More Security with Simple Means – Quick Wins for SMEs

Philipp Frisch
May 17, 2026

Sometimes it’s the simple things that have a big impact. A lock on the garden gate deters opportunistic intruders – even if it’s not a high-security installation. Similarly, there are simple IT security measures that immediately raise the level of protection without major investments or expert knowledge. This article presents such “quick wins.” Even if your company has done little for cybersecurity so far: with these steps, you’ll make a big leap forward.

Immediately Implementable Measures for Greater IT Security

The BSI defines some basic elements of cyber security that every company should implement. Drawing from these and from experience in supporting many SMEs, the following quick wins emerge:

Set Up Data Backup According to the 3-2-1 Rule

Set up regular backups, ideally automated and on external media. A widely recommended approach is the 3-2-1 rule: 3 copies of your data, on 2 different media, 1 copy stored at an external location. In the event of a ransomware infection, you can calmly restore your backup and quickly resume operations. Also occasionally check whether the recovery actually works!

Activate Firewalls on Router and End Devices

Make sure the firewall function on your internet router is active and correctly configured. If you have a corporate network with multiple computers, check whether a central firewall (hardware appliance) makes sense. It acts like a protective wall and filters unwanted internet traffic. The personal firewall built into Windows or macOS on each device should also remain switched on.

Fast Patch Management to Close Security Vulnerabilities

Apply updates for your operating system (Windows, Linux, macOS) and all important programs promptly. Most malware exploits known security vulnerabilities. For example, in 2023, an average of 78 new software vulnerabilities were discovered daily. Regular updates close these gaps. Enable automatic updates where possible, and schedule fixed time windows for manual updates (e.g., every two weeks).

More Simple but Effective Protective Measures

Disable Microsoft Office Macros by Default

If you use Microsoft Office, disable macros in documents by default. Macros are small embedded programs that criminals often smuggle into Excel or Word files. Only if your business processes absolutely require it should macros be allowed – and then managed very restrictively.

Establish Secure Passwords with a Password Manager

Use strong passwords or passphrases (e.g., a combination of multiple words, numbers, and special characters). Don’t put this responsibility solely on employees – support them with a password manager that generates and securely stores complex passwords. The BSI provides tips for creating secure passwords. Important: use unique passwords for every application!

Conduct Regular Employee Awareness Training

Even with a small budget, you can create awareness. For example, distribute security tips provided by the BSI as posters or by email to the team. Hold a brief security discussion every few months. Simply being aware that IT security matters significantly reduces the likelihood of clicking on phishing emails.

Immediate Measures with High Impact

These measures cost little to nothing – especially compared to the damage a cyberattack can cause. Each individual point significantly reduces your risk.

Practical tip: Choose one measure from the list above that hasn’t yet been implemented and complete it this week. For example: “Thursday 3 p.m.: set up backup drive.” Implementing such quick wins immediately also gives you an internal sense of achievement and motivates further improvements.

Philipp Frisch
Managing Director

Ready to scale your sales in a structured way?

Let's build a clear go-to-market and partner strategy together.