← Back to Insights
Best PracticesMarch 23, 20265 min read

The 10 Most Common Cybersecurity Mistakes in SMBs

Checklist of common cybersecurity gaps in a small business
In this article

Ten recurring cybersecurity gaps in small and mid-sized businesses, with practical priorities for accounts, backups, email, updates, suppliers, and incident response.

The 10 Most Common Cybersecurity Mistakes in SMBs

Key Takeaways

  • MFA often protects only some critical accounts.
  • Backups may exist without evidence that required systems can be restored.
  • Former employees' access and reused passwords create avoidable exposure.
  • Many SMBs lack a usable incident response plan.
  • Email authentication, patch management, supplier oversight, employee awareness, and vulnerability visibility are frequently incomplete.

The same problems appear repeatedly during cybersecurity engagements. They are not beginner mistakes. They are blind spots that can exist even in well-managed businesses.

Here are ten common gaps and the practical action associated with each one.

1. MFA Does Not Protect Every Critical Account

Multi-factor authentication may be enabled for the owner's email but not for remote access, administrative portals, cloud applications, or supplier accounts. One unprotected account may still provide an attacker with an entry point.

Insurers also commonly ask about MFA, although requirements vary by insurer, policy, and risk.

What to do: Inventory accounts that provide access to email, remote services, cloud platforms, financial tools, and administration. Apply appropriate MFA, prioritizing phishing-resistant methods where supported. Test emergency-access and account-recovery procedures as part of the rollout.

2. Backups Exist but Restoration Has Never Been Tested

Automated jobs may run for months without anyone confirming whether the required data is complete, protected, and recoverable. During ransomware, hardware failure, or human error, the organization may discover that files are incomplete, corrupted, inaccessible, or that no one knows the recovery procedure.

What to do: Define what must be recovered, the acceptable recovery time and data loss, then perform documented restoration tests at a frequency proportionate to criticality and change. A realistic test is more informative than a green status icon.

3. Former Employees Still Have Access

An employee leaves, but email, VPN, shared folders, applications, tokens, or supplier access remain active. Compromised credentials - or an unfavourable departure - can turn dormant access into a security incident.

What to do: Use a coordinated offboarding checklist. Disable accounts, revoke sessions and tokens, recover devices, transfer business information, and change shared secrets. Human resources, the manager, and IT should agree on timing and responsibilities before the departure.

4. The Same Password Is Used Across Several Services

If one external service is breached, reused credentials can expose business email or other systems.

What to do: Use a managed password manager, unique passwords, and appropriate MFA. Review how shared and emergency credentials are stored, accessed, and changed.

5. There Is No Incident Response Plan

If ransomware affects systems tonight, who makes decisions? Who calls the IT provider, insurer, legal counsel, or incident-response firm? Who communicates with employees and customers? Without a plan, the company improvises under pressure.

What to do: Begin with a short, usable response sheet: verified emergency contacts, escalation criteria, decision authority, communication channels, evidence-preservation guidance, and the first coordinated actions. Keep a protected copy available when normal systems are down, and test the plan through an exercise.

6. The Email Domain Is Poorly Protected

SPF identifies authorized sending infrastructure. DKIM applies cryptographic signatures to messages. DMARC uses authentication results and domain alignment to apply a policy and produce reports.

These controls reduce certain forms of domain impersonation. They do not stop every phishing message, display-name impersonation, lookalike domain, or compromised legitimate account.

What to do: Inventory every legitimate email sender, validate SPF and DKIM, introduce DMARC with monitoring, and move toward an enforcement policy only after reviewing the reports. A DNS record's presence does not prove that the configuration is complete or effective.

7. Security Updates Are Deferred Indefinitely

Updates may be postponed because they require testing, a restart, or operational downtime. Known vulnerabilities remain exposed while the organization waits.

What to do: Maintain an asset inventory and a defined patch-management process. Prioritize using actual exposure, system criticality, known exploitation, vendor guidance, compensating controls, and change risk. Urgent cases may require accelerated action, but no single deadline is appropriate for every vulnerability and environment.

8. Cybersecurity Is Delegated to the IT Provider Without Verification

The IT provider operates the infrastructure, and leadership assumes this automatically includes every cybersecurity responsibility. Unless the contract, responsibilities, reporting, and evidence are clear, important controls may fall between parties.

What to do: Review the service agreement and responsibility matrix. Ask for evidence about MFA, backup testing, patch management, endpoint protection, administrative access, logging, and incident escalation. Independent cybersecurity advice can complement the provider without replacing it.

9. Employees Receive No Relevant Phishing Training

Modern phishing can imitate a supplier, delivery service, executive, or colleague in the recipient's language. One interaction may expose credentials or create an initial foothold.

What to do: Provide short, practical training based on the organization's real risks and reporting process. Reinforce it with relevant reminders and exercises. Training complements technical controls; it does not replace them.

10. The Organization Has No Visibility into Technical Vulnerabilities

An SMB may operate for years without assessing internet-facing services, end-of-life software, missing updates, or selected high-risk configurations. Risks that are not visible cannot be prioritized intelligently.

What to do: Define the business question and appropriate scope. A vulnerability scan can identify known technical weaknesses. A broader audit can examine governance, suppliers, access, processes, recovery, and incident preparedness.

What to Do Now

Use the list as a preliminary discussion tool, not a scored risk assessment.

  1. Identify which items are known facts and which are only assumptions.
  2. Confirm the evidence with the responsible people or providers.
  3. Prioritize critical identities, recoverability, internet exposure, and incident readiness.
  4. Assign an owner and decision date to every approved action.

The number of items that apply does not by itself determine the organization's risk. One severe exposure may matter more than several minor process gaps.

Frequently Asked Questions

Which mistake is the most dangerous?

There is no universal answer. The effect depends on the organization's systems, data, exposure, and recovery capability. Unprotected critical accounts and untested recovery are often high priorities because they affect both the likelihood and impact of an incident.

Is antivirus enough?

No single product addresses every risk. Antivirus or endpoint protection does not, by itself, resolve weak access governance, exposed services, vulnerable infrastructure, supplier responsibilities, inadequate backups, or missing incident procedures.

Where should we begin if several gaps apply?

Begin with evidence. Confirm the protection of critical accounts, test recovery for critical systems, examine internet-facing exposure, and establish incident contacts. Then prioritize the remaining work by business impact, likelihood, dependency, and implementation risk.

Topics
cybersecurity mistakesSMB securityMFAbackupsbest practices
RD
About the Author
Rémi Douville
President · RDCybersécurité Inc.

More than 12 years of cybersecurity experience.

PMP · Master’s degree in Computer Engineering, specializing in cybersecurity management

Want to know where you stand?

Schedule a 20-minute introductory call. We will review your situation and clarify the most useful next step.

Schedule a Call →