You don't need a corporate budget to be well protected. You need a handful of basic measures, applied properly, and one simple rule: prevent, detect and recover.
Most small and medium businesses do not fall to sophisticated attacks but to ordinary things: a reused password, a phishing email opened in a hurry, a system left unpatched, or a backup nobody knew had stopped working. The good news is that those same ordinary things can be fixed without big investment — through a structured, disciplined approach.
This article is a practical, checklist-style guide. If you first want the conceptual picture — what information security actually is and where to start — we cover that separately in information security: what it is and where to start. Here we go straight to the measures that build your business resilience.
Before any tool, it helps to know what you are defending. Information security comes down to three properties, known as the CIA triad:
Every security measure ultimately serves one or more of these three properties. When you assess a risk, the useful question is: "what would happen if this information were seen by the wrong people, were modified, or became unavailable?" The answer shows you where to invest first.
Not all security measures have the same effort-to-effect ratio. For an SME, the following few reduce risk the most, at the lowest cost:
Notice that most of these measures are about process and discipline, not expensive technology. That is the good news for an SME.
One of the most costly misunderstandings is to treat security as a purely technical problem left to IT. In reality, information security covers three dimensions: people, processes and technology. A flawlessly configured firewall does not help if an employee emails a password to an attacker posing as the company director.
The human dimension is often the most vulnerable and, at the same time, the cheapest to strengthen. This is where training, clear onboarding and offboarding procedures, and a culture in which reporting a mistake is encouraged rather than punished all come in — because an incident reported quickly does far less damage than one that is hidden. We wrote at length about the people side in our article on human resource security in ISO 27001.
Information security is not just good practice but also a legal obligation. Art. 32 GDPR requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk — and it explicitly mentions the confidentiality, integrity, availability and resilience of systems, as well as the ability to restore access to data after an incident. In other words, the GDPR requires exactly the resilience we are discussing here.
The key word is "appropriate": the law does not impose a fixed list of tools, but measures proportionate to the risk. A small business does not need the same infrastructure as a bank; it needs to show that it assessed the risks and took reasonable measures against them.
This is where ISO/IEC 27001 comes in, the international standard for an information security management system (ISMS). It does not tell you which button to press; it gives you a framework: you identify risks, choose proportionate measures, document them, apply them and review them regularly. In effect, it turns security from a set of isolated actions into a continuous, demonstrable process — exactly what you need to show a partner or the authority that your measures really are "appropriate".
Many people reduce security to prevention: ever higher walls so no one gets in. But no wall is perfect, and real resilience rests on three legs:
An honest check of the three pillars usually shows where you are out of balance. Many organisations invest heavily in prevention and almost nothing in detection and recovery — then are surprised at how hard they recover from an incident they "should have prevented".
If you were to do just one thing this week, enable MFA everywhere you can and check whether your last backup actually restores. Then work through the list above, one item at a time, and note where you are and are not covered. You don't have to do everything at once; you have to do it in order of risk.
An audit or risk assessment carried out by an external partner shortens this path considerably: it spots the weak points before they become breaches and gives you a priority order proportionate to your real risk, not to a generic model. For what such a check looks like, see our audits and testing page.
Resilience is the organisation's ability to keep operating despite an incident — an attack, human error or a technical failure. It is not only about preventing problems, but also about detecting them quickly and recovering from them with minimal loss. In practice, resilience rests on three pillars: prevention, detection and recovery.
The ones that move the needle most, without big budgets: access control on the least-privilege principle and two-step authentication (MFA); keeping systems up to date (patching); backups verified through test restores; phishing awareness across the team; a written and rehearsed incident response plan; and checking the risk introduced by suppliers. These are cheap to implement but significantly reduce both the likelihood and the impact of an incident.
No. IT is one component, but information security also covers people, processes and documents — on paper, in conversations or in files. Many incidents do not start from a technical vulnerability but from a phishing email, an access left open or a missing procedure. That is why security is a management responsibility, not just a task for the IT department.
ISO/IEC 27001 is an international standard that provides a framework for an information security management system (ISMS): you identify risks, choose proportionate measures, document them and review them regularly. It is not a legal requirement, but it turns security from a set of isolated actions into a continuous, demonstrable process — useful both for the requirements of GDPR Art. 32 and for the trust of your partners.
We assess your level of security, check prevention, detection and recovery, and tell you clearly what to strengthen first — in concrete steps proportionate to your business risk.