Cyber security for an SME starts not with expensive products but with a handful of basic controls applied consistently: multi-factor authentication on every account, identity and content checks on incoming email, backups that are tested and kept out of an attacker's reach, timely patching, and removing a leaver's access on the day they leave.
The 12-point checklist below is ordered so that a business without a dedicated security team can put it in place within 90 days.
Where most small businesses actually stand
In a typical SME, IT is handled by one employee or an outside support provider; according to TÜİK's ICT Usage Survey on Enterprises, 2026, only 10.8% of Turkish enterprises with 10-49 employees employ ICT specialists. Finance, purchasing and sales share the same email platform; shared folders hold quotes, contracts and personnel files. Passwords live in people's heads, sometimes in a spreadsheet, occasionally on a sticky note on the monitor. When someone leaves, their account gets closed "at some point".
This is rarely negligence; it is a matter of priorities. The team is busy shipping orders, and security is invisible until something goes wrong. That gap is exactly what attackers aim for. Sophisticated attacks on large enterprises make the news, but what happens to SMEs is usually far more mundane: a guessed password, a convincing invoice email or a remote access service that is behind on patches.
The cost of doing nothing
The numbers do not support the "it won't happen to us" assumption. In Türkiye, the same TÜİK survey found that 9.4% of enterprises experienced at least one ICT security incident in 2025, and 5.6% reported data loss or corruption due to malware or unauthorised access. The UK, which measures this in more depth, shows an even clearer picture:
According to the UK government's Cyber Security Breaches Survey 2025/2026, 43% of businesses experienced a cyber breach or attack in the previous 12 months, with phishing by far the most common type, reported by 38% of businesses. (UK Cyber Security Breaches Survey 2025/2026)
The same survey found that only 47% of UK businesses use two-factor authentication. Yet the Microsoft Digital Defense Report 2025 states that more than 97% of identity attacks are password attacks, and that phishing-resistant multi-factor authentication can stop over 99% of them. One of the most effective controls available is still missing in around half of businesses.
The human side matters just as much: the Verizon 2026 Data Breach Investigations Report found the human element in 62% of breaches. Technical controls therefore need processes and an email platform that support staff rather than rely on them never making a mistake. There is a legal side too. For companies operating in Türkiye, KVKK, the Turkish Personal Data Protection Law (Law No. 6698), requires data controllers to take technical and organisational measures that ensure an appropriate level of security; the items on this checklist are the technical half of that duty. We cover the full legal framework in our 8-step KVKK compliance roadmap, and what to do when an incident involves personal data in data breach notification within 72 hours under KVKK.
The 12-point SME cyber security checklist
The checklist is grouped under four headings. Start by marking each item "in place", "partly" or "missing"; in practice, "partly" usually means "missing".
Identity and access
- Multi-factor authentication (MFA) everywhere. Email, remote access (VPN, remote desktop), accounting and banking channels, cloud admin consoles. Start with administrator accounts. If you are moving systems to the cloud, write MFA, permissions and logging for cloud accounts into the migration plan from day one; we cover these line items in our article on cloud migration cost and budgeting. For choosing methods and rolling them out to staff, see our MFA rollout plan.
- Personal accounts, not shared logins. Shared mailboxes such as accounts@ are fine, but people should reach them with their own identity and permissions, not a shared password. We look at password choices separately in our guide to business password security; as the number of applications grows, our SAML vs OIDC comparison explains which protocol to use for single sign-on.
- Leavers lose access on the day they leave. Email, file sharing, VPN, accounting software, social media accounts. That requires a single list showing who has an account on which system; linking that list to the leaver record in your HR and personnel management system stops accounts being forgotten. Mailbox handover and forwarding are covered step by step in removing email access when employees leave.
- Least privilege. People reach only the folders and mailboxes their job needs; delete rights are granted separately. Extended across the whole network, this principle becomes the zero trust security model, while data loss prevention (DLP) rules limit sensitive files leaving uncontrolled.
Email and people
- SPF, DKIM and DMARC configured for your domain. They make it harder for others to send mail in your name; our SPF, DKIM and DMARC guide explains the set-up.
- Incoming mail checked for look-alike domains and display-name spoofing. Mail from an attacker's own domain can pass authentication, so content and sender consistency need assessing too. More on the technique in lookalike domain attacks.
- Payment and bank detail changes confirmed outside email. A call-back to the number on file and two-person approval; see our article on bank detail change email fraud.
- Short awareness training and a phishing simulation at least twice a year. The goal is to make reporting a suspicious email easy, not to blame people; training should show with real examples how to spot phishing emails. Add a short AI usage rule as well: which tools may customer and staff data be entered into, and which are off limits? The reasoning is in our article on entering company data into ChatGPT.
Devices and infrastructure
- A patching schedule. Operating systems, browsers, VPN and firewall software; critical patches for internet-facing services applied within days. Regular vulnerability scanning shows which patches are missing, and our patch management process guide covers the flow from inventory to verification.
- An inventory of internet-facing services. Which ports and panels are visible from outside? Are cameras, printers or routers still on default passwords? Is guest Wi-Fi separate from the business network? Who can physically enter the server room or reach the network cabinet belongs on this inventory too; we explain the approach in data centre and server room access control. If you run a plant, see our article on OT security for SCADA networks for separating production from the office.
