At Pixie Labs, it happens to us all the time: an SME client arrives convinced that “that” won't happen to them, that cyberattacks are something that only happens to banks and multinationals. And the truth is the exact opposite. Today, SMEs are one of attackers' favorite targets, precisely because they usually have fewer defenses set up than a large company, even though they handle equally sensitive data: clients, payments, tax information, and access to entire management systems.
The good news, and we tell this to everyone who consults us, is that you don't need a giant IT department to drastically lower risk. Almost no successful attack exploits something sophisticated: most take advantage of careless habits, little things that keep getting postponed. So we want to share the seven changes that, in our experience, make the biggest difference.
We start with the most obvious and yet most ignored thing: passwords. Reusing the same one across multiple services continues to be, after all these years, one of the most common mistakes we see. The problem is that if a single site suffers a data leak, that password is left exposed to be tried on all the other places where you use it. What we always recommend is a password manager —Bitwarden or 1Password, for example— that generates a unique and long key for each service, so no one has to memorize twenty different combinations.
Along with that, enable two-factor authentication on everything possible. It's a second verification (a code on your phone, a specific app) added to the password, which means that even if someone gets your password, they can't log in without that second factor. We always activate it on corporate email, WordPress, hosting, and any management system or CRM.
Next comes something that is often postponed without thinking about the consequences: keeping everything updated. Plugins, themes, and the WordPress core receive security updates all the time, and leaving them for later is like leaving a door ajar. Many automated attacks specifically target outdated versions with publicly known vulnerabilities. Checking this week after week avoids that blind spot.
Something similar happens with backups. Having them is useless if you never checked that they can actually be restored. We always insist on setting up automatic copies, saved outside the server itself, and testing every now and then that the restoration process works. It is the difference between a bad afternoon and losing the entire business to a ransomware attack.
And it is not all technical: most of the incidents we see do not start with a sophisticated hack, but with an email or a message that tricks someone on the team into clicking or sharing a credential. A brief talk, thirty or forty minutes long, so that everyone recognizes typical signs—artificial urgency, senders almost identical to real ones, weird links—greatly reduces the risk, at almost no cost.
Two other things we usually review with our clients: that each person only has the access they actually need (not everyone needs to be an administrator of everything), and that there is, even if in a brief document, a simple plan for the worst-case scenario: who to notify first, which access to revoke, where to restore the backup from. Thinking about it calmly before something happens saves invaluable hours later.
To see it in action
If you prefer a video summary of several of these points, this is a good complement:
None of these seven points requires a huge investment or advanced technical knowledge. What they do require is consistency, revisiting them from time to time, and not leaving them as an eternal pending task. If you'd like, at Pixie Labs we can help you audit how your site and your systems are doing today, and getting all of this running automatically so it doesn't depend on someone remembering to do it.
