SMEs in the Crosshairs of Cybercriminals
In the popular imagination, cyberattacks only hit large corporations and multinationals. The reality is dramatically different: according to the Clusit 2026 Report, 67% of cyberattacks in Italy target small and medium-sized enterprises. The reason is simple: SMEs hold valuable data (customers, suppliers, financial data, intellectual property) but invest far less in security than large companies.
The numbers are alarming. In 2025, Italy recorded more than 2,800 significant cyberattacks, a 23% increase on the previous year. The average cost of a data breach for an Italian SME is estimated at €120,000–€180,000, factoring in system recovery, lost productivity, reputational damage, and GDPR fines. For many small businesses, a serious cyberattack can mean closure.
The good news is that the majority of attacks exploit avoidable vulnerabilities. By following the 10 golden rules presented in this guide, SMEs can reduce their attack risk by 80–90% with modest investment.
Rule 1: Password Management and Authentication
Weak or reused passwords are the number-one attack vector. According to Verizon, 81% of hacking-related breaches exploit stolen or weak passwords.
Password Best Practices
- Business password manager: implement a password manager such as Bitwarden (business version from $3/user/month) or 1Password Business ($7.99/user/month). Each employee gets a personal vault and access to shared team vaults
- Unique passwords: every service must have a unique password, generated by the password manager (minimum 16 characters, alphanumeric + symbols)
- Never use personal passwords for business services: company credentials must be kept separate from personal ones
- Controlled rotation: updated NIST guidelines advise against frequent forced rotation (which leads to predictable passwords); better to use strong passwords and change only when compromise is suspected
Two-Factor Authentication (2FA/MFA)
Two-factor authentication is the single most effective measure for preventing unauthorised access. According to Microsoft, 99.9% of account attacks are blocked by MFA.
- Mandatory on all critical services: email, cloud, CRM, ERP, online banking, hosting, DNS
- Preferred method: authenticator app (Google Authenticator, Microsoft Authenticator, Authy) or hardware keys (YubiKey)
- Avoid SMS: SMS-based authentication is vulnerable to SIM swapping; use it only as a fallback
- Recovery keys: store recovery codes in a safe place (not in the password manager itself)
Implementation cost: the password manager costs €3–€8/user/month. Authenticator apps are free. For 20 employees, the annual investment is €720–€1,920. The cost of a single breach: €120,000+. The cost-benefit ratio is overwhelming.
Rule 2: Regular and Tested Backups
Backup is the last line of defence against ransomware, human error, and hardware failure. But an untested backup is a backup that doesn’t exist.
The 3-2-1-1-0 Rule
The evolution of the classic 3-2-1 rule:
- 3 copies of data (original + 2 backups)
- 2 different media (e.g. local disk + cloud)
- 1 off-site copy (in a different physical location or in the cloud)
- 1 offline/immutable copy (unreachable by ransomware that encrypts connected backups)
- 0 verified errors (regular restore testing)
Backup Solutions for SMEs
| Solution | Indicative Cost | Pros | Cons |
|---|---|---|---|
| Local NAS + Cloud | €500–€2,000 (NAS) + €50–€200/month (cloud) | Fast, comprehensive | Requires management |
| Managed cloud backup | €100–€500/month | Zero management | Dependent on internet connection |
| Veeam / Acronis | €50–€150/server/month | Professional, reliable | Configuration complexity |
Restore Testing
Restore testing is the most neglected and most important part. At least once per quarter, perform a test restore to verify that backups are intact and that recovery times are acceptable. Document the procedure so that anyone can execute it, even in the absence of the IT lead.
Rule 3: Staff Training
The human factor is responsible for 90% of security incidents. No technology can protect against an employee who clicks a phishing link or opens a malicious attachment.
Security Awareness Programme
- Initial training: every new employee receives basic cybersecurity training (2–3 hours)
- Quarterly updates: 30–60 minute sessions on current threats, new phishing techniques, and best practices
- Phishing simulations: periodic simulated phishing emails to test employee awareness. Tools like KnowBe4 or GoPhish automate these simulations
- Written policies: company policy on device use, passwords, email, and internet browsing
What to Teach Employees
- How to recognise phishing emails (suspicious sender, urgency, shortened links, unexpected attachments)
- Never open attachments from unknown senders
- Verify payment or fund transfer requests by phone (BEC attack — Business Email Compromise)
- Never enter company credentials on sites reached via email links
- Immediately report any suspicion to the IT lead
- Never use found or unsolicited USB drives
- Lock the computer when leaving the workstation
Cost: security awareness training platforms start from €20–€40/user/year. For 20 employees: €400–€800/year. A single BEC attack (CEO fraud) can cost tens of thousands of euros.
