Critical IT Issues for Small Businesses

The critical IT issues in a small business are rarely exotic. They’re a backup nobody has restored, an admin account with no second factor, updates that have been “pending” since spring, and a billing process that trusts any email that looks like the boss. None of those make the news. All of them end businesses.

Owners tend to split into 2 groups here. The first assumes attackers only bother with large companies and runs the whole business on a laptop with a single password. The second buys a security product after a scare, never configures it, and feels covered. Both are 1 bad afternoon away from the same outcome.

What separates the businesses that recover from the ones that close is whether a few boring things were already in place before the bad afternoon.

Why Small Businesses Get Hit

Verizon’s 2025 Data Breach Investigations Report analyzed more than 22,000 incidents and 12,195 confirmed breaches. Ransomware appeared in 44% of all breaches. In breaches at small and medium businesses, it appeared in 88%. The median ransom paid was $115,000, which for a large company is a line item and for a 12-person firm is the year.

The entry points are ordinary. Stolen or guessed credentials led at 22% of breaches, and exploited software vulnerabilities followed at 20%. Third-party involvement doubled to 30%, meaning the weak link was often a vendor, a plugin, or a contractor’s account rather than the business’s own systems.

The FBI’s Internet Crime Complaint Center counted $16.6 billion in reported losses for 2024, up a third on the prior year. Business email compromise alone, the fake-invoice and fake-boss emails, accounted for $2.77 billion across 21,442 complaints. That’s about $129,000 per incident, and most of those incidents needed no hacking at all. Someone replied to the wrong email.

Small businesses aren’t targeted because they’re valuable. They’re targeted because they’re easy.

What the Breach Data Shows

Two annual reports cover most of what a small business needs to know, and they agree with each other. Verizon’s Data Breach Investigations Report examined more than 22,000 incidents and 12,195 confirmed breaches for its 2025 edition. The FBI’s Internet Crime Complaint Center logged 859,532 complaints and $16.6 billion in reported losses for 2024, a third more than the prior year.

FindingFigureSource and data year
Ransomware in breaches at small and mid-size businesses88%Verizon DBIR, 2025 edition
Ransomware in breaches at organizations of every size44%Verizon DBIR, 2025 edition
Median ransom actually paid$115,000Verizon DBIR, 2025 edition
Victims who refused to pay64%, up from 50% two years earlierVerizon DBIR, 2025 edition
Breaches starting with stolen or guessed credentials22%Verizon DBIR, 2025 edition
Breaches starting with an exploited vulnerability20%Verizon DBIR, 2025 edition
Breaches involving a third party30%, double the prior yearVerizon DBIR, 2025 edition
Median time from break-in to ransomware being deployed4.3 daysVerizon DBIR, 2025 edition
Business email compromise losses$2.77 billion across 21,442 complaintsFBI IC3, 2024

The BEC row works out to roughly $129,000 per reported incident, and almost none of those involved breaking into anything. Someone replied to an email and changed a payment detail.

The defense figures are just as lopsided. Microsoft has reported that multi-factor authentication blocks 99.9% of automated account-compromise attempts, and Google’s own research found that simply attaching a recovery phone to an account stopped 100% of automated bot attacks, 99% of bulk phishing, and 66% of targeted attacks. CISA cites the same research when it ranks MFA among the highest-impact controls available to any organization.

A free checkbox stops most of the attacks that end small businesses. Turn it on.

The Critical IT Issues

Every item below is cheap to fix relative to the event it prevents. The table gives the first move for each, and the sections underneath explain why that move and not the one the vendor is selling.

IssueWhat it costs when it failsFirst fix this week
Backups never restoredDays of downtime, or paying a ransomRestore 1 file from last night’s backup and time it
No second factor on admin accountsEmail, banking, and website taken over with 1 leaked passwordTurn on MFA for email, bank, domain registrar, and website admin
Updates nobody ownsKnown vulnerabilities exploited months after the patch existedName 1 person and 1 day a month for updates
Email fraud with no processA wire sent to an attacker’s account on a forged invoiceAny change to payment details gets a phone call to a known number
Too many people with too much access1 phished contractor account exposes everythingRemove admin rights from everyone who doesn’t need them today
Legacy systems nothing connects toManual re-entry, errors, and staff who quietly work around the toolList every system and what it talks to, then retire the 1 that talks to nothing
No monitoring or ownerA breach discovered by the customer, not by youTurn on login alerts for email and the website

If you do nothing else from this article, do the first 2 rows today. They cover the 2 attack paths that led the Verizon data.

Backups You’ve Never Restored

A backup is a claim until you’ve restored from it. Businesses that pay ransoms mostly had backups. They had backups on the same network that got encrypted too, or backups 3 months stale, or backups that took 4 days to restore when the business needed 4 hours. The 88% ransomware figure at small businesses is largely a backup story.

The working rule is 3 copies of the data, on 2 kinds of storage, with 1 of them offline or somewhere an attacker on your network can’t reach. Then a restore test on a calendar, quarterly at least. My roundup of the best backup software covers the options by business size, and if the business runs on WordPress, the case for a WordPress backup plugin explains why the host’s backup alone isn’t enough.

Untested means nonexistent.

Accounts Without a Second Factor

Credential abuse led the breach data for a reason that has nothing to do with clever attackers. Passwords leak from other sites, people reuse them, and the first thing anyone tries with a leaked password is the victim’s email. From email, an attacker resets everything else.

