Most cyberattacks on Portuguese SMEs do not target large corporations—they target smaller companies, precisely because, on average, they have fewer defenses in place. This checklist outlines the essential security measures that any SME should have in place, regardless of its industry.
1. Dedicated firewall and network segmentation
A properly configured firewall is the first line of defense between a company’s internal network and the outside world. In companies with multiple departments or types of devices, segmentation into VLANs limits the impact of a compromised device, preventing an isolated incident from spreading throughout the entire network.
2. Backups that have been tested—not just created
Having backups is not the same as having backups that work. Many companies only discover that a backup is corrupted or incomplete when they need it most. Best practices include the 3-2-1 rule (three copies, on two different types of media, with one stored off-site) and periodic restore tests—not just confirming that the backup “ran without errors.”
3. Multi-factor authentication (MFA)
A compromised password is no longer enough for an attacker to access email, files, or critical applications when two-factor authentication is enabled. It is one of the most cost-effective cybersecurity measures and should be enabled for all access to corporate email, VPNs, and management applications.
4. Managed Security Updates
Outdated operating systems, management software, and network equipment firmware are among the most common entry points for cyberattacks. Centralized update management—rather than relying on each employee to update their own devices—ensures that these patches are consistently deployed to all workstations.
5. Employee Training and Awareness
Most security incidents begin with human action—clicking on a phishing link, sharing a password, or opening an attachment without verifying it. Regular awareness sessions, even short ones, significantly reduce this type of risk.
6. Access Control and the Principle of Least Privilege
Each employee should have access only to the systems and data necessary for their role—and nothing more. This limits the impact of a compromised account and makes it easier to audit who accesses what information. Centralized access management, through Active Directory or an equivalent system, is the most efficient way to apply this principle.
7. VPN for remote access
With the rise of remote and hybrid work, access to company systems from outside the office must be done exclusively through an encrypted VPN, never through direct, unprotected connections to the internal network.
8. Continuous monitoring
A successful attack is rarely instantaneous—there are usually signs of anomalous activity before the actual impact (repeated access attempts, network traffic that deviates from the norm, unauthorized changes). 24/7 monitoring allows you to detect and respond to these signs before they escalate into a serious incident.
9. Incident Response Plan
Knowing in advance who to contact, which systems to isolate first, and how to communicate internally in the event of an incident drastically reduces response time—and, as a result, the impact of the incident itself.
Where to Start
If your company has not implemented most of these measures, the most effective approach is not to try to address everything at once, but to start by conducting an audit of your current infrastructure to identify the most critical gaps and prioritize the fixes that will have the greatest impact in terms of risk.




























































