Rule 4: Timely Software Updates
Unpatched software vulnerabilities are the most common entry point for attacks. The Log4Shell vulnerability exploit in 2021 hit millions of systems worldwide, many of which had not applied a patch available for weeks.
What to Update and When
- Operating system: security updates applied within 48 hours of release, for both servers and workstations
- Application software: browsers, Office, PDF readers, email clients updated automatically
- CMS and plugins: WordPress, plugins, and themes updated weekly. 39% of WordPress vulnerabilities come from unpatched plugins
- Firmware: routers, firewalls, NAS, and network devices updated monthly
- EOL (End of Life) software: immediately replace software that no longer receives security updates (e.g. Windows 10 after October 2025)
Centralised Update Management
For SMEs with more than 10 workstations, a centralised patch management system like Microsoft Intune, NinjaOne, or Atera is recommended. Cost: €3–€8/device/month.
Rule 5: Firewall and Network Protection
The firewall is the first barrier between the corporate network and external threats. For SMEs, a next-generation firewall (NGFW) offers advanced protection at accessible costs.
Firewalls for SMEs
| Solution | Indicative Cost | Supported Users | Features |
|---|---|---|---|
| pfSense/OPNsense | Free (hardware separate) | Unlimited | Open source, requires expertise |
| Fortinet FortiGate 40F | €500–€800 + annual licence | Up to 25 | Professional, full UTM |
| WatchGuard Firebox T25 | €600–€900 + annual licence | Up to 25 | Easy management, good value |
| Sophos XGS 87 | €700–€1,000 + annual licence | Up to 30 | Endpoint integration, AI-driven |
Secure Network Configuration
- Segmentation: separate the network into zones (offices, servers, guest Wi-Fi, IoT) to limit the lateral spread of attacks
- Wi-Fi: corporate Wi-Fi with WPA3 and a separate guest network, without access to the internal network
- DNS filtering: block access to malicious sites at DNS level (services like Cisco Umbrella or Cloudflare Gateway)
- Traffic monitoring: IDS/IPS (Intrusion Detection/Prevention System) to identify anomalous traffic
Rule 6: Antivirus and Endpoint Protection
Traditional antivirus is no longer enough. SMEs should adopt Endpoint Detection and Response (EDR) solutions that combine antivirus, behavioural analysis, and automatic incident response.
EDR Solutions for SMEs
- Microsoft Defender for Business: included in Microsoft 365 Business Premium (€20.60/user/month), excellent value for those already in the Microsoft ecosystem
- CrowdStrike Falcon Go: from $59.99/year for 5 devices, enterprise-grade protection
- Sophos Intercept X: from €28/user/year, excellent integration with Sophos firewalls
- Bitdefender GravityZone: from €20/device/year, good entry-level solution
The key is choosing a solution that offers: real-time protection, behavioural analysis (not just signature-based), centralised management, reports and alerts, and firewall integration.
Rule 7: VPN for Secure Remote Access
With hybrid working now standard, remote access to company systems must be protected with a VPN (Virtual Private Network).
VPN Types for SMEs
- Site-to-site VPN: permanent connection between different company locations
- Client-to-site VPN: employee access to the corporate network from remote
- Firewall-integrated VPN: the simplest solution, already included in NGFW firewalls
- Zero Trust Network Access (ZTNA): the evolution of VPN, which verifies identity and device before granting access to each individual resource
VPN Best Practices
- MFA mandatory for VPN connection
- Split tunnelling only if necessary (full tunnel preferred for maximum security)
- Client certificates for additional authentication
- Monitoring of VPN connections to identify anomalous access
- Automatic timeout for inactive sessions
Rule 8: Incident Response Plan
When (not if) a security incident occurs, having a predefined response plan can make the difference between a manageable inconvenience and a business catastrophe.
