← Back to blog Security

Cybersecurity for SMBs: why it's no longer optional

Real risks, practical controls, and a roadmap that fits any budget

Adiel Buenrostro
Leader
📅 Oct 5, 2026 ⏱ 4 min 👁 7
Cybersecurity for SMBs: why it's no longer optional

Why this post exists

SMBs in Mexico are a favorite target of cybercrime — not because of their size, but because of their unprotected attack surface: a single unpatched endpoint, a reused password, a shared folder with open permissions. To attackers, an SMB is a stepping stone: they use it as a backdoor into their corporate clients, or simply to collect a ransom the company can actually pay.

According to Mexico's Cyber Police and INEGI data, in 2024 over 60% of SMBs hit by a serious incident took more than three months to recover, and a significant percentage shut down operations within six months. The question is no longer if you'll be attacked — it's when.

The 2025-2026 threat landscape

1. Phishing and spear phishing

Still the #1 vector. Today's emails aren't the obvious "Nigerian prince" scams; they perfectly mimic suppliers, banks, and tax authorities (SAT). They include links to fake portals that capture credentials in real time.

2. Ransomware

The business model has changed. They now use double extortion: they encrypt your files and threaten to leak sensitive data if you don't pay. Manufacturing, logistics, and financial services in Mexico have been particularly targeted.

3. Business Email Compromise (BEC)

Impersonation of a CFO or supplier requesting urgent wire transfers. Average damage per incident exceeds USD 125,000 according to the FBI.

4. Supply chain attacks

Compromising a software vendor (think SolarWinds, MOVEit, Kaseya) to reach its clients. If you use SaaS or a third-party MSP, you're exposed too.

5. Dark web exposure

Stolen credentials, customer databases, and engineering drawings are traded every day. A simple lookup of your company domain can reveal leaked passwords before you even notice.

Non-negotiable minimum controls

If you can only do five things this quarter, make it these:

1. MFA on everything

Enable two-factor authentication on email, VPN, firewall admin panels, and any cloud service. SMS works, but an authenticator app or physical key (FIDO2) is better.

2. Patching and updates

Turn on auto-updates for operating systems, browsers, and network devices. 80% of successful attacks exploit vulnerabilities with patches available for over a year.

3. Verifiable 3-2-1 backups

Three copies, on two different media, with at least one off-site. Most importantly: test them. A backup you can't restore isn't a backup.

4. Least privilege principle

Each user only accesses what they need. Remove orphan accounts, segment the network (offices, servers, OT), and review who has admin permissions.

5. Continuous awareness

One training per year doesn't work. Run brief monthly phishing drills (5 minutes), report outcomes without pointing fingers, and reward people who report suspicious emails.

Phased roadmap (12 months)

Phase 1 — Months 1-3: Stabilize

  • Asset inventory (endpoints, servers, cloud services)
  • MFA on all critical services
  • Automated, tested backups
  • Password policy with a manager (Bitwarden, 1Password)
  • Estimated cost: low. Most of these are configuration tasks.

Phase 2 — Months 4-6: Harden

  • Automated patching (Windows Update for Business, WSUS, or apt-cron on Linux)
  • EDR or next-gen antivirus on endpoints
  • Next-gen firewall with TLS inspection
  • Network segmentation (VLANs for office, servers, guest WiFi)
  • Estimated cost: medium. Talk to your MSP about a bundle.

Phase 3 — Months 7-12: Mature

  • Formal written security policy
  • Incident response plan with defined roles
  • Annual penetration testing or vulnerability assessment
  • Consider NIST CSF 2.0 or ISO/IEC 27001 certification depending on industry
  • Compliance: LFPDPPP, NOM-151, CNBV regulation if handling financial data

What to do when (not if) you get hit

  1. Disconnect, don't power off. Powering off can destroy volatile evidence.
  2. Call the expert. Your MSP, an incident response (IR) provider, or law enforcement.
  3. Don't pay immediately. Each case is different; paying doesn't guarantee recovery.
  4. Document everything from minute one: what happened, when, who was affected.
  5. Communicate with customers and authorities per regulation (LFPDPPP requires breach notification).

Where to start today

You don't need a CISO or a SOC to begin. You need a designated owner (could be your MSP or your IT director) executing it, clear metrics, and an assigned budget.

At JMSERVICES, we help SMBs build their cybersecurity posture from scratch: from initial assessment to control implementation, team awareness, and audit preparation.

Ready to start? Reach out and let's schedule a free 30-minute diagnostic.


Need help? JMSERVICES offers cybersecurity assessments, MFA rollout, network segmentation, and incident response plans for SMBs in Mexico and the northern border region.

Request a diagnostic →

Brands involved in this project

#ciberseguridad #pymes #ransomware #mfa #iso27001 #nist
Talk to our engineers

Want this kind of result in your plant?

Tell us about your site. We will reply with an honest take, not a sales script.

Reply in under 24 business hours.