In-Depth

Small Businesses Have a Cybersecurity Advantage

Yes -- really. The prevailing wisdom is that enterprises have the resources and technology expertise to build cybersecurity resilience, whereas small businesses are stuck on the wrong side of the cyber security poverty line. In this article, I'll challenge that idea and present a view where SMBs that take cybersecurity seriously can have an edge over bigger organizations.

In my 30 years+ in the IT industry, I worked in both large enterprises (50,000+) and SMBs, and I've also served businesses with 2 to 350 staff as an MSP and MSSP for the last 28 years, so I'll bring the perspective from both worlds.

Cybersecurity Advantages of Being an SMB
The first benefit is agility -- SMBs can make changes quickly. If you're rolling out passkeys / MFA in an enterprise, there are committees, project planning, training sessions, union negotiations and eventually, after many months, the project is started. But given the size of the user cohort, it'll take several more months before it's done. In an SMB, the owner or CEO can be convinced in an afternoon, a test with a few users can be rolled out the next day, and the full user population can be onboarded in a week.

If your business has legacy applications that are business-critical and running on an unsupported version of Windows Server, you may need to plan a large migration project or develop other mitigation plans. In SMBs, the server can be migrated to public cloud in a week or two, or an alternative SaaS or more modern platform can be evaluated in weeks or months and migrations completed in a weekend. Agility is a secret weapon of SMBs, which they often take for granted until they compare with the bureaucratic, glacial pace of most enterprises.

The same goes for swapping a technology platform or service. If a SaaS app isn't working for an SMB, migration and staff training can be measured in weeks or months, whereas large businesses live with year-long projects.

And the most challenging migration for most (non-startup) businesses over the last 10+ years -- on-premises to cloud -- is something that most enterprises realistically will never complete. All of my SMB clients are now completely in the cloud, with no on-premises server infrastructure. In some cases, this took a few months of planning, migration and cleanup; in others, it went faster.

Another huge advantage of smaller teams is speed of communication. Making sure everyone in a large org is on the same page for a new IT initiative is a project for the communications team, spanning weeks of email and Teams messaging campaigns, whereas a 15-minute meeting and training session at the "all hands" meeting works for SMBs.

Operational Security Benefits of Being an SMB
In daily operations there are more benefits for cyber resiliency to be had as well -- take credential resets. Many enterprises rely on outsourced help desk services, where there's no relationship between the person in the call center trying to establish whether the caller really is "John the IT admin" who has just had his laptop and phone stolen, or an imposter. Just ask Jaguar Land Rover or any number of other enterprises that have had their entire systems compromised by a young criminal with exceptional social engineering and open-source research skills.

In most small businesses, everyone knows everyone else, and even if you use an MSP for day-to-day IT support, their technicians should know most people (obviously this will be different for a five-person company compared with a 500-person company). And while the risk of AI voice (and even video) cloning is real and there have been some spectacular stories where these have been used, no one is going through that work to compromise a 10-person SMB (at least not yet). You can even add another layer of resiliency to an SMB by having a shared passphrase that only staff and MSP techs know. "Oh, hello, you're calling from IT to help me with my issue -- sure, just tell me the passphrase and I'll let you connect to my PC."

SMBs also have an advantage when building cyber security culture. If, for example, an accountancy firm owner takes security seriously, demonstrates that commitment to staff and adds regular awareness training, everyone quickly understands their role. Trying to implement a similar "this is how important this is" attitude across huge user populations is challenging, as evidenced by breaches in the news that often start with a trivial human error that should have been caught. The same goes for understanding new threats. Regular updates on new risks such as QR code phishing, voice phishing (vishing) and device code flow attacks can be disseminated quickly, whereas enterprises stuck in "once a year, tick the box" training can't keep everyone up to date in this fast-changing landscape.

Another potential benefit is scale -- let me show you what I mean. I receive alerts when a client staff member adds a new device for MFA, when an Entra Conditional Access policy is added or changed, or when a new application is added to Entra ID. This is a manageable volume of alerts for me, and if I see that a user has added a new phone for MFA, I can follow up with them. In most cases, this happens with me on the phone anyway, guiding them through the process, but if it happens outside of that, it gives me a chance to catch a potential compromise where the attacker is adding their own device for MFA.

I should be the only one adding or editing CA policies, so any alerts outside of my actions are suspicious. In most of my clients' environments, users don't have permission to add apps to Entra; I have to approve them.

