Cyber attacks are not just a problem for large corporations. According to the BSI, over 60% of all ransomware victims in Germany in 2023 were small and medium-sized businesses. The average damage per incident: €200,000.
The good news: basic IT security is not rocket science and is affordable for SMEs. This guide shows you exactly what you need to do.
The Most Common Attack Vectors on SMEs
Phishing and Social Engineering
With over 80% of attacks, phishing is the most common attack method. Employees are tricked by deceptively real emails into entering passwords or opening harmful attachments.
Typical scenario: An email apparently from DHL informs about a package to be delivered. The link leads to a fake login page.
Ransomware
Malware encrypts all data in the network and demands ransom. Without backup this is often existential.
Typical scenario: Employee opens infected email attachment → encryption starts at night → all servers are locked the next morning.
Weak Passwords and Missing MFA
"123456" or "CompanyName2024" are still widespread. Attackers use automated tools that try thousands of password combinations per second.
Unpatched Software
Every known security vulnerability in non-updated software is an open gateway. Attackers have automated scans that search the internet for vulnerable systems.
Insecure Wi-Fi
Open or poorly secured Wi-Fi networks enable man-in-the-middle attacks and network intrusions.
The 10 Most Important Security Measures for SMEs
1. Introduce Multi-Factor Authentication (MFA)
MFA is the most effective single measure against account takeovers. Enable it for:
- Email accounts (Microsoft 365, Google Workspace)
- Cloud services (AWS, Azure, Dropbox)
- VPN access
- Admin access to servers and CMS
Cost: Generally free via authenticator apps. Enterprise MFA solutions from €2/user/month.
2. Regular Backups According to the 3-2-1 Rule
3 copies of your data, on 2 different media, with 1 copy off-site (cloud or external data center).
Important: Regularly test backups for restorability. A backup that cannot be restored is worthless.
Cost: Cloud backup from €20/month for SME sizes.
3. Employee Training
Technology alone is not enough. People are the biggest security risk – and can become the greatest strength.
Train employees regularly on:
- Phishing detection (with simulated phishing tests)
- Password hygiene
- Handling sensitive data
- Reporting obligations for security incidents
4. Patch Management: Keep Software Updated
Define clear processes for updates:
- Operating system: enable automatic updates
- Browsers and office suites: weekly updates
- Servers and critical systems: monthly maintenance windows
- Maintain inventory of all software in use
5. Endpoint Detection and Response (EDR)
Modern virus protection goes beyond classic antivirus software. EDR solutions detect unusual behavior (e.g. ransomware-typical file encryption) and stop attacks in real time.
Recommendations for SMEs: Microsoft Defender for Business, CrowdStrike Falcon Go, Sophos Intercept X
Cost: From €3–8/device/month
6. Network Segmentation
Separate internal systems from each other: office Wi-Fi from the production network, guest Wi-Fi from the internal network, server network from the client network.
This isolates an attack so it cannot spread throughout the entire company.
7. Introduce Password Manager
A password manager enables strong, unique passwords for every service – without having to remember them all.
Recommendations: Bitwarden (open source), 1Password, Keeper
Cost: From €3–5/user/month for business versions
8. Create Incident Response Plan
What to do when it happens? Without a plan, companies lose valuable time in an emergency.
Your plan should include:
- Who is the first contact person for an incident?
- How are systems isolated?
- Who do you need to inform? (GDPR: data protection authority within 72 hours!)
- How do you restore operations?
9. GDPR-Compliant Data Storage
IT security and data protection go hand in hand. Important measures:
- Data protection impact assessment for new tools
- Data processing agreements with cloud providers
- Data minimization: only collect what is necessary
- Deletion concepts for data no longer needed
10. Regular Security Audits
At least once a year you should have your IT security externally reviewed:
- Penetration tests identify open vulnerabilities
- Vulnerability scans for network and web applications
- Review of security policies
Costs and Budget Recommendation
As a rule of thumb, IT experts recommend SMEs to budget 5-10% of the IT budget for security. Typical annual costs:
| Measure | Annual Costs (10 users) |
|---|---|
| EDR solution | €360 – €960 |
| Password manager | €360 – €600 |
| Cloud backup | €240 – €600 |
| MFA solution | €0 – €240 |
| Employee training | €500 – €2,000 |
| **Total** | **approx. €1,500 – €5,000/year** |
Compared to an average damage event (€200,000+), this is a very profitable investment.
What to Do in a Security Incident?
1. Isolate immediately: Disconnect affected devices from the network (pull network cable, disable Wi-Fi)
2. Don't switch off: Forensic evidence can be lost
3. Contact IT emergency: Bring in an external specialist
4. Inform authorities: BSI can advise, data protection authority must be informed about data loss
5. Document: Record every measure
Conclusion
IT security is not a luxury but an obligation for every business. The most important insight: almost all successful cyber attacks could have been prevented with basic measures.
Softwara supports SMEs in implementing IT security measures – from needs analysis to technical implementation. [Contact us](/kontakt) for a free initial consultation.