Multi-factor authentication closes that door on its own. It’s free on every service that matters, and the 4 accounts that need it first are email, the bank, the domain registrar, and the website admin. Lose any of those 4 and you lose the business’s ability to talk to customers, pay people, or exist online. A password manager such as Proton Pass removes the reuse problem at the same time, because nobody has to remember 40 unique passwords.

Updates Nobody Owns

Exploited vulnerabilities sat at 20% of breaches, and almost all of them had a patch available before the attack. The patch didn’t get applied because applying patches was nobody’s job. It was everybody’s job, which is the same thing.

The fix is a name and a date. 1 person owns updates for the website, the laptops, the router, and the plugins, and does them on the first Tuesday of the month. Where automatic updates exist, turn them on. The “if it isn’t broken, don’t fix it” rule that served your grandfather’s tractor is the exact rule that leaves a known hole open for 6 months.

Email Fraud With No Process

Business email compromise doesn’t break into anything. An email arrives from “the supplier” with new bank details, or from “the owner” asking for an urgent transfer, and someone in accounts does what the email says. $2.77 billion in 2024, by the FBI’s count, and that’s only what got reported.

The defense is a rule, not a product. Any change to payment details, and any transfer above a threshold you set, gets confirmed by phone to a number you already had on file. Not the number in the email. The rule costs 2 minutes per invoice and stops the entire category. A proper business email setup helps too, and my piece on how a business email changes customer trust covers the domain and authentication side that makes your own messages harder to forge.

Call the known number. Every time.

Too Much Access

In most small businesses, everyone is an admin because it was easier at setup. That means a phished intern account has the same power as the owner’s. The 30% third-party figure in the Verizon data is largely this: a contractor, a former employee, a plugin vendor, still holding keys nobody revoked.

Give each person the access their job needs this month, and nothing more. Review the list when someone leaves, and review it quarterly anyway.

It’s the least glamorous item on the page and the one that most often turns a small incident into a total one.

Legacy Systems

Not every critical IT issue is a security issue. The accounting package from 2014 that can’t export to anything, the spreadsheet that 3 people edit by emailing copies, the CRM nobody updates because it doesn’t talk to the email system. These don’t get breached. They leak hours, and they produce the errors that customers notice.

The test is whether a system connects to the ones around it. If data goes in by hand and comes out by hand, the tool is a filing cabinet with a subscription. Replace the 1 that’s most isolated first. And pick the replacement by whether it integrates, not by its feature list, because the feature you’ll use most is the export.

No Monitoring or Owner

Most small business breaches are discovered by someone outside the business: a customer who got a strange email, a bank that flagged a transfer, a search engine that marked the site unsafe. By then the attacker has had weeks. Monitoring doesn’t have to mean a security operations center. Login alerts on email and the website, a weekly look at who signed in from where, and 1 person whose job includes noticing.

For the fuller layered setup, my cybersecurity guide for small businesses walks through the defense stack in the order it pays to build it.

When to Bring In Help

A managed IT provider makes sense once the business has more than about 10 devices, handles customer data it would be embarrassing to lose, or has nobody inside who’ll own the list above. Below that line, the 7 fixes in the table are a weekend’s work and a monthly hour, and paying someone $1,500 a month to do them is paying for attention you could supply.

When you do hire, buy outcomes you can check. A restore test you watch. An access review you sign off. A patch report with dates on it. “Monitoring” without a monthly summary of what was seen is a retainer, not a service.

The Limits

These fixes don’t stop a determined, targeted attacker with time and money. They stop the automated, opportunistic attacks that make up nearly all of what hits small businesses, which is the point. The goal isn’t to be unbreakable.

It’s to be harder than the next business on the list, and to recover in hours when something gets through anyway.

The figures come from US and global reports, and the dollar values won’t map to every country. The pattern does. Ransomware, stolen credentials, and forged invoices are the same 3 problems in Pune as in Pittsburgh.

What Quietly Ruins It

Buying a tool instead of assigning a person. The software arrives, nobody configures it, and the dashboard nobody reads counts as coverage until the day it doesn’t.

Exempting the owner. The boss keeps the old password and skips MFA because it’s annoying, and the boss’s account is the one every attacker wants.

Treating the website as separate. The site holds customer data and sits on the same domain as the email. An unpatched plugin is a front door, whatever the rest of the setup looks like.

Doing the audit once. Access lists grow, updates lapse, and a backup that worked in January fails quietly in June. The fixes are a habit, not a project.

Waiting for a scare. The businesses that fix this after an incident pay for the incident and the fix. The ones that fix it before pay for the fix.

Final Remarks

The critical IT issues in a small business aren’t a technology problem. They’re an ownership problem. Every item on the list above is known, cheap, and documented, and it stays undone because it belongs to nobody. Assign them, calendar them, and the business becomes the one attackers skip.

You won’t notice it working. That’s what working looks like.

Tell Google you want more of this.

Add Gaurav Tiwari as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.

Disclaimer: This site is reader-supported. If you buy through some links, I may earn a small commission at no extra cost to you. I only recommend tools I trust and would use myself. Your support helps keep gauravtiwari.org free and focused on real-world advice. Thanks. - Gaurav Tiwari