Back to the articles

    General · United States

    The Four Layers of Small Business Cyber Defense

    By The Business Navigators ·

    Small companies do not get breached by sophisticated attacks. They get breached through a spoofed email, a guessed password, an expired certificate, or an unpatched site. Four layers close all four doors.

    Share
    The Four Layers of Small Business Cyber Defense

    Owners of 10 to 50 person companies tend to assume nobody is targeting them. That is half right. Nobody is targeting them specifically. Automated tools are scanning every domain on the internet, including theirs, and they do not care how big you are.

    The good news is that the doors used against small companies are few and well known. Four layers close them.

    How small companies actually get hit

    Not through anything exotic. Four doors, in rough order of frequency:

    1. Someone spoofs your domain. A client gets an invoice that appears to come from you with different bank details. They pay it. You find out when you chase the invoice.
    2. A password gets guessed. Automated tools try thousands of common passwords against your login pages every day. One reused password and someone is inside.
    3. A certificate expires or a file changes. Browsers start warning visitors, or code gets injected into your site and quietly harvests card details for weeks.
    4. A known vulnerability goes unpatched. Scanners find the unpatched plugin faster than you find the update notice.

    None of these needs a skilled attacker. All four are automated, constant, and cheap to run.

    The four layers

    LayerDoor it closesWhat it does
    Email identityDomain spoofing, invoice fraudSPF, DKIM and DMARC so nobody can send mail as you
    Login protectionPassword guessing, credential stuffingRate limiting, bot filtering, blacklists, a login URL attackers cannot find
    SSL and integrityExpired certificates, injected codeCertificate monitoring and file-change alerts
    Active defenseKnown exploits, malicious trafficA firewall and current threat intelligence in front of your site

    Skip any one of them and you have left a door open. Email identity is the one small firms skip most often and the one that costs the most when it fails, because invoice fraud takes cash out of the business directly and your client is the one who loses it.

    That layer does double duty, which most people miss. The same SPF, DKIM and DMARC records that stop somebody impersonating you also decide whether your own mail reaches the inbox. If you have ever wondered why your emails land in spam, this is usually the reason. Deliverability first covers that side.

    What one incident actually costs

    Owners price security against the monthly fee. The comparison that matters is against the incident.

    A modest one, no data breach, no regulator involved:

    Line itemTypical
    Incident response and cleanup$5,000 to $15,000
    Downtime, 3 daysThree days of revenue
    Client notification and trust repairHard to price, easy to underestimate
    One fraudulent invoice paid by a client$8,000 to $50,000
    Staff time pulled onto the responseTwo weeks of somebody senior

    Add a real data breach with regulated information and you are into legal counsel, notification requirements and possible penalties, which is a different order of magnitude.

    Against that, the layers run about $196 a month bought separately, or $149 a month bundled with a one-time $200 hardening pass for a single domain and site. Individually the pieces are $59 a month for email identity, $39 for login protection, $39 for SSL and integrity, $59 for active defense, each with a $100 one-time setup per domain.

    If you run several domains it changes shape: $129 per domain per month across five domains, or $99 per domain across twenty, with a one-time hardening pass on each. Agencies managing client sites usually land there, and our defense grid covers the WordPress login layer specifically, with white-label so it carries your brand rather than ours.

    The three things to do this week, free

    Before spending anything:

    1. Check your DMARC record. If you do not have one, anyone can send email as your domain today. This is the highest-risk, lowest-cost gap on most small business domains.
    2. Turn on multi-factor authentication everywhere. Email first, then banking, then your site admin. It defeats most credential attacks outright.
    3. List every system with a login and who has access. Most owners find at least one account belonging to somebody who left.

    If you do nothing else, do those three.

    Where WordPress fits

    If your site runs on WordPress, it is the most probed platform on the internet, purely because of its share of the web. That is not a reason to leave it, it is a reason to harden it. Login lockdown, current plugins, file integrity monitoring and a firewall handle the overwhelming majority of what gets thrown at it. WordPress site security covers the hardening pass, including assessment and cleanup if a site has already been compromised.

    What to ask a security vendor

    1. Which of the four doors does this actually close?
    2. What happens when it detects something? Who is notified, and how fast?
    3. Is this configured for me, or am I now running the software myself?
    4. What does the first month look like, concretely?
    5. If we are already compromised, do you assess and clean, or only prevent?

    Question three is the one that separates a tool subscription from a service. A security product nobody configures or monitors is a line item, not protection.

    Next step

    Security spending is hard to justify because success looks like nothing happening. Judge it the way you judge insurance: against the cost of the event, not against the monthly line.

    Check your DMARC record today. If it is missing, that is the door to close first.

    Book a discovery meeting and we will run a scan across your domains and sites and show you which of the four doors are open right now.

    Share this

    Recommended

    Take the free Founder Bottleneck Assessment

    The Business Navigators is the publisher of this article and provides the services described. No third-party compensation is involved.

    Featured offer

    Cyber Defense

    Built and delivered by Business Navigators. Making the Impossible Possible.

    See the Defense Suite layers and pricing

    Stay connected

    Follow Business Navigators on LinkedIn

    Get weekly insights on LinkedIn business development, executive meeting booking and revenue operations.

    Follow on LinkedIn