Buying cybersecurity tools is easy. Knowing whether your business is actually protected is much harder.
Many growing businesses with 20 to 200 employees have antivirus or endpoint security, a firewall, backups, MFA, and an internal or outsourced IT team, sometimes vulnerability scanning, monitoring, or cyber insurance too. On paper, that looks like a strong program. But there is an important difference between having security tools and having effective security. That is where almost every real incident starts.
A company can invest heavily in technology and still have serious weaknesses. The real question is not “What security products do we have?” It is: “If someone tried to compromise our business tomorrow, would our controls actually prevent it, detect it, contain it, and help us recover?”.
Security Tools Are Only Part of the Picture
Imagine a 100-person company with endpoint protection installed everywhere. Sounds good, until you ask: what if 15 laptops stopped reporting to the platform? What if alerts are generated but nobody reviews them? What if former employees still have cloud access, or an attacker compromises a Microsoft 365 account without ever touching a laptop?
The products may be working exactly as designed, and the business can still be exposed. Good cybersecurity requires prevention, visibility, detection, response, recovery, and validation working together. Miss one, and the other five do not fully make up for it.
- 1. You Know What You Are Protecting
- An effective program starts with something surprisingly simple: the business knows what it has.
- Computers and mobile devices
- Employees, contractors, and user accounts
- Cloud applications
- Email systems
- Business-critical software
- Sensitive data
- Network infrastructure
- External services
- Administrative and privileged accounts
- Third-party connections
At 20 employees this is easy to track. At 100 or 200, departments adopt their own applications and old accounts get forgotten. You cannot protect systems you do not know exist.
2. Multi-Factor Authentication Is Actually Enforced
Having MFA available is not the same as having it properly implemented. It should be enforced across:
- Microsoft 365 or Google Workspace
- Remote access
- Financial applications
- Administrative accounts
- Cloud infrastructure
- Password managers
- Applications containing sensitive information
There should also be a process for exceptions. If 148 employees use MFA but two executives are exempt because it is inconvenient, those two accounts are now the most attractive target in the company. Security controls are only as strong as the gaps left around them.
3. Your Devices Are Protected and Monitored
Endpoint protection should cover laptops, workstations, and servers, but deployment is only the beginning. Are
all devices actively reporting? Are updates current? Who investigates the alerts?
A sophisticated platform generating an alert at 2:00 a.m. does not automatically protect the company. Someone still has to decide whether it is real and act on it. The technology gets you halfway there.
4. You Know Which Vulnerabilities Matter
Every organization has vulnerabilities, and the number grows with your employees, applications, and cloud services. The goal is not eliminating every one immediately; it is understanding your exposure and prioritizing what creates real business risk. A mature process provides visibility into:
- Known software vulnerabilities
- Missing security updates
- Misconfigured systems
- Internet-facing services
- Weak security settings
- Unsupported software
- Excessive privileges
- Cloud configuration weaknesses
A list of hundreds of vulnerabilities does not help anyone if nobody knows which five actually matter.
5. Someone Is Watching for Suspicious Activity
Prevention will never stop everything, which is why detection matters. An employee account signs in from an unusual location. A finance employee downloads an unusually large amount of data. Would anyone notice?
Monitoring cannot depend on someone remembering to check a dashboard occasionally. Clear responsibility for investigating suspicious activity is what keeps a manageable incident from becoming a major disruption.
6. Access Is Controlled as the Company Grows
Employees join, leave, and change departments; contractors get temporary access; permissions pile up long after projects end. A business should have processes for:
- Creating new accounts
- Assigning appropriate permissions
- Managing privileged access
- Reviewing access periodically
- Removing unnecessary permissions
- Disabling departing employees promptly
- Managing contractor and third-party access
A useful test: could you produce a reliable list today showing exactly who has administrative access to your critical systems? If that takes more than a few minutes, that itself is the finding.
7. Your Backups Have Actually Been Tested
Many businesses say “yes, we have backups.” A better question is: when did we last successfully restore something from them? Management should understand:
- What information is being backed up
- How frequently backups occur
- Where backups are stored
- How long data is retained
- Who can access or delete backups
- Whether backups are separated from production systems
- How quickly systems could realistically be restored
Finding out during a ransomware incident that backups are incomplete or compromised turns a bad day into a much worse one.
8. Employees Know How to Recognize and Report Threats
Attackers may target finance, HR, executives, salespeople, or IT admins. Employees should recognize:
- Phishing
- Fake login pages
- Payment fraud
- Executive impersonation
- Suspicious attachments
- Unexpected MFA requests
- Credential theft attempts
Awareness alone is not enough. If someone enters a password into a suspicious site, the speed of what happens next matters more than the mistake itself.
9. You Have a Cyber Incident Response Plan
Picture a Monday morning where employees suddenly cannot access critical files. Who determines whether it is ransomware? Who can disconnect systems, contact the provider, or reach the insurer?
At 20 employees, some of this may happen informally, and that can be fine. At 100 or 200, improvising through those same decisions usually costs more time than the incident itself.
10. You Understand Your Third-Party Risk
Growing companies depend on software providers, accountants, payment platforms, and contractors, some of whom can access company systems. Who can access your business from the outside?
Third-party access should be understood, limited, and removed when no longer needed. Cybersecurity does not stop at the edge of your own organization, even though most security reviews do.
11. Your Security Is Tested, Not Assumed
Financial accounts get reconciled, fire alarms get tested, insurance policies get reviewed; cybersecurity should be treated the same way. Depending on your size, validation might include:
- Vulnerability assessments
- Security configuration reviews
- Penetration testing
- Phishing simulations
- Access reviews
- Backup restoration tests
- External exposure assessments
- Incident response exercises
The goal is not proving everything is perfect. Nothing ever is. It is finding weaknesses before someone outside the company does.
The Questions Management Should Be Able to Answer
Business leaders do not need to become cybersecurity experts, but they should get clear answers to:
- Do we know which systems and data are critical to our business?
- Is MFA enforced across critical systems?
- Are all company devices protected and monitored?
- Do we know which vulnerabilities require immediate attention?
- Who reviews and responds to security alerts?
- Who has administrative access?
- How quickly is access removed when someone leaves?
- Are our backups working and tested?
- Do we understand which third parties have access to our systems?
- When did we last independently test our security?
- What would happen if ransomware hit tomorrow?
If management cannot answer these confidently, the problem is rarely a lack of products. It is usually a lack of visibility and validation.
Protection Is a Process, Not a Product
No single product makes a company secure. Real protection comes from combining the right technology with good configuration, visibility, monitoring, employee awareness, access management, and regular validation.
For a business with 20 to 200 employees, this does not require a large internal security department. It means someone owns each critical function, and the controls you depend on are actually monitored and tested. Owning the tools creates a sense of security. Knowing they work is what actually provides it.
Do You Know Whether Your Security Is Working?
If you are unsure, the first step does not have to be buying another product. Start by validating what you already have. That is usually where I start with a new client, and it is almost always more revealing than anyone expects.
Because the most important cybersecurity question is not “What did we buy?” It is “Does it actually work?”.