As responsible within an SME organisation, it is tempting to leave IT and security entirely to external parties. But without direction – Without grip – There are blind spots. That's where it goes wrong. Incidents with suppliers, human errors or unnoticed vulnerabilities in your systems can lead to enormous damage. While you may think or assume that the supplier has taken care of it all.
The heroic act is not in stopping all attacks, that is a utopia. It's in the choice to proactively protect what's important. To put your processes in order, raise awareness, and create a culture in which information security is as self-evident as fire safety and a safe workplace.
What's a cyber attack?
A cyber attack is any attempt to disrupt, steal or abuse systems, data or processes. For SMEs, the most common cyber attacks are:
- Phishing & social engineering: employees are misled to give up data or perform actions.
- Ransomware: files are encrypted and only released after payment of ransom.
- DDoS attacks: Systems or websites shall be temporarily made unreachable.
- Vulnerability exploit: misuse of software errors or wrong configurations.
- Business Email Compromise (BEC): criminals pose as directors or suppliers and send false payment instructions.
Why SMEs are an attractive target
- Limited resources: usually not a large security team or SOC.
- Chain Dependency: SMEs are often suppliers; an attractive springboard to harm industrial companies.
- Human factor: less (structural) training, so higher chance of error.
Steps to prevent a cyber attack
1) Map your crown jewels
Inventory which systems, processes and data are crucial. Think of customer and personnel data, financial administration, production and logistics systems, IP (designs, recipes) and cloud environments.
2) Perform a risk analysis
Decide based on risks, not on feeling. Reply among others:
- Where are sensitive data and who has access?
- His backups Insulated And tested for recovery?
- Are all business critical systems and SaaS accounts equipped with MFA?
- What known vulnerabilities (CVES) affect our tech landscape?
Start with baseline assessment / gap analysis
3) Make sure the basic security is in order
- Strong passwords + MFA: mandatory for email, management accounts and external access.
- Patch Management: updates for OS, applications, firmware and SaaS plugins.
- Network segmentation: separate office, production and host networks; Restrict lateral movement.
- Backups: 3-2-1 line (3 copies, 2 media, 1 off-site/immutable) and periodic recovery testing.
- Least privilege: minimum rights, temporary admin where necessary.
- Secure email: SPF, DKIM, DMARC and anti-phishing policies.
4) Train and involve employees
Make employees your strongest defense:
- Regular security awareness sessions and micro-learnings.
- Phishing simulations with feedback and low-threshold reporting button.
- Clear procedures: How do you recognize an incident and where do you report this?
- Four-way principle for payments and changes to payment data.
5) Set up an incident response plan
Not if, but when It happens: who does what?
- Roles & responsibilities: crisis team, decision-making power, external partners.
- Reporting & communication: Report to supervisors/customers in a timely manner, consistent external communication.
- Technical steps: Isolate, forensically secure, recover from clean backups.
- Practice: tabletop or live exercise at least 1× per year.
6) Limit dependency on suppliers
- Establish security requirements in contracts/SLAs (patching, monitoring, response times).
- Ask for reports (e.g. SOC2/ISO 27001) or review rights.
- Define exit and recovery arrangements (data portability, RTO/RPO).
- Remain the owner of critical accounts and domains.
7) Invest in monitoring and detection
- Activate logging (e.g. M365/Azure AD sign-ins, audit logs) and keep for a sufficient period.
- Use EDR/XDR for endpoints and servers.
- Consider an SME-oriented SOC/SIM service.
- Respond to anomalies (inlogging in from unusual country, massive MFA prompts, suspicious mailbox rules).
Practical examples from the field
Phishing in a commercial enterprise
An employee clicked on a link and entered login data on a false page. The mailbox was abused as a springboard to send false invoices on behalf of the invoices mailbox.
Lesson: Obligatory MSA, training awareness and monitoring mailbox rules.
Ransomware at a logistics company
Planning and warehouse processes were shut down for days. Back-ups were present but not recently tested and functioned only halfway.
Lesson: immutable backups, regular recovery practice, segmentation to limit failure.
Business Email Compromise (BEC)
Criminals imitated a supplier and sent an urgent payment order with a new account number for an order. The finance officer followed the instruction. The money was gone.
Lesson: four-way principle and call control for changes in payment data or IBAN.
Checklist: Preventing cyber attacks
- Map of crown jewelry
- Risk analysis performed and prioritized
- Basic measures in order (MFA, patches, segmentation, back-ups)
- Security awareness and phishing simulations active
- Incident Response Plan drawn up and practiced
- Suppliers' agreements agreed and tested
- Monitoring, logging and EDR/XDR
From "S' regulation to a culture of safety
Cybersecurity is not a one-time project. It is a continuous improvement approach that your organisation must carry widely. Board members prioritize, release resources and show that digital security is as obvious as occupational health and fire safety.
By investing in knowledge, behaviour and processes you build a culture in which working safely is normal – And where an incident doesn't have to be a devastating blow.
Cyber attacks are not a far-off bed show for SMEs. Limited resources and chain dependence increase risk, but targeted measures can avoid a lot of misery. Take direction: chart risks, engage people, secure processes and improve continuously.


