By Gorillx October 1, 2026
Cybersecurity can feel overwhelming, so teams often do nothing. That is the worst outcome. You do not need a huge budget to meaningfully reduce your risk — you need to do the basics well. Here are five wins most teams can get in under an hour each.
1. Turn on multi-factor authentication (MFA)
MFA is the single highest-value control for the effort. Enable it on email, VPN, and any admin accounts first. It stops the overwhelming majority of password-based attacks.
2. Patch what is exposed
You cannot patch everything at once, so start with what is internet-facing and what is actively being exploited. Prioritise by real exposure, not by a scanner’s severity score alone.
3. Review who has admin rights
Admin accounts are the keys to the kingdom. List everyone who has them, and remove the ones that are not needed. Most people do their daily work perfectly well without them.
4. Make sure backups exist — and test one
A backup you have never restored is a hope, not a plan. Confirm backups are running, then actually restore a file to prove it works. Do this before you ever need it.
5. Train people on phishing — kindly
Your team is not the weakest link; they are a control you have not invested in yet. A short, blame-free session on spotting phishing pays off quickly. Treat people as intelligent and they will rise to it.
None of these require a big spend — just a decision to start. Want help prioritising? Request a risk assessment.