Who this is for: owners and office managers who know cybercrime is a real risk but do not have a security team, and want to know where to start.
Most successful attacks on small businesses are not sophisticated. They rely on a stolen password, an unpatched machine, a convincing email or a backup that did not work. Fixing those four things removes most of the risk. Here are the seven controls we put in place first, in order of value.
1. Turn on multi-factor authentication
A password on its own is one leaked database away from being useless. Multi-factor authentication (MFA) adds a second proof, usually a code or approval on a phone. Switch it on for email, Microsoft 365 or Google Workspace, banking, remote access and every administrator account. It is the single most effective control on this list.
2. Keep everything patched
Attackers scan for known flaws in operating systems, browsers, routers and firewalls. Turn on automatic updates for workstations, and schedule a monthly check for servers, firewalls and network equipment. Replace anything that no longer receives security updates, including computers still running Windows 10, which reached end of support in October 2025.
3. Back up properly, and test the restore
Ransomware encrypts files and often the backups connected to them. Keep at least three copies of important data, on two different types of storage, with one copy offline or immutable and out of the office. Then test a restore every quarter. A backup you have never restored is only a hope.
4. Protect email, where most attacks begin
Use a business email service with spam and phishing filtering, and train staff to slow down on any message that creates urgency, asks for payment or changes banking details. A short call to confirm a changed bank account has saved many businesses from invoice fraud.
5. Limit administrator access
Staff should work in standard accounts. Keep administrator rights for the few people who need them and for the tasks that require them. When someone leaves, disable their accounts the same day.
6. Run business-grade endpoint protection
Modern endpoint protection monitors behaviour as well as known viruses, and can isolate an infected machine before it spreads. Free consumer antivirus rarely provides central reporting or response.
7. Write down what you will do when something goes wrong
A one-page plan is enough: who to call, how to disconnect an affected machine, where the backups are and who speaks to customers. Under the Protection of Personal Information Act (POPIA), if personal information may have been accessed without authorisation, you are required to notify the Information Regulator and the affected people. Knowing that in advance saves precious hours.
Where to start
If you are unsure where you stand, start with an assessment: what you have, what is exposed and which of the seven controls are missing. StepEdge provides managed IT and security support for businesses across South Africa, and we are happy to talk it through. Contact us for a conversation, with no obligation.

