IT Security for Small and Medium-Sized Businesses: The Default Isn’t Secure

Nine out of ten small and medium-sized businesses are at risk of cyberattacks. Find out why a standard environment isn't secure and how to get the basics right.

7 minutes

A director at an SME recently said to me, “We use Microsoft 365, so Microsoft takes care of all our security for us, right?” It’s an understandable assumption. You’re paying a large, reliable provider for your email, documents, and collaboration tools, so you assume that security is just as well taken care of. Yet that assumption isn’t correct. And that’s exactly where the risk lies—one that many business owners don’t see coming.

A standard IT environment is not the same as a secure IT environment. This applies to a Microsoft tenant, but just as much to your network, your laptops, and the way employees log in. The software you use provides the building blocks. What you do with it determines whether you’re truly secure.

Recent research highlights just how widespread this misconception is. Nine out of ten Dutch SMEs with 10 to 250 employees face serious cyber risks, according to the Cisco Cybersecurity Readiness Index 2025. At the same time, 45 percent of them are convinced that their current IT infrastructure is well equipped to withstand future attacks. That gap between perception and reality is the real problem. Those who think they are safe take no action.

What is the difference between “standard” and “securely configured”?

When you start using a new environment, the settings are designed for convenience. Above all, everything needs to work quickly and without any hassle. That makes sense, because a vendor wants you to be able to get started right away. Security features that might get in the way of that first impression are therefore often disabled by default or configured to be flexible.

A securely designed environment reverses that order. In such an environment, security comes first, and convenience is carefully organized around it. The difference rarely lies in expensive additional software, but in the choices made. Here are a few examples:

  • By default, anyone can access virtually anything, unless you deliberately restrict access. With a secure setup, users only have access to what they need.
  • By default, you can log in with just a password. For a secure setup, a second step is always required.
  • By default, old, vulnerable login methods are still enabled. In a secure configuration, they are intentionally blocked.

What risks do you face with a standard environment?

The risks are more tangible than many business owners realize. In a typical environment, I consistently encounter the same vulnerabilities in practice.

  • Multifactor authentication isn’t enforced everywhere, which means that a stolen password is often enough to gain access.
  • Outdated login methods are still in use, and it is precisely these that bypass modern security measures.
  • External guests and old accounts have more permissions than necessary.
  • Logging is turned off, which means you won’t be able to determine what happened after an incident.
  • Many standalone security tools are running side by side without any coordination.

The latter is an underestimated problem. Nearly half of all small and medium-sized businesses use between 11 and 40 different security solutions, and two-thirds view that complexity itself as an obstacle to effective defense (Cisco, 2025). More software does not automatically mean greater security.

These aren’t just theoretical risks. One in three small and medium-sized businesses fell victim to a cyberattack last year (Cisco, 2025). Such an attack can bring your business operations to a standstill, damage customer trust, and, in the event of a data breach, make you liable under the GDPR. I’ll be honest: no environment can be made 100 percent secure. But the difference between a standard environment and a well-designed one is enormous.

What actually works when it comes to getting your security in order?

The good news is that the biggest savings come from the basics, not from the most expensive solution. This really makes a difference in practice:

Start with identity. Enforce multi-factor authentication for everyone, including administrators. Microsoft itself states that MFA blocks more than 99.2 percent of attacks on accounts (Microsoft, 2026).

  • Remove outdated login methods so that attackers cannot gain access through a backdoor.
  • Set up conditional access so that logins from unknown locations or devices are subject to additional verification.
  • Give employees only the permissions they need, and delete old accounts and guest access.
  • Enable logging and monitoring so that you can detect and investigate an incident.
  • Turn your tools into a cohesive whole rather than isolated silos.
  • Invest in raising awareness. People remain the most vulnerable point of entry.

A proven way to approach this in a structured manner is to use recognized security standards such as the CIS Benchmarks. To learn how to use them to make your environment more secure, step by step, read this article: Protect Your Environment with Security Standards.

What objections do I often hear, and are they valid?

In conversations, I keep hearing the same objections. They’re understandable, but they’re often incorrect.

  • “We’re too small; no one will attack us.” Most attacks are automated and don’t try to figure out who you are—they just look for an open door. The fact that one in three small and medium-sized businesses has already been affected shows that being small offers no protection.
  • “MFA is too difficult for my team.” You can implement it step by step, and with modern methods, the barrier to entry is low. That small amount of effort is nothing compared to the risk of an account being compromised.
  • “We already have all kinds of security measures in place.” That’s often true, but there’s no cohesion. Two-thirds of small and medium-sized businesses see this jumble of tools as an obstacle. A better-organized system is more valuable than having more.
  • “That’s bound to be too expensive.” Getting the basics right mainly requires attention—it’s not a major project. The cost of an incident is many times higher than that of effective prevention.

A Practical Checklist: Where Should You Start Tomorrow?

Would you like to get an initial idea of where you stand? Go through these points.

  1. Is MFA enabled for all users, including administrators?
  2. Have outdated login methods been blocked?
  3. Has conditional access been set up?
  4. Do you know exactly who has which rights, and are they still accurate?
  5. Are logging and monitoring enabled?
  6. Do you have a clear overview of all the security tools you use?
  7. Do employees receive regular awareness training?

Can’t you say “yes” wholeheartedly to every point? Then you’ve got some work to do, and there’s no shame in that. In fact, now is the time to do something about it.

Would you like to compare your own situation to the Dutch statistics? In the Cybersecurity Monitor 2024: Where Does Your Organization Stand? We’ll help you determine where you stand compared to similar companies.

How does New Yard help you get your security in order?

At New Yard, we don’t focus on what we can sell, but on what your organization really needs. First, we assess the current state of your IT security—from your Microsoft tenant to your devices and access policies. Then we lay a solid foundation and help you streamline the proliferation of disparate tools into a system that works and is manageable. No sales pitch—just an honest assessment and a workable plan.

We don’t rely on isolated measures, but rather on a clear security roadmap for 2026, so that every step contributes to the overall goal and the impact on your employees remains minimal.

Wondering how safe your neighborhood really is?

Want to know where your organization stands, without any immediate cost? Schedule a no-obligation introductory meeting with New Yard. Together, we’ll assess your current situation and give you a clear picture of the key areas for improvement. There’s no obligation, and you’ll at least know where you stand afterward. Visit newyard.nl or contact us.