Don't Overlook These 5 Cyber risk management best practices

Think your small business is too small to be a target? After 26 years in security, I see why small firms are prime prey. Here are 5 practical ways to protect.
The Myth of the Invisible Small Firm
I started helping small professional service firms with their technology and security back in 1999. Back then, we were mostly worried about the 'Melissa' virus or a server hard drive occasionally failing. The world has changed more in the last 26 years than I ever could have imagined. Today, on July 19, 2026, we aren't just dealing with random 'script kiddies' or teenagers looking for a thrill. We are up against organized, AI-powered criminal enterprises that treat your small firm like a branch office they haven't looted yet.
One of the most dangerous things I still hear business owners say is: 'Kevin, why would they target me? I only have 12 employees. I’m invisible.'
I’m here to tell you that being a small firm doesn't make you invisible. It makes you a 'soft target.' Criminals know that a law firm with 15 people or an accounting practice with 25 employees often has fewer safeguards, limited monitoring, and employees who have never been shown what to watch for. According to the Verizon 2025 Data Breach Investigations Report, small businesses experienced approximately four times more confirmed breaches than large organizations last year. Even worse, 88% of those SMB breaches included a ransomware component.
Cybersecurity isn't about buying a specific 'magic' piece of software or checking a box on an IT list. It's about risk management—making smart decisions today so you aren't forced into making desperate ones during a 6:00 AM emergency call. Below are the five practices I've seen make the biggest difference in keeping firms like yours running and profitable.
Key Takeaways:
- Identity is the New Perimeter: Passwords aren't enough. Multi-factor authentication (MFA) must be enforced on every account—no exceptions.
- AI Has Changed Phishing: You can no longer rely on 'bad grammar' to spot fakes. Employees need to watch for emotional urgency and unexpected requests.
- Data Mapping is Mandatory: You cannot protect what you do not know you have. Identify where your client data actually lives.
- Resiliency Over Perfection: Assume an attack will happen. Have a tested, offline backup and a written response plan.
- Insurance Requires Proof: In 2026, you won't get covered (or claims will be denied) without proof of active security controls.
1. Make Identity Your Primary Defense (MFA 2.0)
For decades, we relied on the 'castle and moat' strategy—put up a firewall and keep the bad guys out. But in a world of remote work and cloud apps, that castle doesn't exist anymore. Your firm's 'perimeter' is now the identity of your employees. If I have your staff’s login, I am 'inside' your business, no matter where I am in the world.
I remember a call I got last year from a boutique law firm. They had multi-factor authentication (MFA) set up on their email, but the owner found it 'annoying' for his local desktop login. A criminal used a simple credential-stuffing attack to get into his account, found a saved password for their case management system, and within three hours, they had exfiltrated 40GB of sensitive client discovery files. The 'annoyance' of a 5-second login check cost them nearly $140,000 in forensics and notification costs.
In 2026, 'partial' MFA is a death sentence. You need to enforce it across every single entry point: email, VPN, remote desktops, and especially your financial tools. I also recommend moving toward Passkeys or FIDO2 hardware tokens (like Yubikeys) where possible. Traditional SMS text codes are increasingly being intercepted. If you're still using 'text me a code,' you're using 2018 security in a 2026 threat landscape.
2. Train Your Team for AI-Driven Phishing
We used to tell employees to look for misspelled words or weird logos. Those days are gone. Today's criminals use generative AI to write perfect, personalized emails that mimic the tone and style of your colleagues. They can even use 'deepfake' audio to impersonate your voice on a phone call. I once sat with a CEO who was nearly tricked into a $50,000 wire transfer because she received a voicemail that sounded exactly like her partner, who was away at a conference.
Your training needs to move away from 'red flags' and toward process-based verification. If an email or a call asks for a change in payment instructions, a wire transfer, or access to sensitive data, your staff must have a 'second channel' verification rule. That means they pick up the phone and call a known number—not the one in the email—to verify the request. According to IBM's 2025 Cost of a Data Breach Report, organizations that prioritize employee training see a significant reduction in the total cost of a breach, saving an average of $2.22 million compared to those that don't.
3. Map Your Data Assets (The 'Where is it?' Test)
I often ask business owners: 'If I told you to delete every piece of client PII (Personally Identifiable Information) right now, do you know every place it's stored?' Usually, I get a blank stare. You might think it's all in your main database, but it's also in 'Sent' folders in email, on an old legacy server in the closet that nobody turned off, in a Dropbox account an employee set up three years ago, and on unencrypted thumb drives.
The FTC's 2026 guidelines now mandate that small businesses maintain a written inventory of where sensitive data is stored. This isn't just about compliance; it's about reducing your 'blast radius.' If you don't need the data, delete it. If you do need it, encrypt it and restrict access to only the people who absolutely need it to do their jobs. I worked with an engineering firm that discovered a 'forgotten' server from 2019 was still connected to the internet; it contained the social security numbers of every former employee. That’s a ticking time bomb.
4. Prioritize Business Resiliency Over Simple Backups
Most owners tell me, 'I'm fine, Kevin, we have backups.' But in 2026, ransomware doesn't just encrypt your live data; it spends weeks silently finding and encrypting your backups first. I've seen firms realize their backups were useless exactly when they needed them most. According to Verizon’s 2026 Breach Impact Study, the median time to full resolution for an SMB with compromised backups is nearly three weeks longer than those with 'immutable' copies.
You need a 3-2-1-1 backup strategy:
- 3 copies of your data.
- 2 different media types.
