
Blog
Cybersecurity pillars to protect a small or medium enterprise
Concrete cybersecurity, told as you do it in the company — then the schema.
by Giuseppe Foggetti
Software Engineer & AI Solutions Developer — Foggetti Studio
Phishing and ransomware hit SMEs that thought «we are too small». Security that works is MFA everywhere it is missing, backups you have restored once, and a clear first sixty minutes when something looks wrong.
Skip unread fifty-page policies. Drill the basics. One real restore test beats a binder of good intentions.
Basics that keep you working
Enable MFA on email, admin panels and remote access. Separate backup credentials. Test restore on a non-critical file set.
Write who calls whom in the first hour: IT contact, management, possibly insurer or lawyer. Practice once so panic does not write the playbook.
Dirty data, dirty results
If records and inputs are messy, any automation or language model amplifies the mess. Dedicate an explicit block to minimal clean-up on the MVP perimeter: duplicates, required fields, out-of-range values. That is not «IT work». It is operational truth.
Training that sticks
Short sessions on the team's real cases. A checklist within reach. A super-user per area for the first fifteen days. Avoid catalogue courses that end in a certificate and zero change the following Tuesday.
How you know you are improving
Do not multiply dashboards. Pick a few indicators tied to the process you are touching — on protect a small or medium enterprise, cycle time, output quality and adoption of the official flow usually suffice. Set baseline in week zero. Review at thirty days. If numbers do not move, change process and inputs before you change the tool.
After the pilot: expand without losing the thread
Widen only if the primary KPI improved, adoption beats the agreed threshold, the exception backlog is under control and the owner is still in charge. Otherwise reduce scope or strengthen training. A meeting every two weeks is enough: numbers, top exceptions, decisions. No status theatre.
Document the mapping or happy-path rules on a living page. When someone new joins, that page saves three weeks of oral tradition. Light governance is not bureaucracy: it is operating memory.
Vendors and boundaries
If an external vendor enters, clarify who owns configurations, prompts, mappings and logs. Avoid opaque dependencies. A good partner leaves the company more autonomous at ninety days, not more tied to endless tickets to change one rule.
A detail that makes the difference
Block calendar time for the pilot. Without dedicated slots the project stays «between other things» and never really starts. The operating owner updates status every week in five minutes: done, blocked, next step. It is not elegant. It works.
What to leave out on purpose
The first release is not the moment to prove everything the tool can do. Leave out features without an owner, integrations to little-used systems, automations on rare exceptions and aesthetic reports not tied to a decision. Expanding after the numbers is courage. Expanding before is anxiety dressed as ambition.
What to leave out on purpose
The first release is not the moment to prove everything the tool can do. Leave out features without an owner, integrations to little-used systems, automations on rare exceptions and aesthetic reports not tied to a decision. Expanding after the numbers is courage. Expanding before is anxiety dressed as ambition.
Dirty data, dirty results
If records and inputs are messy, any automation or language model amplifies the mess. Dedicate an explicit block to minimal clean-up on the MVP perimeter: duplicates, required fields, out-of-range values. That is not «IT work». It is operational truth.
Training that sticks
Short sessions on the team's real cases. A checklist within reach. A super-user per area for the first fifteen days. Avoid catalogue courses that end in a certificate and zero change the following Tuesday.
How you know you are improving
Do not multiply dashboards. Pick a few indicators tied to the process you are touching — on protect a small or medium enterprise, cycle time, output quality and adoption of the official flow usually suffice. Set baseline in week zero. Review at thirty days. If numbers do not move, change process and inputs before you change the tool.
After the pilot: expand without losing the thread
Widen only if the primary KPI improved, adoption beats the agreed threshold, the exception backlog is under control and the owner is still in charge. Otherwise reduce scope or strengthen training. A meeting every two weeks is enough: numbers, top exceptions, decisions. No status theatre.
Document the mapping or happy-path rules on a living page. When someone new joins, that page saves three weeks of oral tradition. Light governance is not bureaucracy: it is operating memory.
