This article was co-authored by Mike Wilfley, vcfo Chief Operating Officer and Executive Vice President, and Shane Gronniger, CEO for GCS Technologies.

Ensuring IT Security in Small- to Medium-Sized Businesses

A decade ago, dealing with spam, avoiding worms and viruses, and keeping inappropriate images and websites out of the office environment are what held the attention of organizations and their IT departments when it came to cybersecurity. In the past, companies considered implementing basic protective measures and content filters as a minor check-the-box exercise that they could fund through their operational budget to safeguard themselves from bad actors.

Today, the range and complexity of cyber threats as well as concerns about their impact have grown exponentially. Organizations have introduced widespread vulnerabilities due to the lack of runway, teams, and other elements in place to manage the rise of work-from-home models and cloud adoption in a fully controlled manner. Fortunately, advances in cloud modernization have spawned a new era of tools to better protect organizations. The challenge is that it’s hard for most small- to medium-sized organizations to grasp and implement these measures when their primary IT focus is day-to-day attention to core systems and end users.

Small- to medium-sized businesses (SMBs) must take a different path compared to enterprise-level organizations with deep pockets, as the latter can afford to devote entire teams to protecting against threats. Here, we take a look at today’s IT risk environment for SMBs, as well as the tools, processes, and services that one organization (vcfo) counts on to ensure their systems and data remain secure.

Establishing an IT Security Baseline

Years ago, security concerns heightened for vcfo when a third-party hosting platform for an accounting application some of the team used was encrypted and therefore inaccessible to the team. Although it did not occur on any vcfo system or platform, and despite the protections vcfo had in place at the time, the attack impacted operations for nearly a week. For CFOs and other leaders, instances like these are often what pushes concerns to a point that warrants a thorough review of how their organization views and manages these threats. The first step? Truly understanding the current state of vulnerabilities and gaps across the organization.

To understand the state of IT security and areas that needed shoring up, vcfo turned to GCS Technologies, a managed IT services provider that delivers enterprise-level security to SMBs. As they do with other organizations, GCS undertook a diagnostic dive into vcfo’s systems and related processes and then delivered a report that detailed areas and degrees of vulnerability which set the stage for what to do next.

Continue reading this article…

FAQ: IT Security for Small Businesses

How should a small business start with IT security?

Start with a baseline: know what devices, accounts, and data you have, then get the fundamentals in place — MFA, patching, endpoint protection, backups, and basic policies. Security fails at SMBs mostly through absence of basics, not absence of advanced tooling. This post, co-authored with vcfo, frames it as an executive discipline: from a baseline, improvements can be prioritized by actual business risk.

How much should a small business spend on IT security?

Less than a breach costs, and more than zero — spend follows risk: what data you hold, what downtime costs you per day, and what your industry requires. The good news for Microsoft-based businesses is that licenses they already pay for — Microsoft 365 Business Premium in particular — include Defender, Intune, and Conditional Access, serious security capability that often just isn’t turned on. GCS assessments in the Austin market regularly find most of the needed stack already licensed and idle.

Do small businesses really get targeted by hackers?

Constantly — most attacks are automated and hit whatever is exposed, regardless of company size. SMBs are attractive precisely because they hold real money and data behind thinner defenses. “Too small to be a target” hasn’t been true for years, and breach notification lists are full of companies that believed it.

Should a small business hire security staff or outsource?

For most SMBs, outsourcing wins on math alone: a single security hire costs more than a managed security service and can’t cover around-the-clock monitoring. A managed provider brings the tooling, the coverage, and the accumulated experience of defending many environments at once. The internal role that still matters is ownership — someone who treats security as their responsibility even when execution is outsourced.

Does Texas law give small businesses any protection after a breach?

Yes — Texas SB 2610 provides small businesses that maintain a qualifying cybersecurity program a safe harbor against certain damages in breach lawsuits. The catch is the program must exist and match recognized frameworks before the incident, which turns baseline security from good practice into legal protection. GCS covers who qualifies in its dedicated SB 2610 post. This is general information, not legal advice.

Who provides IT security for small businesses in Austin?

The Austin market has options from national franchises to independent local providers — filter for a real security practice, Microsoft depth if that’s your stack, and people who will actually show up onsite. GCS Technologies is an Austin-based, security-first MSP serving small and mid-sized businesses across Central Texas; whoever you evaluate, make them walk you through their first hour of incident response.

Pin It on Pinterest