This would be unworkable in a large environment where the sheer scale of users adding devices or scores of administrators changing CA policies require investigation of every suspicious change.

Finally, for some regulatory requirements, the ability for a small business which needs to adhere to a specific framework (GDPR, HIPAA or CMMC for example) to work through a set of controls can be manageable with a simpler technology stack and a smaller set of users. Don't get me wrong; many smaller organizations struggle with this kind of compliance, but the overall scale or amount of work is often a lot less than a large enterprise needs to complete.

Challenges for SMBs in Cybersecurity
Of course, it's not all unicorns and rainbows; there are many challenges for SMBs as well. The first hurdle is taking the risk seriously and breaking the "we're too small to be a target" mentality. Yes, you're probably not big enough to be a target of the alpha predator ransomware crews, but there are many second- or third-tier players who don't make the news but will still take your money if you let them. If your business has a turnover, you're a target.

Second, you need to understand enough about the changing cybersecurity landscape to weigh the risks involved. This isn't magic. If you're a business owner, you do this for other risks -- hiring staff, training, insurance, payroll, tax commitments, etc. Just because a risk hasn't actualized for your business yet doesn't mean it doesn't exist. 10 years ago, it was the same for backup -- "Why do I need to pay for a backup system?" quickly turns into "Where do I sign?" when the business is down for two days and data is lost. Today that conversation should be about cyber security resiliency. Please don't wait until a large breach takes down your operation. And if you don't have any idea where to start, talk to your IT Managed Service Provider (MSP); they will either offer services to help you or point you to a Managed Security Services Provider (MSSP). If you don't use either of those and don't have a competent in-house IT team, start by finding an MSP to help you manage your digital estate.

Third, you must allocate enough resources to the problem, just like you do with any other risk in your business. If your warehouse burns down with all your stock, you'll go out of business, so you manage the risk with smoke detectors, sprinkler systems and fire extinguishers, staff training and insurance. The same thing applies to cybersecurity.

Basic Cybersecurity for SMBs
Every business is different: The type of data you store varies, and the country and laws that apply are diverse. Please look at this list as a starting point for a discussion with your MSP:

  • If you have an office, use a business-class firewall that's kept up to date, not a consumer-grade device.
  • Wherever possible, use cloud services for identity, collaboration (M365 or Google Workspace) and any line-of-business applications.
  • Remove on-premises infrastructure wherever possible; securing cloud systems is easier than securing legacy servers.
  • Take identity seriously; it's the foundation for modern security. Move to phishing-resistant authentication (passkeys, hardware keys, Windows Hello for Business, macOS platform credentials) as quickly as possible for all users.
  • Keep operating systems, browsers and applications up to date with patches, preferably through automation. AI's ability to discover vulnerabilities at a huge scale compared with human researchers means the patch window has collapsed, so keeping up to date is vital.
  • Combine a strong eXtended Detection and Response (XDR) platform with comprehensive log monitoring. Most SMBs that are compromised have no idea until it's too late, either because they have no monitoring in place or because no one was watching the alerts as they came in.
  • Use external partners where appropriate; MSPs, MSSPs and even Managed Detection and Response (MDR) providers have their place in the right situation for SMBs.
  • Build a strong cyber security culture in your business; lead by example and take the risk seriously.
  • Standardize your technology platforms as much as possible. Don't have 10 different makes and models of laptops, and avoid Bring Your Own Device (BYOD, sometimes called Bring Your Own Disaster) wherever possible. You don't want personal smartphones, tablets or laptops interacting with your sensitive data.
  • Realize that this is a never-ending journey; you'll never arrive at a "secure" state, you're just aiming to be more resilient today than yesterday.

Conclusion
That list could be a lot longer, but it's a good starting point. Any SMB that takes security seriously, allocates appropriate resources and enlists a strong technology partner can achieve a security posture that would be the envy of most enterprises.

Think I got it wrong? Hit me up on Bluesky or here.

About the Author

Paul Schnackenburg has been working in IT for nearly 30 years and has been teaching for over 20 years. He runs Expert IT Solutions, an IT consultancy in Australia. Paul focuses on cloud technologies such as Azure and Microsoft 365 and how to secure IT, whether in the cloud or on-premises. He's a frequent speaker at conferences and writes for several sites, including virtualizationreview.com. Find him at @paulschnack on Twitter or on his blog at TellITasITis.com.au.

Featured

Subscribe on YouTube