What a protection system is
Ask for «cyberattack protection» and you will get a list of technologies: antivirus, firewall, monitoring. Necessary — and insufficient. A protection system answers two questions at once: how to make a successful attack unlikely, and what happens to the business if it succeeds anyway. The second question is less comfortable, so it is usually skipped.
A third of successful attacks arrive through contractors and partners, and about as many start with stolen credentials. Both routes walk past your perimeter — regardless of how much it cost.
The technical half: basic hygiene
- Patching: most attacks exploit long-known vulnerabilities with available fixes.
- Multi-factor authentication wherever there is remote access or admin rights.
- Backups on the 3-2-1 rule with an isolated copy (details in the ransomware readiness article).
- Network segmentation and least-privilege access.
- Monitoring and logging: you cannot stop an attack you cannot see.
Organizational measures: cheaper and heavier
The most underrated part of protection costs almost nothing, because it is done within existing salaries:
- An incident playbook — who isolates, who decides, who calls lawyers and the insurer.
- Pre-drafted communications — what to tell staff, clients and the press in the first hours. Companies that go silent or contradict themselves lose more on reputation than on downtime — see why companies hide cyberattacks.
- Training people — phishing remains the main entry door; an hour per quarter measurably lowers click rates.
- Contractor requirements — access rules, VPN, a duty to report incidents.
The second half: surviving a successful attack
Assume the attack got through. From that moment four things decide the outcome: isolated backups, a rehearsed recovery plan, manual workarounds for critical operations, and ready communications. This is business continuity — the discipline that starts where security tooling ends. The good news: this half is mostly organizational, built with management will rather than a hardware budget.
Counting protection in money
A security budget becomes defensible when two numbers stand next to each other: the cost of one hour of downtime for key processes, and the current realistic recovery time. We put them on one screen — the resilience dashboard shows a 0-100 index, the price of downtime and weak spots. With that screen, the budget conversation turns into an investment decision: you can see where one dollar of protection saves ten dollars of losses — and where you are already over-insured and can stop spending.
FAQ
Where should a small business start? Four nearly free steps: multi-factor authentication, patching, one isolated copy of critical data, a one-page incident playbook.
How much should we spend? Anchor on the cost of downtime, not on a percentage of the IT budget: price one day of full stop (method here) and compare it with the price of measures that shorten it.
We outsourced security — are we covered? The vendor covers the technical half. Responsibility for the second half — recovery, workarounds, communications — does not transfer with the contract.