Guide · 8 min read

Security for small Namibian businesses: what actually matters first

A prioritised, honest list for organisations with a small budget, no security staff, and something worth protecting.

Small does not mean overlooked

The assumption that a small business is too small to be targeted misunderstands how most attacks work. The majority are automated and indiscriminate: scanning for exposed services, spraying stolen credentials, and delivering ransomware to whoever opens the attachment. None of it evaluates whether the target is interesting.

The consequences also fall harder. A large organisation absorbs a week of disruption. A twenty-person business frequently cannot, and the incidents that close small companies are rarely sophisticated - they are ordinary attacks against organisations that had no way of noticing.

First: the things that are free or nearly free

Do these before spending anything. In terms of risk reduced per rand, nothing else comes close.

  • Enable multi-factor authentication on email, remote access and anything financial. Email compromise is the single most common route to loss for small businesses here, and this largely closes it.
  • Get backups off-site and offline, then restore one. Ransomware makes backups a target; a backup reachable from the network it protects will be encrypted along with everything else.
  • Patch what faces the internet. Your router, firewall, VPN and any published service. These are what automated scanning finds.
  • Remove accounts for people who have left. Dormant accounts with valid credentials are a standing invitation, and nobody notices when one is used.
  • Establish a verbal callback rule for payment changes. Any request to change banking details gets confirmed by phone, on a number you already hold - never one in the email.

Second: what is worth paying for

Once the free work is done, spending starts to make sense. Roughly in order of value.

  • Reputable endpoint protection on every machine, centrally managed so you can see whether it is actually running.
  • Email filtering with attachment and link protection.
  • Continuous monitoring, so a compromise is discovered in hours rather than at the point something visibly breaks.
  • Staff training focused on payment fraud and phishing, using examples your staff recognise rather than generic material.

What is usually not worth it yet

Being clear about this matters as much as the recommendations, because small budgets get spent on the wrong things by vendors who are selling rather than advising.

  • A penetration test before the basics are done. It will produce a long report telling you to do the things in the first section, at considerable cost.
  • Compliance certification you are not required to hold. Pursue it when a client or regulator requires it, not speculatively.
  • Buying more security products than you can operate. Three tools nobody monitors is worse than one that somebody does.
  • Cyber insurance as a substitute for controls. Insurers increasingly require the controls above as a condition, and decline claims where they were absent.

The honest position on monitoring

Continuous monitoring is worth having, and it is not the first thing to buy. If privileged accounts have no multi-factor authentication and your backups have never been tested, monitoring will detect the incidents those gaps cause rather than prevent them.

Fix the fundamentals first. Then monitoring becomes what it should be - the thing that tells you when something has got through anyway, while it is still cheap to deal with.

Get started

Find out what is actually happening on your network

A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.