Office Proofed
Risk at Work

Why “We’re Too Small to Be Targeted” Is Still the Most Expensive Lie in Small Business Security

Why “We’re Too Small to Be Targeted” Is Still the Most Expensive Lie in Small Business Security
Small offices are rarely “targeted” at all — most attacks are automated and opportunistic, hitting whatever door happens to be open. This article explains why headcount offers no protection, which three entry points small offices most commonly leave exposed, what the “too small to matter” mindset actually costs in downtime, insurance, and client trust, and which fundamentals a small team can realistically implement without a security department.

I heard the line again last month, this time from the owner of a nine-person HVAC company just outside Madison. “Grant, who’s going to hack us? We’re nobody.” I spent over a decade in IT operations and compliance for small and mid-sized businesses, and “we’re too small to be targeted” remains the most expensive sentence in small business security. It is expensive not because attackers have a grudge against small offices, but because the belief quietly postpones the unglamorous work — the office network security basics — that decides whether a random Tuesday phishing email becomes a bad month for your company. Nobody picked that HVAC owner. Something just found an open door and walked through it.

Most Attacks Are Drills, Not Daggers

The lie rests on an old mental model: a hooded figure in a dark room choosing victims one at a time, weighing which company is worth the effort. That is not how most modern intrusions work. The bulk of the attacks that reach small offices are automated and opportunistic — software that scans address ranges, tries lists of stolen passwords against login portals, and blasts phishing waves to every email address it can scrape off a website. The system on the other end never asks how many employees you have.

Why Automation Erased “Too Small”

When I say automation, I mean simple economics. Sending a fraudulent invoice email costs effectively nothing, so it gets sent to everyone. A scanner checking for exposed remote-access services has no idea whether the device behind an address belongs to a regional bank or a three-person bookkeeping firm. If the door opens, somebody walks through. In my experience, the offices that got hit were hit because of a default password, an unpatched plugin, or one tired employee clicking a link at 4:45 on a Friday — not because of who they were or how big they were.

There is something almost comforting in that. It means your risk has very little to do with being “somebody” and almost everything to do with whether the obvious doors are locked. My “Avoidable Problems” notebook — the running log of recurring office mistakes I have kept for years — has an entire section of incidents that trace back to the assumption that nobody was looking. Somebody is always looking. They just are not looking at you specifically.

An office employee pausing before a suspicious email during office network security basics training

The Three Doors Small Offices Leave Open

When I walk through a small office for the first time, the same handful of entry points show up again and again, regardless of industry. The table below maps the three doors I most commonly find propped open, and why office network security basics — not enterprise-level spending — is what closes them.

Entry point

What it looks like in a small office

Why being small doesn't protect you

Phishing and fake invoices

A “CEO” wire-request email, a fake printer invoice, a spoofed vendor update

Phishing runs on volume; every scraped address receives the same email

Exposed remote access

A router's admin page or remote desktop service reachable from the internet

Scanners probe every address equally and never check your headcount

Neglected updates and shared logins

An aging server, a shared admin password, laptops nobody restarts

Automated exploits hunt for known weak spots regardless of company size

None of those doors requires a sophisticated attacker, and all three are closed by fundamentals: spam filtering, multi-factor authentication, managed updates, and unique accounts for each person. That is exactly why I keep telling clients that office network security basics outperform wishful thinking — they address how untargeted attacks actually arrive, rather than the fantasy version where a criminal case-studies your company first.

A hybrid worker disconnecting her laptop from the network to stop a suspected infection from spreading

What the Lie Actually Costs

A 22-person insurance agency I worked with learned this the hard way. A single compromised mailbox was used to send a fake change-of-banking-details email to one of their clients. Nobody lost the farm, but the recovery consumed weeks: forensic review, awkward client notifications, company-wide credential resets, and a tense conversation with their cyber insurance carrier. The direct dollar loss was small. The time and the trust were not.

The hidden costs compound in ways owners rarely price in. Cyber insurance applications now ask pointed questions about multi-factor authentication, backups, and endpoint protection — answer them carelessly and premiums climb or coverage narrows. Larger customers increasingly send security questionnaires before they will sign a small vendor, and “we're too small to matter” is not an answer that reassures anybody. Downtime also hits a ten-person office harder than a large one, because there is no bench of spare staff to absorb the disruption. “Too small to be targeted” becomes “too small to absorb the hit” remarkably fast.

Where to Start When You Have No Security Staff

You do not need a security department. You need a short, honest list that matches how untargeted attacks actually arrive, and someone who owns it part-time. This list is what office network security basics look like once you strip away the jargon.

  • Turn on multi-factor authentication for email, accounting, and remote access first — those are the accounts that get abused.

  • Assign one person to own updates: a recurring calendar block to patch laptops, servers, and that networking equipment nobody has logged into since installation day.

  • Put real backups on at least one system, and test a restore once. An untested backup is a hope, not a plan.

  • Run one short annual session on cybersecurity habits for employees, built around the scams your office actually receives, not generic fear clips.

  • Write down who to call before an incident happens: your IT provider, your insurance contact, and whoever speaks for the company.

That list will not make you untouchable — nothing will. It makes you inconvenient, and for an automated attack that has a thousand other doors to try, inconvenient is most of the game. Security gets easier when the rules make sense, and the rules make far more sense once you accept that the internet does not know how small you are.

Updated · 2026-09-09 14:07
Signals

No signals yet — transmit the first.

Transmit a signal
© 2026 Office Proofed. All rights reserved. rendered at 60 fps