European Cybersecurity Month: practical steps to protect your SME
Discover the mistakes SMEs should avoid, how to build cyber resilience and how L-DIH services can help. Practical guidance for European Cybersecurity Month
Cybersecurity is often treated as a technical issue, but for SMEs an incident can quickly become a business problem. A phishing email can compromise an account. A ransomware attack can interrupt operations. An untested backup can delay recovery. Even a short disruption may affect customers, suppliers, revenue and reputation.
To mark European Cybersecurity Month, the Luxembourg Digital Innovation Hub (L-DIH) asked Anitha Arulrajakumar, expert from the Luxembourg House of Cybersecurity (LHC), to answer practical questions about the risks SMEs face and the steps they can take to improve their resilience.
European Cybersecurity Month takes place every October. Coordinated by the European Union Agency for Cybersecurity (ENISA) with participating European countries, it provides an opportunity to make cybersecurity a company-wide responsibility rather than a topic reserved for IT teams. Even one focused activity can help turn awareness into a repeatable practice throughout the year.
Several organisations also hold events during Cybermonth. SMEs can consult this page to find an activity that matches their needs.
Three common mistakes SMEs make with cyberthreats
- Assuming they are too small to be targeted: cyberattacks are often opportunistic. Phishing, credential attacks and ransomware can affect organisations of any size. SMEs may also provide an entry point into larger customers or supply chains. Artificial intelligence (AI) has further increased the speed and scale of attacks while making phishing and social engineering more convincing.
- Relying on technology without processes: antivirus software, firewalls and backups do not automatically make an organisation resilient. Gaps often remain around secure configurations, employee awareness, multi-factor authentication, password management, patching, backup testing and incident response.
- Depending on one person: cybersecurity may rely heavily on a single employee or external provider. If procedures are undocumented, the organisation may struggle to respond or recover when that person is unavailable or an incident occurs.
Three easy steps to strengthen data security
- Enable multi-factor authentication: prioritise email, cloud applications, administrator accounts and remote access. A stolen password should not be enough to access company information.
- Identify what matters most: maintain a simple inventory of devices, applications and important information. Identify the data whose loss, disclosure or unavailability would create the greatest operational, financial, contractual or reputational impact.
- Back up and test recovery: maintain multiple, separate backups of critical information. Test regularly that they can be restored, since an untested backup should not automatically be considered recoverable.
Finding the right cybersecurity partner
An SME should first understand its needs rather than start by purchasing a security product. A suitable cybersecurity partner should understand the company's business, critical information, IT environment and risks before recommending solutions.
SMEs should look for a partner who:
- assesses the environment before recommending solutions
- understands the company's sector and regulatory obligations
- defines responsibilities between the SME and the provider
- provides transparent service levels and escalation procedures
- supports both prevention and incident response
Outsourcing IT or cybersecurity does not outsource the company's risk. Management should retain visibility over what is being protected and how. The Network and Information Security Directive (NIS2) and the Digital Operational Resilience Act (DORA) reinforce the importance of management accountability and oversight for organisations within their scope.
Building cyber resilience beyond prevention
Good cybersecurity starts with fundamentals such as multi-factor authentication, strong passwords, endpoint protection, network segmentation and reliable backups. Resilience also means preparing for the moment when preventive controls fail.
Every SME should be able to answer a few basic questions:
- Who do we call if a ransomware attack happens tomorrow?
- How do employees report an incident?
- Can we continue operating without our main server?
- How quickly can we restore our data?
- Who contacts customers or suppliers if necessary?
If the answers are unclear, the organisation still has resilience work to do. Cyber resilience does not mean preventing every attack. It means reducing the likelihood of an incident, detecting it quickly, limiting its impact and recovering the business.
How L-DIH can help SMEs
The L-DIH and LHC offer three services that help SMEs assess their current position, identify priorities and prepare for an incident.
- Light Cybersecurity Assessment: a 30-minute online assessment that provides an initial view of an organisation's cybersecurity maturity and recommendations for improvement.
- Deep Cybersecurity Assessment: a four-hour workshop that examines the organisation's risks in greater detail and supports the development of a tailored action plan.
- Crisis Management Readiness Assessment: a four-hour exercise using Room#42, a simulated cyberattack scenario for management teams. Participants respond to a crisis and receive a debrief highlighting areas for improvement.
SMEs looking for additional support can explore the full range of available services on the L-DIH Marketplace, or contact L-DIH directly to discuss their cybersecurity needs.