Elements of an Incident Response Plan
- Identification: how to recognise an incident (indicators of compromise, alerts, user reports)
- Containment: immediate actions to limit the damage (isolating the compromised machine, disconnecting from the network)
- Eradication: eliminating the threat (malware removal, closing backdoors, changing compromised passwords)
- Recovery: return to normal operations (restore from backup, system integrity verification)
- Lessons learned: post-incident analysis to improve defences
Emergency Contacts
The plan must include contacts to call in the event of an incident:
- Internal IT lead (or external IT partner)
- Cybersecurity provider / CSIRT
- Legal / DPO for data protection authority notification (mandatory within 72 hours for personal data breaches under GDPR)
- Law enforcement (in the event of a criminal offence)
- Cyber insurance provider (if applicable)
Rule 9: GDPR and NIS2 Compliance
Regulatory compliance is not just a legal obligation but a useful framework for structuring corporate security.
GDPR: Obligations for SMEs
- Record of processing activities: a document listing all personal data processing activities carried out by the company
- Privacy notices: for customers, employees, suppliers, and website visitors
- Security measures: technical and organisational measures appropriate to the risk (encryption, access control, backup)
- Data breach notification: notification to the supervisory authority within 72 hours and to data subjects in the event of high risk
- DPO: mandatory only for certain categories of organisations, but recommended for all
- DPIA: mandatory data protection impact assessment for high-risk processing
GDPR fines: up to €20 million or 4% of global turnover. In 2025, the Italian Data Protection Authority issued fines totalling over €30 million, many of them to SMEs for inadequate security measures.
NIS2 Directive: What Changes for SMEs
The NIS2 Directive (Network and Information Security), transposed in Italy in 2024 with progressive application, extends cybersecurity obligations to a much larger number of companies than the previous NIS:
- Who is covered: companies with more than 50 employees or turnover above €10 million in sectors deemed critical or important (energy, transport, healthcare, digital infrastructure, food manufacturing, waste management, postal services, chemicals, but also digital and ICT service providers)
- Key obligations: risk analysis, security policies, incident management, business continuity, supply chain security, training
- Management responsibility: NIS2 introduces personal liability of top management for cybersecurity
- Fines: up to €10 million or 2% of global turnover
Rule 10: Cyber Insurance
Cyber insurance is the final safety net. Even with all preventive measures in place, residual risk exists, and a specific insurance policy can cover the costs of an incident.
What Cyber Insurance Covers
- Recovery costs: expenses for restoring systems and data after an attack
- Business interruption: lost revenue during system downtime
- Legal costs: legal expenses for data breach management and notifications
- GDPR fines: some policies cover fines (where legally permissible)
- Ransomware ransom: coverage for ransom payment (controversial but available)
- Crisis management: crisis communications and reputation management costs
- Third-party liability: damages to clients or partners resulting from the breach
Cyber Insurance Costs
For an SME with turnover between €1 and €5 million:
- Annual premium: €1,000–€5,000 for coverage of €250,000–€1,000,000
- Requirements: most insurers require minimum security measures (antivirus, backup, MFA) as a policy condition
- Insurers: Zurich, Generali, AXA, Hiscox, Coalition offer specific SME products
Real-World Examples of Attacks on SMEs
To understand the severity of the threat, here are some real scenarios (anonymised) of attacks on Italian SMEs:
Case 1: Ransomware on an Accounting Firm
An accounting firm with 12 employees suffered a ransomware attack that encrypted all files, including backups on a network-connected NAS. The ransom demanded was €50,000 in Bitcoin. Without off-site backups, the firm lost 3 months of work and had to manually reconstruct financial statements and tax returns. Total estimated cost: €180,000 including lost productivity, extra work, reputational damage, and client notifications.
Lesson: an off-site/immutable backup would have reduced the attack to an inconvenience of a few hours.
Case 2: Business Email Compromise on a Manufacturing Company
A manufacturing company with 40 employees received an email apparently from their Chinese supplier, communicating a change of bank details. The accounts department transferred €85,000 to the new account. Only a week later, upon contacting the supplier for a payment reminder, was it discovered that the email was fake. The funds, immediately transferred to foreign accounts, were not recovered.
Lesson: a simple verification phone call to the supplier would have prevented the fraud.