- 1 copy offsite.
- 1 copy that is Immutable (meaning it cannot be changed or deleted for a set period, even by an administrator).
Beyond the tech, you need a written Incident Response Plan. This isn't a 50-page manual. It's a two-page 'cheat sheet' that tells your team: Who do we call first? Who is our legal counsel? How do we notify clients? I've watched firms spin their wheels for 48 hours just trying to find their insurance policy number while their systems were down. That downtime is the real killer—it costs an average of $53,000 per hour for a typical firm according to VikingCloud 2025 data.
5. Manage Your Digital Supply Chain
As a small firm, you rely on vendors for payroll, IT, CRM, and cloud hosting. Your security is only as good as their security. The Verizon 2025 DBIR found that breaches involving a third party doubled in a single year, now accounting for 30% of all incidents. If your IT provider gets hit, every one of their clients (including you) gets hit.
You must perform basic due diligence on your vendors. Ask them: Do you have an SOC 2 Type II report? Do you enforce MFA on your own staff? If they can't give you a straight answer, they are a risk to your business. I've seen 'managed service providers' that didn't even use MFA on their own internal tools, which eventually led to 40 of their clients being hit by ransomware simultaneously. Don't let your vendor's negligence become your bankruptcy.
The Real Cost of Doing Nothing
I know this feels like a lot. You’re trying to run a business, not a security department. But the math in 2026 is brutal. The average cost for a small business to recover from a 'contained' ransomware incident (where backups work) is between $250,000 and $1.2 million. If your backups are hit, that number jumps to over $3 million. Meanwhile, a proactive security program for a 20-person firm usually costs about 50 to 60 times less than a single recovery effort.
Cybersecurity shouldn't bury you in technical noise. It should be the foundation that allows you to grow without looking over your shoulder. Start by fixing your identity (MFA), talking to your team, and knowing where your data lives. Those three steps alone will put you ahead of 90% of the targets out there.
Frequently Asked Questions
Q: Is antivirus software enough to protect my firm in 2026?
A: No. Traditional antivirus is like a lock on a front door that only works if the criminal has a key we've seen before. Today, you need Endpoint Detection and Response (EDR). Think of EDR like a 24/7 security guard inside your computer that watches for 'suspicious behavior' (like a program suddenly trying to encrypt 1,000 files), rather than just looking for known viruses.
Q: Why is my cyber insurance carrier asking so many technical questions?
A: In 2026, cyber insurance is no longer a 'checkbox.' Carriers have lost billions of dollars to ransomware and are now requiring proof of controls. They may ask for screenshots of your MFA settings or your backup test logs. If you tell them you have a control in place and then have a breach where that control was actually missing, they can—and will—deny your claim.
Q: What is the single most common way small firms get hacked?
A: Credential theft via phishing. Most attacks don't involve 'hacking' into a system through a technical hole. They involve an employee being tricked into giving away their username and password. Once the criminal has those, they simply 'log in' as a legitimate user. This is why MFA is your most important defense.
Q: Should I pay the ransom if we get hit?
A: Most law enforcement and security experts (myself included) advise against it. According to the latest data, only 29% of victims who pay the ransom actually get all their data back. Furthermore, paying a ransom marks you as a 'payer' in the criminal community, making you a target for future attacks. The only real solution is to have immutable backups that make the ransom demand irrelevant.
Q: We use 'The Cloud' for everything, so aren't we already secure?
A: This is a common and dangerous misconception. Companies like Microsoft or Google are responsible for the security of the cloud (the infrastructure), but you are still responsible for your security in the cloud (who has access, how they log in, and what data you put there). If your employee has a weak password and no MFA on their Microsoft 365 account, the 'Cloud' won't stop a criminal from logging in and stealing your data.
Related Articles in Cyber Risk Management
- 7 Proven Steps to Assessing Digital Vulnerabilities for SMBs
- Risk Assessment and Analysis: 7 Key critical Takeaways for Effective Security?
- 7 Powerful Reasons Cyber Risk Management is Critical for Your Business Success — Complete guide on Cyber Risk Management
- 5 Effective Cyber Risk Reduction Methods for Businesses
- Small Business Cyber Risk Assessment: 5 Shocking Truths
- 5 Powerful Cyber Risk Monitoring Tools for SMBs
- Guide to implementing cyber risk strategies: 5 Simple Steps
- 5 Powerful Benefits of Cybersecurity Risk Analysis for Companies
- 5 Powerful Cyber Risk Mitigation Techniques SMBs Need
- Essential Cyber Insurance for Small Businesses: 2024 Guide
- 5 Power Steps to Build a Comprehensive Cyber Risk Plan
- 5 Proven Ways to Reduce Cyber Risk Impact on Business Operations
- 3 Proven Tips on How to Prioritize Cyber Risks
- 7 Powerful Affordable Cyber Risk Management Solutions for SMBs
- 5 Critical Key Cyber Risk Factors in Small Businesses to Tackle
- 5 Powerful Benefits of Risk-Based Cybersecurity Programs for SMBs
- 5 Powerful Reasons to Consider Cyber Insurance for Small Business Risks
- 5 Essential Steps for Reducing Cyber Liability for Small Business
- Cybersecurity Risk Management: 7 Key Strategies to Master Now
Watch: Your Cloud Data ISN'T SAFE! 3 MUST DOs for SMBs to Stop Hacks
Kevin Mabry
Founder & CEO, Sentree Systems
Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.
His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.
Is your business protected?
Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.
Schedule Your Free Assessment