5 Cybersecurity Mistakes Most Businesses Make (And How to Fix Them)
Most cybersecurity incidents don't happen because businesses were targeted by sophisticated attacks that nobody could have prevented. They happen because of predictable, avoidable mistakes that left the door open. This article covers the five most common mistakes we see in businesses across West Sussex and beyond — and exactly what to do about each one.
Mistake 1: Treating MFA as Optional
Multi-factor authentication is not optional security. It is the single most impactful control against the most common attack vector: credential compromise. Microsoft's data is unequivocal — MFA blocks over 99% of automated account takeover attacks.
Yet many businesses either haven't enabled MFA at all, or have enabled it for some users but not others (exceptions are routinely made for executives, who are often the highest-value targets), or have enabled it but not enforced it (making it an option users can decline).
The fix is straightforward: enforce MFA through Conditional Access policies, with no exceptions for senior staff. Choose authenticator app-based MFA over SMS. Apply it to every account that has access to business systems.
If you do one thing after reading this article, enforce MFA everywhere. Nothing else you do will have as much impact.
Mistake 2: Assuming Microsoft 365 Is Secure Out of the Box
Microsoft 365 is an excellent platform with extensive security capabilities. But those capabilities are not configured by default. A Microsoft 365 tenant running on default settings is missing significant security controls that are included in the licence and take configuration to enable.
The most important gaps: Safe Links and Safe Attachments in Defender for Office 365 are not enabled by default. Email authentication (DMARC, DKIM, SPF) requires DNS configuration that isn't automatic. Conditional Access policies that enforce MFA and device compliance need to be created. Audit logging isn't enabled by default in all configurations.
The fix is a security configuration review of your Microsoft 365 tenant. An experienced provider can work through your configuration against Microsoft's security benchmarks and identify and close the gaps. For most tenants, the most important improvements can be made in a few hours of focused work.
Mistake 3: Having Backups That Haven't Been Tested
Every business believes it has backups. Not every business has backups that work.
The most common backup failure scenarios are: backups that completed initially but have been silently failing for weeks or months; backups that complete successfully but are stored on network-attached storage that ransomware can encrypt along with everything else; backups that exist but whose restore process has never been tested.
The third point is particularly important. A backup is only as good as the restore it enables. Many businesses discover that their backup strategy has critical gaps only when they actually need to restore — which is the worst possible time to find out.
The fix has three components: ensure backups are isolated from your primary network (cloud backups with immutability settings are one good approach); verify backup completion regularly (don't just assume — check the logs); and test restoration at least annually. Run a full recovery exercise: wipe a non-critical system and actually restore it from backup. Time it. Confirm the restored data is complete and current.
Mistake 4: Neglecting Patch Management
Known vulnerabilities in unpatched software are the primary technical entry point for automated attacks. Every month, Microsoft and other vendors release patches that address known security issues. Every month, businesses fail to apply them, leaving those vulnerabilities exposed.
The common reasons for patching delays are understandable: patches can cause compatibility issues, update windows are inconvenient, and IT resource is stretched. But the solution to these problems is better patch management processes, not deferring patches indefinitely.
The fix requires two elements. First, a defined patch management process: who is responsible, what schedule are patches applied on, what's the maximum acceptable delay for critical patches (14 days is the Cyber Essentials requirement). Second, visibility: a tool or process that shows you the patch status of all managed devices, so you know the state of your environment rather than assuming patches have been applied.
For businesses using Microsoft Intune, Windows Update for Business, or a managed IT provider with RMM tools, patch management can be largely automated with appropriate reporting. For businesses managing it manually, the process needs to be formalised and documented.
Mistake 5: No Plan for When Things Go Wrong
Every cybersecurity programme should account for the reality that some attacks will succeed despite your preventive controls. The question isn't whether to have an incident response plan — it's whether you have one before or after the crisis.
Businesses without incident response plans make expensive decisions under pressure. They call the wrong people in the wrong order. They shut down systems that should be preserved for forensic investigation. They miss the 72-hour ICO notification window. They communicate poorly with customers and staff, creating unnecessary additional damage to the business.
The fix doesn't require a lengthy document. A practical incident response plan for an SME might be a single page: who to contact in what order (IT provider, legal counsel, cyber insurer, ICO if required), what to do immediately with affected systems (isolate, don't shut down), what information to preserve for investigation, and template communications for staff and customers.
Having that plan, discussing it with key staff, and reviewing it annually is the difference between a costly incident that's manageable and a costly incident that's catastrophic.
Putting It Together
None of these five fixes are technically complex or prohibitively expensive. They're the kind of security fundamentals that every business should have in place, and the reason many don't is practical rather than principled — nobody got around to it, nobody understood the risk clearly enough to prioritise it, or it felt overwhelming to know where to start.
If you've read this and identified gaps, the right response is to start with the most impactful fix first: MFA. Then work through the others systematically. Or get in touch with us — we can work through your current security posture, identify the specific gaps in your environment, and help you close them efficiently.