I asked a twenty eight person construction firm to pull up their software renewal list last spring. Seventeen line items. Four of them were overlapping security tools nobody in the office could name the owner of.
That’s the pattern I keep running into. Owners aren’t cheap about security. They’re just buying it in the wrong order, one invoice at a time, usually after a scare or a sales call. The good news is that the fix isn’t a bigger budget. It’s a better sequence: find the money you’re already spending, close the gaps that actually get exploited, then decide what’s worth adding.
Below is the order I’d use if I were sitting at your desk, plus the specific things to look at in each step.
What actually gets a small business breached?
Not exotic hacking. The FBI Internet Crime Complaint Center has documented for years that phishing and similar social engineering tactics dominate reported complaints by volume. Read that against your own shop and the implication is uncomfortable: your biggest exposure probably isn’t your firewall. It’s a person in accounting clicking a link that looks like a shipping notice.
Every security conversation I have starts here, because it changes what you buy first. If the realistic attack path runs through your people, then spending your next dollar on another endpoint agent while nobody has ever been shown a real phishing email is backwards. You’d be buying a better lock for a door that’s already propped open.
And no, a yearly slideshow during onboarding doesn’t count. I mean someone actually testing your team, then telling them what they missed. If your current provider has never sent a fake invoice to your staff to see who bites, ask why. That’s the honest ordering problem. Training feels soft and hard to measure. Tools come with a dashboard that looks like progress. Dashboards don’t stop clicks.
Run this thirty minute renewal audit
Before you approve another security line item, open your card statement and your software list side by side.
- Write down every recurring charge with the words security, backup, monitoring, endpoint, or protection in it.
- Next to each one, name the person who can log in and configure it. Blank means nobody.
- Mark anything you bought during a scare and haven’t opened since.
- Note the renewal date and the last time anyone reviewed those terms.
What you’re looking for is gaps and duplicates, and I promise you have both. Two tools doing endpoint protection is common. So is a backup product nobody has ever restored from. That second one is worse than not having it, because you’re paying monthly for a false sense of safety.
I’d rather see you consolidate three overlapping subscriptions into one properly managed service than add a fourth tool to the pile. Fewer moving parts, one throat to choke when something breaks at 11pm.
If you’re doing this and you keep hitting questions you can’t answer, that’s usually the signal to bring in outside help. Cybersecurity Services for Businesses run by a team that does this daily will generally catch the configuration gaps you can’t see from the admin console. Worth it, if only to get a straight answer about what you already own.
The boring controls that stop most attacks
Here’s where I get contrarian with vendors. Multi factor authentication on email and your financial systems does more for you than almost any product you can buy this quarter. So does patching on a schedule you can actually keep. So does restricting who can approve a wire transfer, and giving new employees a short leash on money moving until they’ve been around a while.
None of those come in a box. All of them close doors attackers walk through. According to the National Institute of Standards and Technology, a structured framework for identifying, protecting, detecting, responding, and recovering is the accepted baseline for managing this work. You don’t need to read the whole thing. You need to be able to say out loud who does each of those five things at your company. If the answer for three of them is “our IT guy, probably,” you’ve just found your gap list.
I’d rank them in this order for a small firm: get MFA turned on everywhere, fix your patching, write down what happens when someone leaves the company, then test your backups by restoring one. That last step takes an afternoon and tells you whether your backup vendor is selling you storage or recovery. Those aren’t the same product, and I’ve watched owners learn that distinction the hard way.
When to bring in outside help, and what to ask
You don’t need a security team on payroll. You do need someone whose job is to look at this monthly instead of when something breaks. The U.S. Small Business Administration points owners toward outside expertise as a normal part of small business risk management, which lines up with what I see: firms that review this quarterly catch problems while they’re still small.
When you interview a provider, skip the product tour. Ask four questions:
- What did the last assessment you ran turn up, in plain language?
- Who on your team will actually be assigned to us, by name?
- If we get hit, what do you do in the first hour, hour by hour?
- What happens to our costs if we say no to your recommendations?
The fourth question is the one that separates a partner from a reseller. A partner can live with a no. A reseller can’t, and you’ll hear it in the answer.
What I’d do first if this were my company
Tonight, open the card statement and start the renewal list. That’s it. Thirty minutes.
Then turn on MFA for email and banking, in that order, and get somebody to test your team with a realistic phishing email inside a month. After that, sit down with whoever touches your systems and write down who owns each of those five framework areas. The blanks become your to do list, and honestly, they’re usually shorter than owners expect.
Budget follows clarity. Most of the firms I’ve watched get this right didn’t spend more. They stopped paying twice for the same thing. So here’s the question to sit with: if you had to name the person who’d notice a breach at your company on a Tuesday afternoon, could you? If not, you just found your first hire, your first call, or your first real conversation with your current provider.




