Assume breach: identity-first security that survives a bad day
The controls that stop most real incidents — strong identity, fast patching, tested backups, and a plan for the day something gets through.
7 min readIdentity is the new perimeter
Most incidents that reach small organisations start with a stolen or reused credential, not a exotic exploit. Phishing-resistant multi-factor authentication on email, finance, and admin accounts removes the cheapest way in.
Give people only the access their role needs, review it on a schedule, and remove it the day someone leaves. A password manager for unique credentials is the lowest-effort, highest-return control you can roll out this week.
Close the doors attackers walk through
Keep operating systems, browsers, and business apps on automatic updates, and track the handful of internet-facing services you run. Unpatched, exposed software is how opportunistic ransomware finds a target.
Teach the team to pause on urgency: an unexpected message that asks you to log in, pay, or move data is a signal to verify through a known channel, not to click.
Practise the recovery, not just the backup
Keep at least one backup that an attacker on your network cannot reach or encrypt, and restore a file from it on a schedule so you know it works.
Write the incident plan before you need it: who is called, who can isolate a device, who talks to customers, and where the evidence goes. A rehearsed hour saves a ruined week.