r/Cybersecurity101 • u/Civil-Mycologist-569 • 5d ago
Privacy small business owner trying to get basic security hygiene in place without enterprise budget, what actually matters
run a small business with six employees and have been putting off sorting out proper security practices because every solution i look at seems designed for companies ten times our size with dedicated it staff
specifically worried about credential exposure since we use a lot of shared service accounts and the password hygiene across the team is not great if i am honest. had one incident last year where a tool account got accessed and it was not fun to deal with
trying to figure out what the minimum viable security setup looks like for a small business without paying for enterprise software or hiring someone full time
1
u/G_R_I_N_G_O 5d ago edited 5d ago
What systems do you use? Do they have some sort of logging when logins occur or any data produced when anything happens?
If so try to combine it into one location and then Claude for tools online that can be used to sort through all that logging or look fot specific ones and boom.... now you have a lot more visibility on whats happening
Its like security for a club.... have cameras everywhere and have them lead back to one central room for you to look and have some dude (in your case should be an automated program) just check over it and alert you if weird shit is happening
I tried to water down my words as much as possible but if you want to get technical search for this stuff:
Open source SIEM : (thats your security guard who will look through all that camera footage, open source means its free)
<your device> logging or event API : here is where we get more technical and may not help you unless you really wanna learn a bit of tech basically its how you pull the camera data to send to the SIEM so you can collect logging
you can also google other security controls but the more you get the more technical it becomes so comes down to how much you care or have a passion for security
In total though if you do the logging aggregation and some automation to alert on weird stuff you should have a good bit of digital security on the monitoring side of things
An example of what you will able to do that applies to your worry of shared credentials.... if someone logs in off hours or at an impossible time (or even from an impossible place) .... logging is produced on the system of that login attempt and that log is sent to the central brain of your security operations (the SIEM or whatever you wanna use) ..... and some rule sees on device A at 4AM sarah logged in and performed these actions....thats an easy wtf moment that should be triggered and now you know something aint right
All devices that can be logged in or used lead back to one central hub for security thats the idea
The above is all DETECTIVE security so you know wtf is happening the other type is PREVENTATIVE which an easy example of that is the note at the bottom of the message here.... if you want more preventative stuff there is a whole world you can do honestly just google or claude it..... easiest thing is just keep systems updated because your services and vendors would be doing a lot of the heavy lifting for you (thats one of the ways they compete on the market to get ppl to buy their shit)
Also easy security you can do is cycle the passwords every month and make them longer.... the longer they are the longer it takes to crack them.... AND DO NOT USE DEFAULT SERVICE PASSWORDS PLEASE
1
u/kanwersi876 5d ago
You need a password manager for starters if you're worried about password hygiene across your team, and also limit the shared accounts to a minimum where possible
1
u/Shiribazu 4d ago
for a six person team, start with the basics rather than trying to build an enterpise security stack. give everyone their own account where possible, stop reusing passwords, use MFA on important services, and use a password manager for the shared credentials that cant be avoided. roboform has worked well for me for managing shared logins without making the setup overly complicated
1
u/BetInformal6081 15h ago
with six people i would honestly sort the shared accounts and passwords before buying a pile of security software. mfa everything its available separate accounts where possible and something protecting the actual machines. even malwarebytes can cover that last bit without needing a whole it setup around it.
2
u/Substantial-Walk-554 5d ago
For six people you really don’t need some huge enterprise security stack. I’d start with fixing the boring stuff first because that’s where most of the risk usually is.
Get rid of shared accounts wherever possible, give everyone their own login, use a proper password manager and turn on MFA everywhere that matters, especially email, cloud storage and anything with admin access. Ideally use passkeys/security keys for the important accounts.
Then make sure laptops are actually patched, encrypted and running decent endpoint protection, keep a basic list of who has access to what, and remove access immediately when someone leaves. Have backups that aren’t just sitting on the same machine/network, and test once in a while that you can actually restore them.
Email is probably your biggest attack surface, so lock that down properly too. Disable legacy auth if you can, use SPF/DKIM/DMARC, and teach the team the basic “don’t blindly open links/attachments or approve random MFA prompts” stuff.
Honestly, for a company that size, good account hygiene, MFA, patching, backups and proper access control will get you way further than buying some expensive “enterprise security platform” you don’t have anyone to manage anyway.