Written by Kelsey Beauchamp
October is Cybersecurity Awareness Month, but cybersecurity is something small and medium businesses need to think about all year long.
For SMBs across North Dakota, South Dakota, and Minnesota, cybersecurity does not need to mean buying every new security product or becoming an expert in the latest cyber threats. It starts with understanding where your business may be vulnerable and making practical decisions to reduce risk.
Unfortunately, some cybersecurity advice has been repeated for so long that it sounds like fact, even when it is outdated, incomplete, or simply wrong.
Those assumptions can create blind spots.
For a small or medium business, a cybersecurity incident can mean more than an IT problem. It can interrupt operations, prevent employees from working, expose sensitive information, disrupt customer service, and create unexpected recovery costs.
The good news is that many cybersecurity gaps can be addressed once you know where to look.
Here are six cybersecurity myths we regularly see SMBs get wrong and what business owners and leaders should know instead.
Myth 1: Our Business Is Too Small for Cybercriminals to Target
It is easy to assume cybercriminals are primarily interested in large corporations with millions of customer records.
That is not how many cyberattacks work.
Cybercriminals frequently look for opportunity. If your business has vulnerable accounts, weak passwords, exposed systems, or employees who can be tricked into providing access, the size of your organization may not matter.
A 10-person accounting firm in Fargo, a construction company in Grand Forks, a professional services business in Sioux Falls, or a growing organization in the Twin Cities can all have information or systems worth targeting.
Small and medium businesses may have access to:
- Employee and customer information
- Financial records
- Business bank accounts
- Email accounts
- Microsoft 365 data
- Vendor payment information
- Proprietary business information
- Customer and vendor systems
Attackers may also use one compromised organization as a path to its customers, vendors, or business partners.
The fact: Cybercriminals often choose targets based on opportunity, not company size.
The better question is not, "Are we big enough to be targeted?"
Ask, "If someone tried to compromise our business today, how difficult would we make it for them?"
Myth 2: Our Employees Will Recognize a Phishing Email
The obvious phishing emails filled with spelling mistakes and suspicious links have not disappeared, but they are no longer the only threat.
Modern phishing emails can be polished, professional, and highly convincing.
Attackers can imitate executives, vendors, financial institutions, Microsoft 365 notifications, delivery services, and other organizations your employees interact with every day. AI has also made it easier to create convincing messages without many of the traditional warning signs employees were taught to recognize.
That means employees need to look beyond grammar and spelling.
Before responding to an unusual request, consider the behavior behind the message.
Would this person normally:
- Ask you to change payment instructions by email?
- Request sensitive information unexpectedly?
- Send a login link you were not expecting?
- Ask you to purchase gift cards?
- Pressure you to act immediately?
- Request a wire transfer or unusual payment?
- Ask you to bypass your normal business process?
If something feels unusual, verify the request using a known method of communication before clicking, responding, or sending information.
The fact: A professional-looking email can still be a phishing attempt.
Security awareness training can help employees develop the habits needed to recognize suspicious behavior, not just suspicious-looking emails.
Myth 3: Multi-Factor Authentication Means Our Accounts Are Fully Protected
Multi-factor authentication, or MFA, is one of the most important cybersecurity controls an SMB can implement.
But MFA does not make an account invulnerable.
Attackers have developed techniques designed to get around weaker authentication methods. One example is MFA fatigue, sometimes called prompt bombing. An attacker repeatedly sends authentication requests hoping an employee will eventually approve one because they are distracted, confused, or simply want the notifications to stop.
Other attacks attempt to trick users into entering credentials or approving authentication through convincing fake login experiences.
This does not mean MFA is ineffective. It means MFA works best as one layer of a broader cybersecurity strategy.
Businesses should combine strong authentication with appropriate access controls, employee education, security monitoring, endpoint protection, email security, and other safeguards based on their risk.
The fact: MFA significantly improves account security, but it should be part of a broader cybersecurity strategy.
Cybersecurity works best in layers. No single security control should be expected to protect your entire business.
Myth 4: We Have Backups, So We're Covered
Having backups is important.
Being able to recover from those backups is what actually matters.
Consider this scenario: Your business is hit by ransomware or experiences a major system failure tomorrow morning.
Could you restore your critical information?
How quickly?
When was your backup last tested?
Which systems would be restored first?
How long could your business realistically operate without them?
For an SMB, downtime can quickly become expensive. Employees may be unable to work, customers may not receive service, and critical business processes can come to a stop.
A backup strategy should consider more than whether a copy of the data exists. Businesses should also think about retention, protection, testing, recovery priorities, and realistic recovery expectations.
The fact: Having backups is not the same as having a reliable recovery strategy.
A good business continuity plan helps you understand both what is protected and how your business would get back to work after a disruption.
Myth 5: Cybersecurity Is the IT Department's Responsibility
Your IT provider or internal IT team plays an important role in protecting your organization, but cybersecurity decisions happen throughout the business.
