detected. Turn on disk encryption for laptops, since devices are lost and stolen, and require a screen lock.
At the network edge, a business-grade firewall should sit between the office and the internet, with its security features switched on, its firmware current and its rules reviewed. Remote access should go through a VPN or other secured method with MFA, never through remote desktop exposed directly to the internet.
- Separate guest Wi-Fi from the office network
- Place CCTV, attendance devices and other smart equipment on their own network segment
- Change default passwords on routers, recorders, printers and access points
- Close any port forwarding that nobody can explain
Least Privilege and User Awareness
Least privilege means giving each person only the access they need for their role. Staff should not work day to day with administrator rights on their computers. Shared folders should be restricted by department. Administrator accounts should be separate from everyday accounts, few in number and protected with MFA. When a breach does occur, limited access limits the damage.
Technology cannot do everything, so staff awareness matters too. It does not need to be elaborate. Short, regular reminders work better than a long annual session: how to spot a suspicious email, why passwords are never shared, what to do with a found USB drive, and above all who to tell if something seems wrong.
Have an Incident Plan Before You Need One
Even well-protected businesses have incidents. What separates a bad day from a disaster is whether people know what to do. An incident plan for a small business can fit on two pages:
- Who decides, and who is called first: internal contacts, your IT provider, and their out-of-hours numbers
- Immediate steps: disconnect affected devices from the network, do not wipe anything, preserve evidence
- How to reset passwords and revoke sessions for compromised accounts
- Where the backups are and who can restore them
- Who needs to be informed: management, the bank, affected clients, insurers and any relevant authorities
- A short review afterwards to fix the root cause
Keep a printed copy, because the plan is of little use if it is stored only on the system that has just been encrypted. Businesses should also be aware of UAE data protection requirements that may apply to the personal data they hold, and take advice where needed.
If maintaining all of this in-house is unrealistic, it can be delivered as part of cybersecurity services or built into a managed IT service, so the routines are carried out and reported on by a dedicated team.
