May 27, 2026

Enterprise-grade security. Without enterprise cost.

How SMEs can implement ISO 27001-aligned security without a CISO budget.

The Security Budget Paradox

Small and medium enterprises face a paradox: the cyber threats targeting them are enterprise-grade. But their security budgets are not.

Ransomware doesn't discriminate by company size. Regulatory requirements (GDPR, NIS2, DORA) apply regardless of headcount. Supply chain attacks increasingly target smaller organizations as entry points to larger ones.

Yet most SMEs operate with security practices that would be considered inadequate in an enterprise context — not because they don't care, but because they don't know where to start, and the guidance available assumes resources they don't have.

The Minimum Viable Security Program

After 15+ years of implementing security frameworks in organizations ranging from 50 to 5,000 employees, I've identified the minimum set of controls that deliver 80% of the risk reduction for 20% of the cost.

Priority 1: Identity and Access Management

Most breaches begin with compromised credentials. Before any other investment, implement: Multi-factor authentication on all external-facing systems (Microsoft 365, VPN, banking portals). Privileged Access Management — separate accounts for administrative access, with session logging. Regular access reviews — quarterly audit of who has access to what. Password manager deployment — eliminate shared passwords and weak credentials.

Cost: €0–500/month depending on existing Microsoft licensing. Risk reduction: Eliminates 80%+ of credential-based attacks.

Priority 2: Endpoint Protection and Patch Management

Unpatched systems are the second most common attack vector. Implement: Automated patch management (Windows Update for Business, or a dedicated tool). Endpoint Detection and Response (EDR) — modern antivirus with behavioral detection. USB and removable media controls. Encrypted hard drives on all laptops.

Cost: €5–15/endpoint/month. Risk reduction: Eliminates the majority of malware-based attacks.

Priority 3: Email Security

Phishing remains the most common initial attack vector. Implement: Advanced email filtering (Microsoft Defender for Office 365 Plan 1 or equivalent). DMARC, DKIM, SPF configuration — prevents email spoofing. Security awareness training — quarterly phishing simulations. Clear procedures for wire transfer requests and invoice changes.

Cost: €2–5/user/month. Risk reduction: Reduces phishing success rate by 90%+.

Priority 4: Backup and Recovery

The only guaranteed defense against ransomware is clean backups. Implement: 3-2-1 backup rule: 3 copies, 2 different media, 1 offsite/cloud. Tested recovery procedures — backup that has never been tested is not a backup. Immutable backups — ransomware-proof storage that cannot be encrypted or deleted. Recovery time objectives — define acceptable downtime before disaster strikes.

Cost: €100–500/month depending on data volume. Risk reduction: Eliminates existential threat of ransomware.

The Documentation Minimum

Regulators and auditors want to see evidence of a security program, not just security tools. The minimum documentation set: Information Security Policy (2-3 pages). Acceptable Use Policy. Incident Response Plan. Business Continuity Plan. Asset inventory (even a spreadsheet). Access control records.

This documentation can be created in 2-3 days by someone who knows what they're doing. It doesn't require a consultant — it requires discipline.

The SME Security Roadmap

Month 1-3: MFA everywhere. Patch management automated. Basic email filtering. Backup tested.

Month 4-6: EDR deployed. PAM implemented. Security awareness training initiated. Documentation baseline created.

Month 7-12: DMARC/DKIM/SPF configured. Quarterly access reviews established. Incident response plan tested. Vendor risk assessment process defined.

This roadmap doesn't require a CISO. It requires a competent IT manager with clear priorities and management support.

What Good Looks Like

An SME with mature security practices has: Written policies that employees have read and signed. MFA on everything external. Tested backups with documented recovery time. A named person responsible for security (even part-time). An incident response plan that has been practiced.

This is achievable with a budget of €500-2,000/month for a 50-200 person organization. The cost of a single ransomware incident — downtime, recovery, reputation damage — typically exceeds €50,000-500,000.

Enterprise-grade security is not about enterprise-grade budgets. It's about enterprise-grade thinking applied at the right scale.