The controls that stop most small-business attacks
The defense is unglamorous and mostly cheap: multi-factor authentication on every account that matters, backups proven by an actual restore, accounts closed the day someone leaves, patches applied on a schedule, and SPF, DKIM, and DMARC configured so nobody can send invoices as you. Together these close off the majority of realistic attack paths against a small business.
None of this requires enterprise tooling. It requires someone accountable for checking that it is actually done — which is the part that is usually missing. Configuration drifts, an exception becomes permanent, a backup silently fails. The value of an ongoing arrangement is not the software; it is the accountability.
There is also a practical payoff beyond safety: these same controls are what cyber-insurance carriers and larger clients now ask about. Putting them in place once answers the questionnaire, satisfies the client, and protects the business — the same work, three returns.
What you probably do not need
A ten-person business does not need a SOC, a SIEM, or a threat-intelligence subscription — and a vendor leading with those is selling fear. We size controls to the organization, and part of every review is telling you what you can safely skip.
When you do need more: regulated data (health, legal, financial), a security questionnaire from a larger client, or federal contract work. That is when a structured security audit or CMMC readiness work becomes the right next step — and we will route you there rather than upsell a bigger monthly plan.