Currently taking new clients ยท Get in touch today
Menu
Get a free quote โ†’
Show prices in
Colour theme
hello@sevenlayers.onlineWhatsApp +92 300 9449830
Cyber Security

The three attacks that actually hit small businesses

ยท 6 min read

Security coverage tends toward the dramatic: sophisticated intrusions, novel vulnerabilities, state-sponsored groups. That is not what happens to a twelve-person business. What happens is far more mundane, which is good news, because mundane things have mundane defences.

1. Invoice fraud

Somebody emails your finance contact, appearing to be a supplier you genuinely use, saying their bank details have changed. The invoice looks right because it often is right โ€” lifted from a real thread in a compromised mailbox somewhere along the chain. Payment goes to the attacker, and by the time the real supplier chases it, the money has moved.

Variants: an email that appears to come from the owner asking for an urgent transfer; a request to change payroll bank details just before pay day.

What stops it

  • One rule, written down: bank details are never changed on the strength of an email. They are confirmed by phoning a number you already held, not one supplied in the message.
  • Two people approve payments above a threshold you set.
  • Make it socially acceptable to slow down. Most of these succeed on urgency, and staff who fear looking obstructive are the target.

2. Account takeover of a mailbox

Someone's email password is guessed, phished, or reused from a service that was breached years ago. The attacker does not announce themselves. They read quietly, learn how you talk, set a forwarding rule, and wait for a conversation about money.

What stops it

  • Multi-factor authentication on every account, without exceptions. This one control removes the large majority of the risk, and app-based codes or hardware keys are meaningfully better than SMS.
  • A password manager, so passwords are unique and long rather than memorable and reused.
  • Check periodically for mail forwarding rules nobody created deliberately โ€” a classic sign, and easy to miss.
  • Remove accounts the day someone leaves, not the month after.

3. Ransomware through something unpatched

Rarely a clever exploit. Usually a remote access service exposed to the internet with a weak password, or a server missing a patch published months earlier. The result is your files encrypted, your backups encrypted if they were reachable, and a demand.

What stops it

  • Nothing administrative faces the internet. Remote desktop, management interfaces, database ports and admin panels belong behind a VPN.
  • Patch on a schedule that exists, rather than when something reminds you.
  • Backups that are off-site and immutable โ€” see our piece on restore testing, because this is the control that decides whether ransomware is a bad week or the end of the business.
  • Ordinary staff accounts are not administrators. It limits how far anything gets.

The honest summary

Multi-factor authentication, a payment-verification rule, patching, and backups you have actually restored. Four things. None of them expensive, none of them exotic, and together they address most of what genuinely happens to businesses this size.

The reason they often are not in place is not cost or ignorance โ€” it is that nobody owns them. Give each one a name against it and a date, and you have done more than most.

If you want an outside pair of eyes, a security review looks at whichever layer the risk actually sits in โ€” the website, the server, the network, or the process โ€” rather than only the one we happen to sell.

Get a free quote โ†’โ† All articles
Let's work together

Ready to grow your business online?

Book a free 30-minute call. We'll listen, give you honest advice, and get you a clear quote within 24 hours.

What you get from the call
Free
  • 01Honest, practical advice
  • 02A clear fixed-price quote
  • 03A realistic timeline
  • 04No pressure, no jargon
Get a free quote โ†’
Get a free quote