The myth of "we're too small to be targeted"

This is the single most dangerous belief in SME security. The reality is close to the opposite: small and midsize businesses are disproportionately targeted precisely because attackers know they typically have weaker controls, fewer dedicated resources, and slower detection.

According to global small-business cybersecurity data, a large share of breaches hit organisations with fewer than 1,000 employees. An SME doesn't need an enterprise budget to defend itself — but it does need a framework, applied consistently.

Step 1: Identify what you actually need to protect

Start with a simple inventory. Not everything an SME owns is equally worth protecting, and treating every asset as equally critical is how limited security budgets get spread too thin to matter anywhere. Ask:

  • What data do we hold that has real value — customer records, financial records, intellectual property?
  • What systems are business-critical — email, point-of-sale, payment processing?
  • What people have access to sensitive systems or data — and what happens if that access is compromised?

You cannot protect what you haven't identified. This single step alone drives a significant share of what follows.

Step 2: Understand your real threat landscape

Not all SMEs face equal risk. For most SMEs in East Africa, the highest-frequency threats tend to cluster around a few well-understood categories:

  • Business Email Compromise (BEC) — fraudulent emails impersonating suppliers or executives, often requesting payment redirects
  • Phishing — credential-stealing messages disguised as legitimate correspondence
  • Ransomware — malware that encrypts business data and demands payment for its release
  • Insider threats — employees accidentally or deliberately mishandling sensitive information

Understanding which threats are most likely to actually reach your business lets you prioritise controls, instead of buying tools aimed at threats you're unlikely to face.

Step 3: Apply a simplified controls framework

The Center for Internet Security (CIS) Controls are a globally recognised cybersecurity framework. For most SMEs, implementing just the first few controls represents a dramatic improvement in security posture:

ControlWhat to do
InventoryKnow every device and account that touches your network
SoftwareKnow every application installed
Data protectionClassify and protect sensitive data
Admin privilegesLimit who has administrative access
Secure configurationHarden default settings on systems
Audit logsLog and monitor activity

Step 4: Train your people

Technology controls alone are insufficient — people are consistently the most exploited control in smaller organisations. A basic security-awareness programme at SME scale should cover: recognising phishing attempts, practising good password hygiene, understanding what to report and to whom, and safe handling of sensitive information. This doesn't need to be elaborate — a short, focused training session, run consistently, outperforms an occasional long one that's quickly forgotten.

Step 5: Have a plan before you need one

Incident response planning at SME scale isn't about a large document — it's about clarity on a small number of questions before something goes wrong: who can call it an incident, who is authorised to make decisions during one, how do you communicate with staff and customers, and where are your backups tested and verified to work.

The RETIS approach to SME cyber risk

RETIS Systems works with SMEs across sectors on practical cybersecurity — real conversations, no jargon, and no unnecessary spend. The Cybersecurity Health Check exists specifically for this audience — a real, scoped Essential-tier engagement, not a full enterprise assessment forced onto a business that doesn't need one yet.

Frequently asked questions