Cybersecurity advice aimed at small businesses tends to swing between two useless extremes: terrifying you with threats, or burying you in enterprise jargon you cannot act on. The truth is that a small business does not need a security operations centre. It needs a solid baseline — a handful of controls that, together, stop the overwhelming majority of attacks that actually target businesses like yours. South Africa is a heavily targeted market, so this is worth getting right.
Here is that baseline, in priority order. It underpins our managed IT work.
1. Multi-factor authentication, everywhere
If you do one thing, do this. Multi-factor authentication — a code or prompt in addition to your password — blocks the vast majority of account-takeover attacks, because a stolen password alone is no longer enough. Turn it on for email, for Microsoft 365, for your banking, and especially for any administrator account. It is free, it takes minutes, and it is the single highest-return security control a small business has.
2. Keep everything updated
Most successful attacks exploit known weaknesses that already have fixes available — the business just never applied them. Keeping Windows, your applications, your phones, and your website current closes those doors automatically. Where you can, turn on automatic updates; where you cannot, make patching someone’s explicit job. An unpatched system is not stable, it is just untouched until something finds it.
3. Tested backups
Backups are your insurance against the attack that gets through — particularly ransomware, which South African businesses face at among the highest rates on the continent. But a backup only counts if it works and if the attacker cannot reach it, so keep an off-site copy and actually test a restore now and then. The question that matters is not “do we back up?” but “when did we last successfully restore one?”
4. Email and domain protection
Email is the front door for phishing and business email compromise. Authenticating your domain with SPF, DKIM, and DMARC makes it far harder for anyone to impersonate your business, and good email filtering catches most malicious messages before they reach an inbox. Together these defend both your customers and your own staff from the most common attacks. Our DNS and email security playbook walks through setting each record up correctly.
5. Endpoint protection and least privilege
Every laptop and phone is a way in, so each needs proper, modern protection — not a free consumer antivirus, but managed endpoint security. And give people only the access their role needs: not everyone should be an administrator, because every admin account is a bigger prize for an attacker who gets in.
6. People — the most-skipped control
Most breaches involve a person being tricked, not a system being hacked. A little ongoing awareness — how to spot a phishing email, how to verify a request to change banking details, who to tell when something looks wrong — does more than most expensive tools. Make it safe and normal for staff to report a mistake quickly; the breach that gets contained early is the one someone owned up to.
7. A plan for when something slips through
No baseline is perfect, so decide in advance what happens when something does get through. It need not be a thick document — just the basics written down: who to call, how to isolate an affected machine, where the backups are and who can restore them, and which accounts to lock first. Under POPIA you may also have to report certain breaches, so knowing the steps before you are panicking turns a crisis into a procedure. The businesses that recover quickly are the ones who decided what to do while it was still hypothetical.
The practical next step
None of this is exotic, and none of it requires an enterprise budget. The hard part is making it consistent rather than occasional. If you are not sure where your gaps are, a short security review will measure you against this baseline and tell you what to fix first — usually starting with whichever of these six you have not fully done. It also forms part of a sensible POPIA posture.
Published 16 June 2026. Last updated 16 June 2026.