Case 3: Phishing on an E-Commerce Business
An e-commerce business with 8 employees had their admin credentials stolen through a phishing page replicating the hosting provider’s login panel. The attacker installed a web skimmer that stole the credit card details of 1,200 customers over 3 weeks before the problem was discovered. Cost: customer notification, forensic investigation, Data Protection Authority fine, lost customers. Total estimated: €95,000.
Lesson: MFA on the hosting account would have prevented access even with stolen credentials.
How Much Security Costs vs How Much an Attack Costs
| Security Measure | Annual Cost (20 users) | What It Prevents |
|---|---|---|
| Password manager + MFA | €1,000–€2,000 | Credential theft, unauthorised access |
| Managed backup (3-2-1-1-0) | €2,000–€5,000 | Ransomware, data loss |
| Security awareness training | €500–€1,000 | Phishing, social engineering |
| Managed EDR/antivirus | €1,000–€3,000 | Malware, ransomware, APT |
| NGFW firewall | €1,500–€3,000 | Intrusions, malicious traffic |
| VPN + secure access | €500–€1,500 | Remote data interception |
| Cyber insurance | €1,500–€4,000 | Financial coverage for incidents |
| Total prevention | €8,000–€19,500/year | |
| Average cost of an attack | €120,000–€180,000 |
The investment in prevention is 6–22 times lower than the cost of a single incident. And an incident is not a rare event: according to statistics, one in four SMEs will suffer a significant cyberattack in the next 2 years.
FAQ: Frequently Asked Questions About Cybersecurity for SMEs
Is my company too small to be a target?
No. The majority of attacks are automated and untargeted: criminals launch phishing campaigns and vulnerability scans against millions of targets, hitting anyone who is vulnerable. An SME with weak defences is an easier and more profitable target than a large company with a dedicated SOC. Moreover, SMEs are often used as an entry point for attacking their larger clients or suppliers (supply chain attack).
I don’t have an IT department: how can I manage security?
There are Managed Security Service Provider (MSSP) services that provide managed security for SMEs without internal IT departments. These services include 24/7 monitoring, firewall and antivirus management, managed backup, incident response, and consultancy. Costs range from €500 to €2,000/month depending on complexity, significantly less than a dedicated internal IT employee. UreTech offers IT management and security services designed for SMEs.
Should I pay the ransom in the event of ransomware?
The unanimous recommendation of the authorities (national cyber agencies, ENISA, law enforcement) is to not pay the ransom. Paying does not guarantee data recovery (in 20% of cases, data is not returned), it finances criminal activity, and it marks the company as a target for future attacks (“who pays once, pays again”). The real protection is having functioning, tested backups that allow recovery without giving in to extortion.
Does GDPR apply to my small company too?
Yes, GDPR applies to any organisation that processes personal data, regardless of size. Even a freelancer with a mailing list of 50 contacts must comply with GDPR. Fines are proportionate to the size of the company, but they exist and can be significant. The good news is that basic GDPR compliance is achievable with a modest investment and represents good security practice.
How often should I update security measures?
Cybersecurity is not a project with an end date but a continuous process. Software updates should be applied weekly, staff training should be at least quarterly, policies should be reviewed annually, and backup tests and incident response plans should be verified at least every 6 months. Threats evolve constantly, and defences must evolve with them.
Does NIS2 apply to my SME?
NIS2 applies to companies with more than 50 employees or with turnover above €10 million operating in specific sectors (energy, transport, healthcare, digital infrastructure, food, chemicals, manufacturing, postal services, waste management, ICT services). Even if your SME is not directly covered, you may be involved as a supplier to a NIS2-regulated company, which will need to verify the security of its supply chain. It is therefore advisable to comply preventively with the directive’s requirements.
Conclusion
Cybersecurity is not a luxury reserved for large companies: it is a survival necessity for every SME. The 10 points in this guide represent a practical, implementable framework that can drastically reduce the risk of cyberattacks with an investment proportionate to the company’s size.
The right approach is not paranoia but awareness: know the risks, implement proportionate defences, and have a plan for when something goes wrong. Like fire insurance, you hope you’ll never need it, but not having it is irresponsible.
At UreTech we offer cybersecurity consultancy and implementation services designed for SMEs: from initial assessment to measure implementation, from staff training to ongoing management. Contact us for a free security assessment of your company: we will identify the most critical vulnerabilities and propose a prioritised action plan. Also visit our services and portfolio.