You know your company should be doing more about cybersecurity. But the list of possible measures is long, vendor offerings are confusing, and the budget is finite. The question is not what you could do, but where to start.
These ten rules are our answer. They do not come from a textbook but from the incidents we handle at Swiss SMEs. In almost every one of them, a single rule from this list would have prevented the damage or made it much smaller. The order is deliberate: the top of the list is where little effort buys the most.
Rule 1: Multi-factor authentication everywhere
If you implement only one thing from this article, make it this one. Most attacks do not begin with a hacked firewall but with a valid password. It comes from a phishing email, from a data breach at another service, or it was simply guessed. A second factor turns that password into a useless string of text.
Everywhere means: Microsoft 365 or Google Workspace, VPN, remote maintenance, every admin account, every cloud console. Wherever possible, use phishing-resistant methods such as passkeys or hardware keys. SMS codes are better than nothing, but they can be intercepted or phished.
Rule 2: Install updates, outside first
Every known vulnerability with an available patch is being scanned for automatically by attackers. The time between a vulnerability being published and the first attacks on it is now often just days.
Prioritise by exposure: first everything reachable directly from the internet, meaning firewall, VPN gateway, web server, mail server, remote access tools. Then workstations and browsers, because that is where phishing lands. Then the rest. Set a fixed patch window and stick to it. An update that has been waiting for six months is an open door with a sign on it.
Rule 3: Separate admin rights
Nobody does everyday work with an admin account. Not IT, not management, nobody. Whoever reads email and browses the web does so with a regular account. Admin rights live on separate accounts that are used only for the task at hand.
The reason is simple: one click on the wrong attachment with admin rights hands the attacker the whole machine immediately, and often the whole network. The same click with a regular account gives them a user profile they first have to break out of. That effort costs time, and time is what Rule 8 buys you.
Rule 4: Backups that survive an attack
Before encrypting anything, ransomware groups deliberately look for backups and delete them. A backup that is reachable from the company network with regular credentials is therefore not a backup.
The proven rule of thumb is 3-2-1: three copies, on two different media, one of them off site. What matters most is that at least one copy is offline or immutable, so it cannot be deleted even with stolen admin rights. And: test the restore. Not the backup, the restore. A backup that has never been restored is a hope, not a plan.
Rule 5: Secure remote access
Open remote access is the classic entry point. An RDP port reachable from the internet. A VPN without a second factor. A remote maintenance tool a former IT partner installed years ago.
Check what is reachable from outside and close everything that does not absolutely need to be open. What stays open gets MFA. And ask whether your VPN really needs to lead into the entire network. Someone who only needs the time tracking tool should only see the time tracking tool. That is the core of Zero Trust, and it can be rolled out step by step.
Rule 6: Know what you have
You can only protect what you know about. Almost every incident features a system nobody remembered: an old server in the basement, a test environment that was never shut down, a cloud account an employee created before leaving.
Keep an inventory: which systems are running, where they are, who is responsible, which ones are reachable from the internet. A well-maintained spreadsheet is a good start. The problem: it only shows what someone wrote down. Shadow IT, meaning the forgotten server, the intern's notebook, the tool a department introduced without IT, is missing by definition.
This is exactly where Goldoak Spectacles helps. Because it collects events from your network, your endpoints and your cloud, it also sees systems that appear on no list. You get not just alerts but a picture of what is actually running in your environment. If you want to know what is hiding in your network, request a demo and we will show you on your own environment.
Rule 7: Harden email and identity
The mailbox is target number one. Whoever controls it can reset passwords, redirect invoices and order payments in the name of management. A few settings make a big difference here:
- Disable legacy authentication. Older protocols such as IMAP or POP without modern login bypass MFA. They can be switched off in Microsoft 365 and Google Workspace.
- Monitor forwarding rules. After breaking in, attackers like to set up a silent forward to read along. Block external forwarding or at least have it reported.
- Use conditional access. Sign-ins from countries where nobody works, or from unknown devices, can be blocked or challenged with additional checks.
- Set SPF, DKIM and DMARC. So nobody can send convincing-looking email in your name.
Rule 8: Detect instead of hope
The first seven rules make a break-in harder. None of them makes it impossible. So you need an answer to the question: how do you notice when someone is inside?
The honest answer in many SMEs is: not at all, until the files are encrypted. Yet attackers often move around the network for days or weeks before encrypting. That time is your window, but only if someone is watching. That means modern endpoint protection (EDR or XDR), central collection of sign-ins and events, and above all someone who reads alerts and reacts, including on a Friday evening.
That is exactly the gap we built Spectacles for: it collects events from endpoints, identities and cloud, detects suspicious behaviour and can isolate an affected system before the attacker moves on. And behind the alerts sits a team, not just a dashboard.
Rule 9: Have an incident plan before you need it
When it happens is not the moment to work out who to call. An incident plan fits on two pages and answers a few questions: Who decides? Who do we call, internally and externally? What do we switch off first? How do we communicate when email no longer works? Where is this plan when the network is encrypted?
Print it out. Walk through it once a year, at a table, in an hour. You will find gaps, and that is the point. Cyber insurers now ask specifically about this, and whoever knows immediately what to do during an incident saves days. If you need help when it matters, our incident response is the external contact you can write on that plan.
Rule 10: Involve employees and suppliers
Technology alone is not enough. The person who opens the attachment is not a security problem but your most important sensor, provided they know what to report and are not afraid to do it. Training therefore does not mean assigning blame. It means showing what phishing looks like today and making clear that a quick call to IT after a wrong click is always the right move.
The same applies outward. Your IT partner, your accountant, your software supplier all have access to your network. Ask how they protect that access, and remove access that is no longer needed. A large share of the incidents we see does not begin at the company itself, but at a third party with too much access.
Conclusion
None of these ten rules requires a major project. The first five can be implemented in a few weeks and prevent the majority of the attacks we see in practice. Rules 6 to 10 make sure you detect an attack, survive it and learn from it.
Start at the top and work your way down. If you want to know where your company stands today, a security health check shows you the gaps with priorities. And if you need a second opinion while implementing, bring your questions to a consulting session.