How to Get Breached, Step 1: Assume You’re Too Small to Be a Target
Why “nobody wants our data” is one of the most expensive sentences a small business owner can say
Automated cyber attacks don’t check your company size. They look for the easiest open door.
Welcome to How to Get Breached, our weekly guide for business owners who want to make a cybercriminal’s job as easy as possible. Step one is a classic, and it costs nothing to adopt. Just decide that hackers only go after banks, big retailers, and national brands. Not a 20-person company with a modest office and a coffee maker that leaks. Once you believe that, you can skip the security budget, the complaints about multi-factor authentication, and the backup testing. Attackers appreciate the cooperation.
For everyone who would rather not get breached, here’s why this advice backfires.
Attackers Don’t Check Your Size First
Most cyberattacks are automated. Bots scan the internet around the clock for exposed remote access, unpatched firewalls, and email accounts with weak or reused passwords. They don’t look up your revenue before they knock. They look for an open door.
We see this firsthand. The security monitoring we run for our clients records automated login attempts and scans every day against organizations of every size, including small offices most people would assume nobody cares about.
Small Means Easier, Not Safer
Small businesses often have fewer defenses: no dedicated security staff, older equipment, and shared passwords that never get changed. Attackers know this. Verizon’s 2025 Data Breach Investigations Report found ransomware in 88% of breaches at small and mid-sized businesses, compared with 39% at large organizations.
Your business is also a doorway to other people. Your email account can be used to send fake invoices to your customers. Your vendor relationships and bank accounts are worth something to a criminal even if your customer list isn’t.
A Hypothetical Scenario
Picture a fictional 15-person distribution company. The office manager uses the same password for work email as for a shopping site that was breached years ago. There’s no multi-factor authentication. An attacker logs in quietly, watches email for two weeks, then sends a few customers a polite note with “updated” bank details. Nobody notices until payments stop arriving. No advanced hacking was needed. The door was simply unlocked.
Practical Action Steps for Owners and IT
Turn on multi-factor authentication (MFA) for email, remote access, banking, and every cloud app, starting with email.
Patch operating systems, firewalls, and VPNs on a schedule, and replace equipment that no longer receives security updates.
Close exposed remote access. Remote desktop should never face the open internet.
Keep backups with at least one copy offline or immutable, and test a full restore at least quarterly.
Put security monitoring in place so someone reviews suspicious activity around the clock, not just during business hours.
Train staff to spot phishing, and require a phone call to a known number before changing any payment details.
Write a one-page incident response plan listing who to call first: your IT provider, your cyber insurer, and legal counsel.
Review your cyber insurance requirements. Many carriers now require MFA and tested backups before they’ll pay a claim.
Questions Your Customers May Ask You
Is my information safe with you? A strong answer explains what you actually do: MFA, monitored systems, tested backups, and staff training.
Why do you call me to confirm payment changes? Because fake invoice emails are one of the most common scams, and a quick call stops them.
What happens if you get hit by ransomware? You should be able to say that you have tested backups and a plan to restore operations quickly.
Would you tell me if my data were exposed? Yes. Explain that you have a response plan that includes timely notification.
How Farmhouse Networking Can Help
Farmhouse Networking helps small and mid-sized businesses close the gaps attackers count on. We provide 24/7 security monitoring, manage MFA, patching, and backups so they stay current, run staff security awareness training, and support compliance requirements specific to your industry. Our team is 100% U.S.-based, and when you call, a real person answers.
Find Out Where You Stand
You don’t need to guess whether your business is an easy target. Email support@farmhousenetworking.com to schedule a free breach-readiness review. We’ll show you where your gaps are and what to fix first, in plain language.
Next week: How to Get Breached, Step 2: Use the Same Password Everywhere.
And God will generously provide all you need. Then you will always have everything you need and plenty left over to share with others. As the Scriptures say, “They share freely and give generously to the poor. Their good deeds will be remembered forever.” For God is the one who provides seed for the farmer and then bread to eat. In the same way, he will provide and increase your resources and then produce a great harvest of generosity in you. - 2 Corinthians 9:8-10
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.