Vendors and boundaries
If an external vendor enters, clarify who owns configurations, prompts, mappings and logs. Avoid opaque dependencies. A good partner leaves the company more autonomous at ninety days, not more tied to endless tickets to change one rule.
A detail that makes the difference
Block calendar time for the pilot. Without dedicated slots the project stays «between other things» and never really starts. The operating owner updates status every week in five minutes: done, blocked, next step. It is not elegant. It works.
A detail that makes the difference
Block calendar time for the pilot. Without dedicated slots the project stays «between other things» and never really starts. The operating owner updates status every week in five minutes: done, blocked, next step. It is not elegant. It works.
What to leave out on purpose
The first release is not the moment to prove everything the tool can do. Leave out features without an owner, integrations to little-used systems, automations on rare exceptions and aesthetic reports not tied to a decision. Expanding after the numbers is courage. Expanding before is anxiety dressed as ambition.
Dirty data, dirty results
If records and inputs are messy, any automation or language model amplifies the mess. Dedicate an explicit block to minimal clean-up on the MVP perimeter: duplicates, required fields, out-of-range values. That is not «IT work». It is operational truth.
Training that sticks
Short sessions on the team's real cases. A checklist within reach. A super-user per area for the first fifteen days. Avoid catalogue courses that end in a certificate and zero change the following Tuesday.
How you know you are improving
Do not multiply dashboards. Pick a few indicators tied to the process you are touching — on protect a small or medium enterprise, cycle time, output quality and adoption of the official flow usually suffice. Set baseline in week zero. Review at thirty days. If numbers do not move, change process and inputs before you change the tool.
After the pilot: expand without losing the thread
Widen only if the primary KPI improved, adoption beats the agreed threshold, the exception backlog is under control and the owner is still in charge. Otherwise reduce scope or strengthen training. A meeting every two weeks is enough: numbers, top exceptions, decisions. No status theatre.
Document the mapping or happy-path rules on a living page. When someone new joins, that page saves three weeks of oral tradition. Light governance is not bureaucracy: it is operating memory.
Vendors and boundaries
If an external vendor enters, clarify who owns configurations, prompts, mappings and logs. Avoid opaque dependencies. A good partner leaves the company more autonomous at ninety days, not more tied to endless tickets to change one rule.
Vendors and boundaries
If an external vendor enters, clarify who owns configurations, prompts, mappings and logs. Avoid opaque dependencies. A good partner leaves the company more autonomous at ninety days, not more tied to endless tickets to change one rule.
A detail that makes the difference
Block calendar time for the pilot. Without dedicated slots the project stays «between other things» and never really starts. The operating owner updates status every week in five minutes: done, blocked, next step. It is not elegant. It works.
What to leave out on purpose
The first release is not the moment to prove everything the tool can do. Leave out features without an owner, integrations to little-used systems, automations on rare exceptions and aesthetic reports not tied to a decision. Expanding after the numbers is courage. Expanding before is anxiety dressed as ambition.
In short: what to do Monday morning
Short version to bring to a meeting.
Steps
- Write the business goal in one sentence + out of scope.
- Name owner and sponsor.
- Define an MVP with acceptance criteria.
- Run a real-user pilot and log exceptions.
- Review KPIs; go/no-go on expansion.
Quick checklist
- Goal written down.
- Owner active.
- MVP defined.
- Pilot planned.
- KPI baseline set.
KPIs (max three)
- Average process time (before/after).
- Error or rework rate.
- % usage of the official flow.
Practical value (and the next step)
SME security is not a slogan: it is MFA, tested backups and the first sixty minutes after a suspicion. Practical value is keeping work going when someone tries phishing or ransomware.
Enable MFA where it is missing, test a restore, and write who calls whom in an incident. One real drill beats ten unread policies.
If you want a second opinion on the scope of your case, Foggetti Studio can help you read the current state and define a realistic MVP.