---
title: "The Four Layers of Small Business Cyber Defense"
description: "Small companies get breached through spoofed email, guessed passwords, expired certificates and unpatched sites. See the four layers that close them and what an incident really costs."
canonical: "https://thebusinessnavigators.com/insights/four-layers-small-business-cyber-defense"
type: "article"
author: "The Business Navigators"
category: "General"
published: "2026-09-10"
updated: "2026-09-10"
---

# The Four Layers of Small Business Cyber Defense

_Small companies do not get breached by sophisticated attacks. They get breached through a spoofed email, a guessed password, an expired certificate, or an unpatched site. Four layers close all four doors._

Owners of 10 to 50 person companies tend to assume nobody is targeting them. That is half right. Nobody is targeting them specifically. Automated tools are scanning every domain on the internet, including theirs, and they do not care how big you are.

The good news is that the doors used against small companies are few and well known. Four layers close them.

## How small companies actually get hit

Not through anything exotic. Four doors, in rough order of frequency:

1. **Someone spoofs your domain.** A client gets an invoice that appears to come from you with different bank details. They pay it. You find out when you chase the invoice.
2. **A password gets guessed.** Automated tools try thousands of common passwords against your login pages every day. One reused password and someone is inside.
3. **A certificate expires or a file changes.** Browsers start warning visitors, or code gets injected into your site and quietly harvests card details for weeks.
4. **A known vulnerability goes unpatched.** Scanners find the unpatched plugin faster than you find the update notice.

None of these needs a skilled attacker. All four are automated, constant, and cheap to run.

## The four layers

| Layer | Door it closes | What it does |
|---|---|---|
| Email identity | Domain spoofing, invoice fraud | SPF, DKIM and DMARC so nobody can send mail as you |
| Login protection | Password guessing, credential stuffing | Rate limiting, bot filtering, blacklists, a login URL attackers cannot find |
| SSL and integrity | Expired certificates, injected code | Certificate monitoring and file-change alerts |
| Active defense | Known exploits, malicious traffic | A firewall and current threat intelligence in front of your site |

Skip any one of them and you have left a door open. Email identity is the one small firms skip most often and the one that costs the most when it fails, because invoice fraud takes cash out of the business directly and your client is the one who loses it.

That layer does double duty, which most people miss. The same SPF, DKIM and DMARC records that stop somebody impersonating you also decide whether your own mail reaches the inbox. If you have ever wondered why your emails land in spam, this is usually the reason. [Deliverability first](/insights/email-deliverability-why-emails-go-to-spam) covers that side.

## What one incident actually costs

Owners price security against the monthly fee. The comparison that matters is against the incident.

A modest one, no data breach, no regulator involved:

| Line item | Typical |
|---|---|
| Incident response and cleanup | $5,000 to $15,000 |
| Downtime, 3 days | Three days of revenue |
| Client notification and trust repair | Hard to price, easy to underestimate |
| One fraudulent invoice paid by a client | $8,000 to $50,000 |
| Staff time pulled onto the response | Two weeks of somebody senior |

Add a real data breach with regulated information and you are into legal counsel, notification requirements and possible penalties, which is a different order of magnitude.

Against that, the layers run about $196 a month bought separately, or $149 a month bundled with a one-time $200 hardening pass for a single domain and site. Individually the pieces are $59 a month for email identity, $39 for login protection, $39 for SSL and integrity, $59 for active defense, each with a $100 one-time setup per domain.

If you run several domains it changes shape: $129 per domain per month across five domains, or $99 per domain across twenty, with a one-time hardening pass on each. Agencies managing client sites usually land there, and [our defense grid](/defense-grid) covers the WordPress login layer specifically, with white-label so it carries your brand rather than ours.

## The three things to do this week, free

Before spending anything:

1. **Check your DMARC record.** If you do not have one, anyone can send email as your domain today. This is the highest-risk, lowest-cost gap on most small business domains.
2. **Turn on multi-factor authentication everywhere.** Email first, then banking, then your site admin. It defeats most credential attacks outright.
3. **List every system with a login and who has access.** Most owners find at least one account belonging to somebody who left.

If you do nothing else, do those three.

## Where WordPress fits

If your site runs on WordPress, it is the most probed platform on the internet, purely because of its share of the web. That is not a reason to leave it, it is a reason to harden it. Login lockdown, current plugins, file integrity monitoring and a firewall handle the overwhelming majority of what gets thrown at it. [WordPress site security](/wpsecurity) covers the hardening pass, including assessment and cleanup if a site has already been compromised.

## What to ask a security vendor

1. Which of the four doors does this actually close?
2. What happens when it detects something? Who is notified, and how fast?
3. Is this configured for me, or am I now running the software myself?
4. What does the first month look like, concretely?
5. If we are already compromised, do you assess and clean, or only prevent?

Question three is the one that separates a tool subscription from a service. A security product nobody configures or monitors is a line item, not protection.

## Next step

Security spending is hard to justify because success looks like nothing happening. Judge it the way you judge insurance: against the cost of the event, not against the monthly line.

Check your DMARC record today. If it is missing, that is the door to close first.

Book a discovery meeting and we will run a scan across your domains and sites and show you which of the four doors are open right now.

Canonical page: https://thebusinessnavigators.com/insights/four-layers-small-business-cyber-defense

## Contact Business Navigators

- Email: circle@thebusinessnavigators.com
- Book a meeting: https://book.thebusinessnavigators.com
- LinkedIn: https://www.linkedin.com/company/the-business-navigators
- Website: https://thebusinessnavigators.com/

Making the Impossible Possible.
