Every budget season, someone asks us what security product they should buy next. It is a fair question and we have opinions. But the honest answer, for most small and mid sized businesses we walk into, is that the best available upgrade is not a purchase at all. It is switching on things they already own and changing a few habits that cost nothing but attention.

That is not a popular position in an industry that sells tools. It is still true. The gap between the security a typical business has paid for and the security it has configured is enormous, and closing it will do more for you in 2026 than almost anything with a monthly fee attached. Here is the list, in the order we would do it.

Most Businesses Already Own the Fix

Microsoft 365 Business Standard includes multi factor authentication. So does Google Workspace, your accounting software, your bank, your CRM, and your file sharing tool. None of it does anything until someone turns it on and requires it.

The same is true further down the stack. Conditional access rules, audit logging, password policies, external sharing controls, and alerting sit inside subscriptions businesses already pay for every month. When we audit a new client, the most common finding is not a missing product. It is a product bought, deployed at defaults, and never configured. So before anyone quotes you a new platform, ask what you already own and how much of it is switched on.

Turn On the MFA You Are Already Paying For

This is the highest return change available to a small business, and it is free with almost every subscription you have. CISA’s guidance for small businesses puts it bluntly: “Users who enable MFA are MUCH less likely to get hacked.” CISA also calls for enabling MFA on all system administrator accounts and recommends it be “mandated using technical controls, not faith.”

That last phrase is the part people skip. Making MFA available is not the same as requiring it. If it is optional, the people you most want protected are usually the ones who opted out. Require it, for everyone, including the owner.

A few practical notes. Any MFA beats no MFA, so start with what you have. App based codes and push approvals are better than text messages. The strongest option, and the one CISA calls phishing resistant, is FIDO based authentication using a hardware key or a passkey, which blocks the fake login page attack entirely. We wrote YubiKey vs Passkey vs MFA for exactly this decision. Cost on the software side: zero.

Take Away Local Admin Rights

Most people are logged into their computer as an administrator all day. It happens by default when a machine is set up quickly, and nobody revisits it. The consequence is that anything running on that machine, including anything the user was tricked into running, inherits full control of the computer.

BeyondTrust’s Microsoft Vulnerabilities Report for 2026 found 1,273 Microsoft vulnerabilities disclosed in 2025, of which 509, or 40 percent, were elevation of privilege flaws. Critical vulnerabilities rose to 157, up from 78 the year before. The report notes that removing local admin rights has historically mitigated roughly 75 percent of Microsoft’s critical vulnerabilities. CISA’s small business guidance says the same thing more simply: “Remove administrator privileges from user laptops.”

The objection is always the same, and it is reasonable. People need to install things. The answer is a separate admin account used only when needed, or a request process that takes two minutes. Small friction, very large category of damage removed, and it is a configuration change rather than a purchase.

Put a Phone Call Between a Request and a Payment

Business email compromise is the most expensive attack aimed at businesses your size, and it involves no malware at all. Someone emails your bookkeeper pretending to be a vendor or an executive and asks for a payment or a change of bank details. The FBI’s Internet Crime Complaint Center recorded 24,768 business email compromise complaints in 2025, with reported losses of $3,046,598,558, out of $20.877 billion in total reported internet crime losses that year.

The control that stops it costs nothing. Write down a rule and give it to everyone who can move money:

  • Any new or changed banking details get a voice call. No exceptions, including from the owner.
  • Call a number you already had on file. Never the number in the email requesting the change. That is the trick.
  • Urgency is a reason to slow down, not speed up. Real vendors will wait ten minutes. Attackers manufacture deadlines because delay kills the scam.
  • Tell staff in writing that following the rule is never insubordination. This is the piece that makes the other three work.

That last point matters most. Payment fraud usually succeeds because an employee did not feel free to question a request that appeared to come from a boss. You fix that with permission, given in advance, in writing.

The Boring Hygiene That Beats New Software

The rest of the list is unglamorous, which is the point. None of it appears in a vendor demo.

  1. Delete accounts for people who left. Not disabled and forgotten. Removed, including SaaS tools, VPN, shared logins, and registered MFA devices. The Verizon 2025 Data Breach Investigations Report found credential abuse to be the most common way attackers get in, and an unused account with a valid password is exactly that.
  2. Review who has access to what, twice a year. Print the list of who can see payroll, banking, customer records, and the file server. Most businesses find someone still holding access from a role they left years ago.
  3. Patch on a schedule, not on impulse. CISA calls keeping systems patched “one of the most cost-effective practices” and recommends prioritizing anything in its Known Exploited Vulnerabilities catalog. Pick a day of the month, turn on automatic updates, and include what is easy to forget: firewalls, switches, printers, and cameras.
  4. Test a restore, not just a backup. A backup you have never restored from is a theory. Pick a file, restore it, and time it. That number is your real recovery capability.
  5. Write down who to call. One page. IT provider, cyber insurance carrier and policy number, bank fraud line, attorney, and the two people internally who decide. Print it, because if the incident involves your email you will not be reading it on your computer.

That last one takes twenty minutes and is the difference between a bad Tuesday and a bad quarter. CISA recommends every small business have a written incident response plan and practice it with leadership. You do not need a binder. You need a page and a shared understanding of who picks up the phone.

The Bottom Line

We are not arguing that security products are useless. Endpoint protection, monitoring, and email filtering are worth having, and we deploy them. The argument is about sequence. Buying a monitoring tool while everyone still runs as a local administrator with optional MFA is like installing cameras and leaving the back door open. The camera will faithfully record the problem.

Do the free things first. They take attention, not budget approval, and they remove the specific failure modes that cause losses at businesses your size. Once they are done, the conversation about tools gets better, because you will be buying to extend real coverage instead of to paper over gaps. We made the broader case in why cybersecurity is no longer optional for mid-sized businesses.

If you want an honest look at what you already own and what is not switched on, we will tell you plainly, including when the answer is that you do not need to buy anything. Harrison Ward Technology serves small and mid sized businesses throughout Denton County. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).