Cybersecurity for SMBs: why it's no longer optional
Real risks, practical controls, and a roadmap that fits any budget
Why this post exists
SMBs in Mexico are a favorite target of cybercrime — not because of their size, but because of their unprotected attack surface: a single unpatched endpoint, a reused password, a shared folder with open permissions. To attackers, an SMB is a stepping stone: they use it as a backdoor into their corporate clients, or simply to collect a ransom the company can actually pay.
According to Mexico's Cyber Police and INEGI data, in 2024 over 60% of SMBs hit by a serious incident took more than three months to recover, and a significant percentage shut down operations within six months. The question is no longer if you'll be attacked — it's when.
The 2025-2026 threat landscape
1. Phishing and spear phishing
Still the #1 vector. Today's emails aren't the obvious "Nigerian prince" scams; they perfectly mimic suppliers, banks, and tax authorities (SAT). They include links to fake portals that capture credentials in real time.
2. Ransomware
The business model has changed. They now use double extortion: they encrypt your files and threaten to leak sensitive data if you don't pay. Manufacturing, logistics, and financial services in Mexico have been particularly targeted.
3. Business Email Compromise (BEC)
Impersonation of a CFO or supplier requesting urgent wire transfers. Average damage per incident exceeds USD 125,000 according to the FBI.
4. Supply chain attacks
Compromising a software vendor (think SolarWinds, MOVEit, Kaseya) to reach its clients. If you use SaaS or a third-party MSP, you're exposed too.
5. Dark web exposure
Stolen credentials, customer databases, and engineering drawings are traded every day. A simple lookup of your company domain can reveal leaked passwords before you even notice.
Non-negotiable minimum controls
If you can only do five things this quarter, make it these:
1. MFA on everything
Enable two-factor authentication on email, VPN, firewall admin panels, and any cloud service. SMS works, but an authenticator app or physical key (FIDO2) is better.
2. Patching and updates
Turn on auto-updates for operating systems, browsers, and network devices. 80% of successful attacks exploit vulnerabilities with patches available for over a year.
3. Verifiable 3-2-1 backups
Three copies, on two different media, with at least one off-site. Most importantly: test them. A backup you can't restore isn't a backup.
4. Least privilege principle
Each user only accesses what they need. Remove orphan accounts, segment the network (offices, servers, OT), and review who has admin permissions.
5. Continuous awareness
One training per year doesn't work. Run brief monthly phishing drills (5 minutes), report outcomes without pointing fingers, and reward people who report suspicious emails.
Phased roadmap (12 months)
Phase 1 — Months 1-3: Stabilize
- Asset inventory (endpoints, servers, cloud services)
- MFA on all critical services
- Automated, tested backups
- Password policy with a manager (Bitwarden, 1Password)
- Estimated cost: low. Most of these are configuration tasks.
Phase 2 — Months 4-6: Harden
- Automated patching (Windows Update for Business, WSUS, or apt-cron on Linux)
- EDR or next-gen antivirus on endpoints
- Next-gen firewall with TLS inspection
- Network segmentation (VLANs for office, servers, guest WiFi)
- Estimated cost: medium. Talk to your MSP about a bundle.
Phase 3 — Months 7-12: Mature
- Formal written security policy
- Incident response plan with defined roles
- Annual penetration testing or vulnerability assessment
- Consider NIST CSF 2.0 or ISO/IEC 27001 certification depending on industry
- Compliance: LFPDPPP, NOM-151, CNBV regulation if handling financial data
What to do when (not if) you get hit
- Disconnect, don't power off. Powering off can destroy volatile evidence.
- Call the expert. Your MSP, an incident response (IR) provider, or law enforcement.
- Don't pay immediately. Each case is different; paying doesn't guarantee recovery.
- Document everything from minute one: what happened, when, who was affected.
- Communicate with customers and authorities per regulation (LFPDPPP requires breach notification).
Where to start today
You don't need a CISO or a SOC to begin. You need a designated owner (could be your MSP or your IT director) executing it, clear metrics, and an assigned budget.
At JMSERVICES, we help SMBs build their cybersecurity posture from scratch: from initial assessment to control implementation, team awareness, and audit preparation.
Ready to start? Reach out and let's schedule a free 30-minute diagnostic.
Need help? JMSERVICES offers cybersecurity assessments, MFA rollout, network segmentation, and incident response plans for SMBs in Mexico and the northern border region.
Request a diagnostic →