Most small business owners assume they’re too small to be a target. Attackers count on that assumption.
Vulnerability rarely announces itself. It shows up as small, ignorable details: an odd email, a login alert nobody asked for, a patch that never got installed.
Here are five signs your business is vulnerable to cyber threats, and what to do about each one.
1. You’ve received unexpected password reset emails
Unsolicited “someone tried to sign in” or password reset emails are a sign someone is probing your accounts. Don’t ignore them.
One alert is noise. A pattern is reconnaissance. Check the sign-in logs in Microsoft 365 or Google Workspace and look at the location and device behind the attempt.
If an attempt succeeded, reset the password, revoke active sessions, and check the mailbox for a forwarding rule you didn’t create. Hidden forwarding rules are one of the first things an attacker adds and one of the last things anyone thinks to look for.
2. Your employees are getting strange phishing emails
If your team is reporting unusual emails, especially ones that seem to know your company name, vendors, or internal processes, attackers may have already done reconnaissance on your business.
Generic spam is broadcast. Mail that names your suppliers, matches your invoice format, or references a project in progress is targeted. Targeting means somebody did homework, sometimes from inside a mailbox they already had access to.
Ask the obvious question about any suspicious message: could the details in this email only have come from a conversation someone else was reading?
3. You haven’t patched your systems in over 30 days
Unpatched systems are the #1 entry point for ransomware. If you don’t have automated patching in place, you’re leaving the door open.
Nobody needs an unknown vulnerability when a known one has been sitting exposed for a month. Once a vendor ships a fix, the details of what it fixed are public, and so is the roadmap for anyone who wants to attack the machines that haven’t installed it.
Patching also has to cover more than Windows. Browsers, firmware, firewalls, VPN appliances, and line-of-business applications all ship security updates. The device at the edge of your network is usually the one nobody remembers to check.
4. You don’t have MFA enabled everywhere
Multi-factor authentication stops the vast majority of credential-based attacks cold. If any of your business accounts, including email, banking, and cloud tools, don’t require MFA, fix that today.
Everywhere means everywhere: email, VPN, remote desktop, payroll, banking, and every administrator account. One account without it is the account that gets used.
Where you have the choice, use an authenticator app or a hardware key rather than SMS codes.
5. You’ve never had a security audit
If you don’t know your attack surface, you can’t defend it. A basic security audit reveals misconfigurations, open ports, and vulnerable software before attackers find them.
It also surfaces the things that accumulate quietly: the remote desktop port someone opened for a weekend and never closed, a former employee’s account that is still active, a backup job that stopped completing weeks ago, a shared administrator password three people know.
None of that is exotic. It is just invisible until someone goes looking.
What to do if you recognized your business here
Start with what costs nothing. Turn MFA on everywhere today, and treat unexpected password reset alerts as an incident rather than an annoyance.
Then close the gaps that need someone watching them: patching on a schedule, monitoring that runs at 2am, and a recovery plan you have actually tested. That is what managed cybersecurity is for. The work only counts if it happens every day, not once a quarter.
Not sure where you stand? Talk to NEBIS — we’ll show you exactly what an attacker would see, and what to fix first.