What a security baseline actually costs a 30-person business
Almost nothing that happens to a New Zealand SME is sophisticated. It is a phishing email, a machine nobody patched, a password that never changed, or a laptop on cafe wifi. The controls that stop those are cheap and boring.
By the ICS engineering team July 2026 7 min read
Security gets sold to small businesses the wrong way round. The pitch usually opens with the most advanced product the vendor sells, because that is where the margin is. What a thirty-person company actually needs is the unglamorous set of controls that close the routes attackers genuinely use.
Here is what those routes are, and the order we would fix them in.
How organisations this size actually get hit
Social engineering, mostly phishing. An email that is not always easy to tell apart from a genuine one persuades somebody to hand over information or click something. This is the most common form of attack, and it works because it targets a person rather than a system.
Malicious code. Viruses and worms that self-replicate and damage files without the user knowing. Spyware and trojans used to collect data quietly. Ransomware, which waits, encrypts everything, and demands payment for access to your own information. It usually arrives as an unsolicited attachment or a download that looks legitimate.
Man in the middle. An attacker inserts themselves between a device and a server. This most often happens when somebody logs in over insecure public wifi, and the user passes their information through the attacker without knowing.
Unpatched software. Out-of-date systems give attackers known vulnerabilities to work with. A zero-day attack occurs when a vulnerability becomes public before the developer has shipped a fix, and unpatched estates are where that does the most damage.
Denial of service. Flooding a system or server with more requests than it can handle to take a site offline. Less common at this size, but expensive when it lands on a business that trades online.
The four things to do first
These are the controls we put in before anything else, because they close the most exposure for the least money.
-
Verify the backups by restoring one
Not by checking that the backup job reports success. Actually restore a file and open it. A surprising number of businesses discover at exactly the wrong moment that their backups have been failing silently for months.
-
Patch everything, on a schedule
Operating systems, applications, firmware on the firewall and switches. Updates contain the fixes for the security issues attackers are actively using. Cyberattacks thrive on outdated devices.
-
Review who can access what
Almost every business we audit has accounts belonging to people who left, and staff holding administrative rights they were given once for a specific job. This costs nothing to fix and removes a large amount of risk.
-
Train the staff on the four habits
Only trust HTTPS addresses when entering anything sensitive. Do not open attachments or links from unknown sources. Keep devices updated. Back up files regularly. These four cover the large majority of real incidents.
What comes after that
Once the four above are genuinely done, the next layer is worth buying: firewall and endpoint protection properly configured rather than installed and forgotten, encryption on devices that leave the building, and a security assessment with vulnerability testing to find what is specific to your environment.
At ICS we also write a technical job description for each role, setting out what that person can access on their machines. It is a short document and it prevents a disproportionate number of problems, mostly by making access decisions explicit instead of accidental.
The point about foundations
The most effective way to reduce the impact of an attack is to build a solid foundation and then grow the security stack on top of it. A proper foundation identifies the gaps that are actually there and tells you what to do about each one, in order.
Buying an advanced product before that foundation exists is how businesses end up spending real money and remaining exposed to a phishing email.
Start with the audit
We will tell you which of the four are already in place and which are not, whether or not you engage us afterwards.