Article

Cybersecurity mistakes businesses should stop making

Most security incidents in small and mid-sized organizations exploit ordinary gaps, not sophisticated weaknesses. Stopping ten common mistakes, such as relying on passwords alone, delaying updates and never testing backups, closes the doors attackers use most.

The short answer

If you do nothing else, stop making these ten mistakes:

  1. Relying on passwords alone.
  2. Delaying updates or running unsupported software.
  3. Treating antivirus as enough.
  4. Keeping backups you have never restored.
  5. Letting everyone be an administrator.
  6. Assuming your cloud provider handles security.
  7. Having no incident response plan.
  8. Treating security training as a once-a-year event.
  9. Forgetting your suppliers.
  10. Believing you are too small to be a target.

CISA's Secure Our World guidance and the NIST Cybersecurity Framework address almost all of them, and are a sensible starting point for any US organization.

1. Relying on passwords alone

Passwords get phished, guessed and reused. Do instead: require multi-factor authentication on email, remote access, cloud applications and administrator accounts, and use a password manager so people can have unique passwords everywhere. Prefer phishing-resistant methods such as security keys or passkeys for high-risk accounts.

2. Delaying updates or running unsupported software

Attackers move quickly once a vulnerability is public, and CISA's Known Exploited Vulnerabilities Catalog lists flaws that are already being used in real attacks. Unsupported devices stay exposed to vulnerabilities that will never be patched. Do instead: turn on automatic updates where practical, patch internet-facing systems first, track end-of-support dates for operating systems and key applications, and budget to replace them in time.

3. Treating antivirus as enough

Traditional antivirus looks for known malware. Many attacks now use legitimate tools and stolen credentials that signature-based products do not flag. Do instead: use endpoint detection and response (EDR), which records behavior and can isolate a device, and make sure someone watches and acts on the alerts, around the clock if possible. See EDR vs antivirus.

4. Keeping backups you have never restored

A backup that has never been restored is a hope, not a plan. Ransomware also targets connected backups. A widely used approach is the 3-2-1 rule (three copies, on two types of media, one off site), with offline or immutable copies that are only connected when needed, and routine testing of recovery. CISA's #StopRansomware guidance covers backups as part of ransomware preparation. Do instead: keep an offline or immutable copy, test restores on a schedule, and know how long a full recovery would take. See why a backup is not a recovery plan.

5. Letting everyone be an administrator

When staff use administrator accounts for daily work, one malicious click can compromise the whole device or network. Do instead: apply least privilege. Give administrator rights only to those who need them, use separate admin accounts for admin tasks, and review access when people change roles or leave.

6. Assuming your cloud provider handles security

Cloud providers secure their infrastructure, but you remain responsible for your data, user access and configuration. Under software as a service, the customer still manages user access and data, and your organization stays accountable for its information however much of it sits in the cloud. Do instead: configure Microsoft 365, Google Workspace and other SaaS tools securely, turn on audit logging, and back up critical SaaS data separately.

7. Having no incident response plan

Without a plan, the first hours of an incident are lost to confusion. Do instead: write a short plan naming who decides, who investigates, who communicates and who calls your legal counsel and insurer. Include how you will assess and report breaches under the laws that apply to you: every state has a breach notification law, and some sectors have their own rules (for example HIPAA for health data). Keep the plan available offline and rehearse it once a year.

8. Treating security training as a once-a-year event

A single annual video changes little. Do instead: run short, regular training and phishing simulations based on real threats, make it easy to report suspicious messages, and thank people who report. See building a security awareness training program.

9. Forgetting your suppliers

IT providers, software vendors and contractors often have remote access to your systems or hold your data. Do instead: keep a list of suppliers with access, require multi-factor authentication and security commitments in contracts, remove access that is no longer needed, and ask how they would notify you of an incident.

10. Believing you are too small to be a target

Many attacks are automated and opportunistic. They scan for any exposed system or stolen password, regardless of company size. Smaller organizations are often easier to compromise and can be a route into larger customers. Do instead: use the NIST Cybersecurity Framework or CISA's guidance as a checklist and fix the gaps in order of risk.

Quick self-assessment

  • MFA is required for email, remote access, cloud apps and admins.
  • Updates install automatically or within an agreed window.
  • We know which systems reach end of support in the next 18 months.
  • EDR is deployed and alerts are monitored.
  • We have an offline or immutable backup and tested a restore this quarter.
  • Daily work is done without administrator rights.
  • SaaS security settings and audit logs have been reviewed.
  • We have a written, rehearsed incident response plan.
  • Staff receive regular training and can report phishing easily.
  • Supplier access is listed and reviewed.

Limitations

This list is a starting point, not a full security program. Regulated sectors (health, finance, education) and organizations holding sensitive data usually need more, such as formal risk assessments, network segmentation and centralized logging.

Next step

A security assessment shows which of these gaps apply to you and which to fix first. Our cybersecurity services then help close them, with 24/7 monitoring and support for managed-service clients.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Secure Our World, Cybersecurity and Infrastructure Security Agency (CISA)
  2. #StopRansomware guidance, Cybersecurity and Infrastructure Security Agency (CISA)
  3. Known Exploited Vulnerabilities Catalog, Cybersecurity and Infrastructure Security Agency (CISA)
  4. NIST Cybersecurity Framework, National Institute of Standards and Technology (NIST)

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in USD before any work starts