How Much Cybersecurity Does My Business Actually Need?
For many small and midsize businesses, cybersecurity creates an uncomfortable question: how much protection is actually enough? Most owners get it wrong in one of two directions. They overspend, chasing whatever a vendor is pushing that quarter. Or they underspend, because nobody in the business ever forces the question.
After twenty years advising companies on exactly this, I can tell you neither one actually reduces risk.
A company with 25 employees does not need the same infrastructure as a global bank. But antivirus and a firewall alone are not a strategy anymore. The goal is understanding your actual risk and building protection that matches it. For most SMBs, that’s a small number of controls, chosen deliberately
Start With the Business, Not the Technology
One of the most common cybersecurity mistakes is starting with products: Do we need EDR? Should we buy another firewall? Do we need penetration testing? What about 24/7 monitoring? Those may be reasonable questions, but they come later. I would rather see a business get five fundamentals right than own fifteen tools nobody configured properly.
The first questions should be about the business itself:
- What information do we need to protect?
- Which systems are critical to daily operations?
- What would happen if we lost access to them for a day or a week?
- Who has access to sensitive information?
- What regulatory or contractual requirements apply to us?
- How dependent are we on Microsoft 365, Google Workspace, cloud applications, suppliers, and other third parties?
- How quickly could we recover from ransomware, account compromise, or data loss?
A 15-person accounting firm handling sensitive financial information may require stronger controls than a 50-person company with limited sensitive data.
Employee count matters, but business risk matters more.
What Does a Typical SMB Actually Need?
What Does a Typical SMB Actually Need?
There is no universal cybersecurity package, but most businesses should establish a strong security baseline before investing in more sophisticated technology.
- Protect User Accounts
Many attacks begin with compromised credentials, not someone hacking through a firewall. Enable multi-factor authentication wherever possible, especially for email, cloud services, financial systems, admin accounts, and remote access. Of everything on this list, this is the single highest-value control for the lowest cost, and still the one I see left half-done most often.
Review access regularly: remove it quickly when someone leaves, and do not let permissions pile up when people change roles. - Secure Every Endpoint
Every laptop and workstation is a potential entry point. Traditional antivirus misses a lot of what modern endpoint protection catches: unusual behavior, ransomware, processes that should not be running. Devices should be configured properly, encrypted, and kept updated. One compromised laptop should never become a gateway into the rest of the company. That is the whole point. - Keep Systems Patched
Cybercriminals rarely bother with anything exotic. Most of the time they are exploiting a known vulnerability that already has a fix sitting unused. Operating systems, browsers, business applications, and network devices all need a defined patching process. You do not need a large security team for this. You need one person responsible for it, and visibility into whether updates are actually going in. - Protect Email
Email is still where most of this starts. Phishing, fake invoices, credential theft, impersonation, and business email compromise can all begin with one convincing message landing in someone’s inbox. Technology blocks a lot of it. It does not block all of it. Employees still need to recognize a suspicious request, especially anything involving payments, passwords, or sudden urgency. - Back Up What Matters
Backups are not just an IT convenience; they are part of your cybersecurity strategy. Ask yourself: if our critical systems were encrypted or destroyed tomorrow, could we actually recover? Test the answer instead of assuming it.
Know where backups are stored, who can access them, and how long restoration would realistically take. A backup that has never been tested is, in practice, worse than knowing you have no backup at all: at least then you know where you stand. - Know Your Vulnerabilities
You cannot manage a weakness you do not know exists. Identify vulnerabilities across your systems, applications, cloud environments, and anything facing the internet, on a regular schedule, not once a year. Not every vulnerability is equally dangerous. A good process sorts them into what needs urgent attention and what can wait for normal maintenance, because treating everything the same wastes the one resource smaller businesses actually have less of: time. - Train Employees
Employees are part of the security environment whether anyone planned it that way or not. They should recognize phishing, protect credentials, handle sensitive information properly, and know how to report something that feels off. You are not trying to turn them into security specialists. You are trying to make the secure choice the easy choice. - Have a Plan for When Something Goes Wrong
No cybersecurity program can guarantee an incident will never happen, which makes preparation critical. You should know who to contact, who has authority to make decisions, how compromised systems get isolated, how operations continue, who talks to customers or partners, and whether legal, insurance, or regulatory notifications are required.
A simple incident response plan built before an attack can save valuable time when every minute matters.
Where Businesses Often Overspend
Cybersecurity spending does not automatically equal maturity. SMBs can accumulate security products without understanding what each one actually protects, creating overlapping tools, unnecessary licenses, and alerts nobody reviews. In twenty years of doing this, I have walked into more than one business with a security stack that looks impressive on paper and does almost nothing in practice, because no single person owns any of it.
Before buying another solution, ask three questions: What specific risk does this reduce? Do we already have something that addresses it? Who will manage and respond to it? That third question matters most: a sophisticated platform provides limited value if nobody owns its alerts.
Where Businesses Often Underspend
The opposite mistake is assuming your IT support already has this covered. IT and cybersecurity overlap, but they are not the same job. Keeping computers running, managing Microsoft 365, keeping the Wi-Fi up, that is operations. Cybersecurity is a different discipline: identifying threats, reducing exposure, monitoring activity, testing controls, and understanding business risk. Good IT people know the difference. Not all of them will tell you.
For many SMBs, the biggest gaps are not expensive technologies. They are basic controls that were never properly implemented or verified.
A Better Approach: Build Security in Layers
Think of cybersecurity as layers, not a single product:
- Foundation: MFA, secure configurations, patching, backups, access controls, and endpoint protection.
- Visibility: knowing which devices, users, applications, vulnerabilities, and external exposures exist.
- Detection: identifying suspicious behavior when preventative controls fail.
- Response: a defined process for containing and recovering from an incident.
- Validation: regularly checking whether the controls you rely on are actually working.
As your business grows or its risk profile changes, add more layers. This lets spending grow alongside real business needs instead of following vendor recommendations.
So, How Much Cybersecurity Is Enough?
The right answer differs for every business. A 20-person firm, a 60-person healthcare organization, and a 100-person technology company may need very different programs, but the principle stays the same: your investment should be proportional to your risk.
The goal is not maximum security at any cost. Perfect security does not exist, and I am always skeptical of anyone who claims otherwise. Aim to reduce your most important risks to an acceptable level, keep the ability to detect problems quickly, and be ready to recover when something happens.
For many SMBs, that is achievable without an internal security department or a long list of enterprise products. What matters is choosing the right controls, implementing them correctly, and continuously checking they are doing what you expect.
Not Sure Where Your Business Stands?
A useful first step is not buying another product. It is understanding what you already have, where your biggest risks are, and which gaps deserve attention first. That is the conversation I would rather have with a business before they buy anything else.
The result should be simple: the protection your business actually needs. Nothing you are paying for just because someone told you that you should.