7 min read
The controls that stop most attacks
- Multi-factor authentication on email, remote access and any admin account — this alone blocks the majority of account takeovers
- Automatic patching for operating systems, browsers and key applications
- Endpoint protection that is actually monitored, not just installed
- Backups following the 3-2-1 rule, with a restore tested at least twice a year
- Least-privilege accounts: day-to-day users should not be local administrators
- Regular short phishing awareness training rather than an annual slide deck
Telecoms-specific risks
Phone systems are a target too. Toll fraud — where an attacker compromises a VoIP account and dials premium international numbers overnight — can produce a five-figure bill in a weekend.
Protect against it with strong SIP credentials, international dialling barred by default, spend caps, and alerting on unusual call patterns. SIM swap fraud is the mobile equivalent: add a port-out PIN and account-level authentication with your provider.
Cyber Essentials and why it's worth it
Cyber Essentials is a UK government-backed scheme covering five basic technical controls. It's inexpensive, often required to bid for public sector and larger corporate work, and it forces you to fix exactly the gaps attackers exploit.
If something happens
- Have a written incident plan with named contacts and out-of-hours numbers
- Know your reporting obligations — the ICO must be told of a qualifying personal data breach within 72 hours
- Keep an offline copy of the plan; you may not be able to open the shared drive
Key takeaways
- MFA, patching and tested backups prevent most SME incidents
- Bar international dialling and set spend caps to prevent toll fraud
- Cyber Essentials is a cheap way to prove and improve your baseline