Backups and incident response
- 3-2-1 backups with tested restores. At least one copy out of the attacker's reach, and a real restore test at least every three months. Details in our guide to a ransomware backup strategy. See backup restore testing for how to run the test.
- A one-page incident plan. Who gets called when something looks wrong, which accounts get locked, who contacts the bank and, where needed, handles the KVKK notification? Keep the phone numbers on paper as well. Spotting and investigating an incident needs logs: SIEM and log management covers that side, and if you offer internet access to guests or staff, Law 5651 log retention applies too.
A 90-day order of work
| Period | Focus | Items |
|---|---|---|
| Days 1–30 | Identity and email | 1, 3, 5, 7 |
| Days 31–60 | Backups and patching | 9, 10, 11 |
| Days 61–90 | Permissions, training, plan | 2, 4, 6, 8, 12 |
This order closes the most common attack routes (passwords and email) first, then secures the backups that let the business recover if an attack still succeeds.
Common mistakes when rolling it out
- Enabling MFA for administrators only. Attackers usually come in through the least protected account, and a finance or sales mailbox is as valuable as an admin's.
- Keeping backups on the same network. A backup on a network-attached drive can be encrypted by ransomware along with the live data.
- Filling in the checklist once and forgetting it. New staff, new systems and new suppliers change the picture every month; without a schedule the checklist goes stale. Cover suppliers separately with a third-party vendor security assessment; if you sell to EU customers, the questions they will ask are collected in our article on NIS2 requirements for suppliers.
If you want to tie these controls into a lasting management system, the ISO 27001 information security standard is a sound framework; if your email, backups or files sit on a cloud server abroad, add the KVKK rules on cross-border data transfer to the list as well.
On the personal data side, two areas are often overlooked in SMEs: the rules on CCTV recording under KVKK for office, warehouse and shop cameras, and the AI and personal data obligations that apply to data staff paste into AI tools.
Under KVKK, the basis for these technical measures is a personal data inventory that shows which data sits where. Every service provider that can reach your data, such as an accounting firm, a cloud provider or an IT support company, should also sign a data processing agreement.
For personnel files, see our guide to employee personal data under KVKK; for notices aimed at customers and visitors, read explicit consent vs privacy notice.
When you work through the email items, use how to set up email with your own domain for your domain's core records and business email encryption for protecting sensitive attachments.
How we do this at Digital Bridge
When we work with SMEs through our cyber security consultancy, the checklist does not stay on paper:
- Current-state review: we check the 12 items against your actual systems and scan your internet-facing services for known vulnerabilities. Where it makes sense, we run a written-scope penetration test.
- A risk-ordered plan: findings are reported by severity, each with a practical remediation step.
- Personal data: for systems holding staff and customer data, we handle technical measures alongside our data protection compliance work, including the process for handling data subject requests.
- Backups and infrastructure: we set up backup and restore scenarios as part of our cloud migration and infrastructure consultancy, and we actually test the restore.
- Awareness training: phishing simulations, social engineering examples and an incident reporting procedure. We describe the yearly cycle in our security awareness training program guide; to keep attendance records audit-ready, use the same method as digital tracking of OHS training records.
Which checklist items Smart360 covers
The identity, email and file sharing items are supported directly by our business application suite, Smart360. Smart360 brings SmartMail (business email) and SmartFiles (business file management) together under one admin panel and one identity, SmartID.
Item 3 — leavers: because every product is reached with one identity, a leaver's access is closed in a single action. When someone moves department, their access changes across all products at once, and in SmartMail mailbox access is removed automatically when they leave a department. Sessions are listed with device details and can be ended remotely; changing a password ends every session.
Items 2 and 4 — personal accounts and least privilege: mailbox passwords are generated by the system, stored encrypted with AES-256-GCM and never handed out to staff. Shared mailboxes in SmartMail have nine separate permissions per mailbox (view, write and send, delete, quarantine and more), with delete and quarantine management switched off for new assignments. SmartFiles assigns eight independent rights, such as read, write, edit and delete, to a person or department in a single matrix.
Items 6 and 7 — email checks and payment emails: SmartMail assesses every incoming message against 12 signals, including its own SPF/DKIM/DMARC and PTR checks, look-alike domains and international characters, display-name and brand impersonation, Reply-To and link mismatches, risky attachments and comparison with known fraud techniques. The reasoning is shown as a written report, and the organisation sets its own quarantine threshold. For critical outgoing mail sent on the company's behalf, an approval flow can be required before sending.
Sign-in screens: Smart360 Security uses human verification on sign-in screens, so password-guessing attacks are stopped before they reach the server.
In SmartFiles, uploading a file with the same name creates a new version, and earlier versions can be restored, which makes it easy to recover a quote that was accidentally overwritten. That does not replace the independent backup in item 11; the two should be planned together.
Security is one of the seven dimensions that determine a business's digital maturity; to measure it alongside the others, see our article on digital maturity assessment.
Next step
This week, mark each of the 12 items "in place", "partly" or "missing", and focus only on the four items for the first 30 days. For more depth on each item, browse our full Cyber Security & Compliance guide. If you are not sure where to start, get in touch; we will review your current position with you and look at how Smart360 covers the items on the list.