Accounting receives requests to change banking information.
HR handles sensitive employee information.
Executives have access to valuable accounts and confidential communications.
Employees receive links, attachments, login requests, and unexpected messages every day.
Your technical safeguards matter, but employees also need to know how to recognize unusual activity and what to do when something does not seem right.
The goal is not to turn every employee into a cybersecurity expert.
The goal is to make good security decisions part of normal business operations.
The fact: Cybersecurity is a shared business responsibility.
When employees understand common threats and know when to ask for help, they become another layer of your organization's cybersecurity defenses.
Myth 6: We'll Know What to Do If a Cybersecurity Incident Happens
Imagine it is Tuesday morning.
Several employees suddenly cannot open important files. Someone receives a suspicious message. Another employee reports that something unusual is happening with their computer.
What happens next?
That is when many SMBs discover they have never answered some basic questions:
- Should employees shut down their computers or leave them running?
- Who contacts IT?
- How will employees communicate if normal systems are unavailable?
- Who has authority to make decisions?
- When should the cyber insurance carrier be contacted?
- Who communicates with customers, vendors, or employees?
- Where is important contact information stored if normal systems cannot be accessed?
A stressful incident is not the time to build your plan from scratch.
An incident response plan should establish roles, communication paths, escalation procedures, and business priorities before they are needed. Depending on the situation, additional incident response, insurance, legal, forensic, or regulatory professionals may also need to become involved.
The fact: Your cybersecurity response plan should not debut during an actual incident.
Planning ahead helps your team make better decisions when time matters.
Cybersecurity for SMBs Starts With Asking Better Questions
Cybersecurity Awareness Month is a useful reminder to evaluate whether the assumptions guiding your business are still accurate.
For small and medium businesses in North Dakota, South Dakota, and Minnesota, cybersecurity does not have to be overwhelming.
You do not need to chase every new cybersecurity trend.
You need to understand your risks, protect the systems that matter to your business, prepare your employees, maintain reliable recovery options, and have a plan for when something goes wrong.
Most importantly, do not confuse having security products with having a cybersecurity strategy.
At Information Management Systems (IMS), we help SMBs across the Red River Valley and surrounding communities make practical technology and cybersecurity decisions. Our approach combines responsive IT support, cybersecurity, business continuity planning, and strategic technology guidance so business leaders can focus on running their organizations instead of trying to become IT experts.
No cybersecurity strategy can eliminate every threat, but the right combination of technology, processes, employee awareness, and planning can help reduce risk and improve your organization's ability to respond and recover.
If one or more of these cybersecurity myths sounds familiar, it may be time for a closer look at your business technology and security strategy.
Schedule a free 10-minute discovery call with IMS. We'll talk about your current environment, your concerns, and whether there are practical opportunities to improve your security and technology approach.
Call us at 701-364-2718 or visit www.imsnetworking.com to schedule your conversation.
Frequently Asked Questions About Cybersecurity for Small and Medium Businesses
1. Do small businesses really need cybersecurity?
Yes. Small and medium businesses can be attractive targets because they have valuable business data, financial accounts, employee information, email accounts, and relationships with customers and vendors. Cybersecurity for small businesses should focus on practical risk reduction, including strong authentication, employee awareness, endpoint and email protection, reliable backups, security monitoring, and recovery planning.
2. What cybersecurity protections should a small or medium business have?
Cybersecurity needs vary based on the organization, industry, technology environment, and risk profile. In general, SMB cybersecurity should use multiple layers of protection. These may include multi-factor authentication, secure access controls, endpoint protection, email security, security monitoring, employee security awareness training, protected backups, patching, network security, and an incident response plan. No individual security tool can eliminate all cyber risk.
3. Is multi-factor authentication enough to protect a small business from cyberattacks?
No. Multi-factor authentication is an important cybersecurity control, but it should not be the only one. Attackers may use phishing, MFA fatigue, credential theft, malicious software, social engineering, or other techniques to gain access. SMBs should combine MFA with employee education, security monitoring, appropriate access controls, email and endpoint protection, and other safeguards.
4. How often should a small business test its backups and recovery plan?
Backup and recovery processes should be reviewed and tested regularly based on the importance of the systems and data being protected. SMBs should know whether backups are completing successfully, whether data can actually be restored, which systems need to be recovered first, and what realistic recovery expectations look like. A managed IT provider can help a business develop a testing and business continuity strategy appropriate for its environment.
5. How can businesses in North Dakota, South Dakota, and Minnesota improve their cybersecurity?
SMBs in North Dakota, South Dakota, and Minnesota can start by reviewing their current technology, security controls, employee practices, backup and recovery capabilities, and incident response planning. A local managed IT and cybersecurity partner can help identify gaps, prioritize improvements, and build a practical technology strategy based on the organization's operations, risk, budget, and growth plans.
