You know you have to do something about cybersecurity and you have no idea where to start. Every article you read suggests something different, every provider recommends precisely the service they sell, and you have a budget that will not stretch to everything and a team that is already short on time. The good news is that sequence matters more than budget: there is an order that produces results from month one in a company with 10 to 50 employees, and it starts with things that cost nothing.
The rule that puts everything else in order
Before buying anything, apply one simple test: spend first on what removes the most risk per euro, rather than on what sounds most advanced. In a company with no security function of its own, the thing that removes most risk is almost never an expensive tool. It is usually knowing what you have, who can get in, and what you do when something fails.
The classic mistake is starting from the end: buying a sophisticated solution for a company that still does not know how many of its servers are exposed to the internet, or who still has access to the mailbox of an employee who left eight months ago.
Month one: know what you have and who gets in
The first step costs no money, it costs a couple of afternoons. Build an honest inventory of what your company actually uses day to day:
- Cloud services you pay for: email, storage, ERP, CRM, invoicing, marketing tools.
- Servers and machines, including the ones in an old office or under somebody's desk.
- Domains and published websites, abandoned ones included.
- Who has access to each of them and at what permission level.
- People who no longer work for you and still have active accounts.
That last item usually produces the first surprise. Closing accounts that should not exist costs nothing, takes a morning and removes a real way in. It is the best ratio of effort to risk removed you will find anywhere in this process.
Month one as well: two-factor on what genuinely matters
Turning on two-step verification for critical accounts is the single highest-impact measure in a company this size. Email comes first, because whoever controls the mailbox can reset passwords on nearly everything else. Then online banking, admin access to your cloud services, and any system holding customer data.
Most services you already pay for include this at no extra cost. The usual objection is that it inconveniences the team, and it is solved by explaining why it is being done before switching it on rather than after.
Month two: backups that somebody has actually tested
Nearly every SME has backups. Far fewer have ever checked that they restore. The gap between those two situations shows up on the worst possible day, when ransomware has already encrypted the data and the backup turns out to be encrypted too, or incomplete, or five months old.
Check three things and write down the date you checked them: that the backup really covers everything you need to keep operating, that at least one copy sits out of reach of your connected systems, and that somebody has restored a test file and it worked. Repeat the test every quarter.
Months two and three: people, which is how attackers get in
Most incidents in companies this size begin with a person clicking where they should not, or acting on a request that looks legitimate. Two specific scenarios deserve an explicit conversation with your team.
CEO fraud: an email that appears to come from a director or a known supplier asks for an urgent transfer or announces a change of bank account. The control that stops it is procedural rather than technical: any payment or change of bank details gets verified by calling a number you already had, never the one printed in the message.
Smishing: text messages impersonating the Spanish tax agency, the postal service, social security or a bank, carrying a link that asks for credentials. Tell your team that these institutions do not request data or payments by SMS, and that when in doubt you reach them by typing the official address into a browser.
Those two conversations cost one thirty-minute meeting and head off the two most frequent frauds hitting Spanish SMEs.
Month three: look at yourself the way an attacker does
By this point you have covered the basics and it is time to stop guessing. A vulnerability scan of everything you have published on the internet answers one concrete question: what does somebody looking for weak points in your company find, with no prior access at all?
Typical findings in a company this size are easy to recognise: an admin panel reachable from any IP address, an old service nobody remembered, an expired certificate, a system nobody has updated in years because "it works and nobody touches it". A security assessment turns those assumptions into a concrete, prioritised list, and that list is what lets you spend budget where it counts.
From month four: turn it into a routine
What separates a company that improves from one that makes a single push and drifts back is frequency. Systems change, new vulnerabilities get published every week, and the inventory you built in January is out of date by June.
Vulnerability management is exactly that step: periodic review, prioritisation based on your context, and follow-up until each issue is actually fixed. Without that follow-up, an audit report becomes a PDF nobody opens.
Alongside it, spend an hour writing a minimum incident response plan on a single page: who decides, who gets called, what gets disconnected first, where the supplier phone numbers live and what gets communicated to customers. Nobody improvises well at three in the morning.
What you can safely postpone
With limited resources you also have to decide what is not happening yet. These can wait without your real risk rising noticeably:
- Getting certified against ISO 27001. It is a commercial door-opener when a client or a tender asks for it, and that moment does arrive eventually, though it is no legal obligation and no first step.
- Advanced detection tooling while you still have nobody to review its alerts. An alarm nobody listens to protects nothing.
- Exhaustive penetration testing before fixing what a basic scan already finds.
On public funding, get the fact right: the Kit Digital and Kit Consulting calls have closed, so you cannot apply today. The sensible move is to have your inventory and your priorities documented so you can move quickly if a future call opens.
The whole thing in one sentence
Start by knowing what you have and who gets in, protect email with a second factor, test your backups, talk to your team about CEO fraud and smishing, and only then look at yourself from the outside and turn it into a routine. That order fits in a quarter, needs no department of your own, and leaves your company in better shape than most others its size. The concrete first step, if you want to stop guessing, is measuring where you stand today.
Want to know how exposed your website is?
Ciphraverse's Security Assessment checks websites, portals and e-commerce with a professional external audit designed for SMEs.