This is a common question we get from business owners, and the truth is there is no one-size-fits-all security strategy. Your protection should be as unique as your business operations.
One of the most important concepts in cybersecurity is the balance between ease of use and security. It is important to find this balance of an acceptable level of security and accessibility to ensure that data is safeguarded and employees are content. If security controls are too complicated or slow down workflow, your team will inevitably find dangerous workarounds to bypass them.
How do I find that balance?
To answer this question, you must first identify what you are protecting. The more sensitive and regulated the data is, the more security that is required for that data. For most small businesses, this data will likely include employee and business records. Next, you must identify what you do not want to happen with that data. From there, take a targeted approach to preventing those outcomes to protect that data.
Over-enforcement usually looks responsible from the top. Password changes every 30 days, a VPN for everything, an approval ticket to install anything. What actually happens is that people write passwords on sticky notes, quietly share the one login that already works, and email files to personal accounts to skip the VPN. You end up with less visibility than you started with.
Under-enforcement is easier to spot and harder to admit. Shared admin accounts, no MFA on email, and a former employee whose access nobody ever switched off.
Both fail the same way. The goal is not maximum security. It is security your team will actually follow.
So what security features do I implement?
Like many cybersecurity questions, the honest answer is that it depends. That said, here is a general list of targeted controls with high threat mitigation value.
- 1.MFA (Multifactor Authentication)
- 2.Access Controls
- 3.Security Patching
How do I implement those?
There are a number of ways to implement these security controls.
1.MFA (Multifactor Authentication)
- What it stops: Someone who already has your password. Stolen credentials are only useful if the password by itself gets them in.
- How to do it: Many services that have a login have an option to enable MFA, with some services requiring it by default. Additionally, ensure that you are using a trusted authenticator, such as Google Authenticator, Microsoft Authenticator, or Duo Authenticator.
2.Access Controls
- What it stops: One compromised account becoming a company-wide problem. If a bookkeeper's login is stolen, the attacker gets the bookkeeper's access, not everything.
- How to do it: The two important factors of access controls are the two A's, authentication and authorization. Access controls outline that verified users (authenticated) are only able to access resources they should have access to (authorization). These controls can be implemented within document sharing permissions, and in Microsoft 365 security controls. Different technologies will have more or less granularity over these controls.
3.Security Patching
- What it stops: Attacks using publicly known holes. When a vulnerability is published, the fix and the exploit go public at the same time.
- How to do it: Set apps and computers to automatically update. One of the leading causes of breaches is unpatched software, which leaves already-patched vulnerabilities sitting there to be exploited. Next time your computer prompts for an update, make sure you click OK!
A quick way to check where you stand
Run through these. Each one takes a minute.
- 1.Can you name the data that would hurt most if it leaked?
- 2.Is MFA turned on for email, for everyone, including owners and admins?
- 3.Does anyone share a login with anyone else?
- 4.If someone left today, do you know what to shut off, and whose job it is?
- 5.Are computers and applications set to update on their own?
- 6.Has anyone on your team found a workaround to a security rule in the last month?
If you answered no to the first five, that is your starting list to fix things. Question six is what no one mentions most of the time, and it is the only one that tells you whether your controls are actually working or are just there for show.
This seems like a lot. Can you help?
We know security can be a difficult balancing act, but you don't have to do it alone. The security pros at Azlera can help achieve that balance and protect your data. We tailor custom security solutions to your business and work with industry leaders to help provide the best solutions for you. If you are weighing what this should cost, our pricing page explains how we scope it.
Ready to secure your business without compromising on accessibility?
We will look at what you have, show you where you are over or under protected, and tailor it to your setup.
Book a comprehensive security scan
Related service: Cybersecurity services
