I heard the line again last month, this time from the owner of a nine-person HVAC company just outside Madison. “Grant, who’s going to hack us? We’re nobody.” I spent over a decade in IT operations and compliance for small and mid-sized businesses, and “we’re too small to be targeted” remains the most expensive sentence in small business security. It is expensive not because attackers have a grudge against small offices, but because the belief quietly postpones the unglamorous work — the office network security basics — that decides whether a random Tuesday phishing email becomes a bad month for your company. Nobody picked that HVAC owner. Something just found an open door and walked through it.
Most Attacks Are Drills, Not Daggers
The lie rests on an old mental model: a hooded figure in a dark room choosing victims one at a time, weighing which company is worth the effort. That is not how most modern intrusions work. The bulk of the attacks that reach small offices are automated and opportunistic — software that scans address ranges, tries lists of stolen passwords against login portals, and blasts phishing waves to every email address it can scrape off a website. The system on the other end never asks how many employees you have.
Why Automation Erased “Too Small”
When I say automation, I mean simple economics. Sending a fraudulent invoice email costs effectively nothing, so it gets sent to everyone. A scanner checking for exposed remote-access services has no idea whether the device behind an address belongs to a regional bank or a three-person bookkeeping firm. If the door opens, somebody walks through. In my experience, the offices that got hit were hit because of a default password, an unpatched plugin, or one tired employee clicking a link at 4:45 on a Friday — not because of who they were or how big they were.
There is something almost comforting in that. It means your risk has very little to do with being “somebody” and almost everything to do with whether the obvious doors are locked. My “Avoidable Problems” notebook — the running log of recurring office mistakes I have kept for years — has an entire section of incidents that trace back to the assumption that nobody was looking. Somebody is always looking. They just are not looking at you specifically.

The Three Doors Small Offices Leave Open
When I walk through a small office for the first time, the same handful of entry points show up again and again, regardless of industry. The table below maps the three doors I most commonly find propped open, and why office network security basics — not enterprise-level spending — is what closes them.
Entry point | What it looks like in a small office | Why being small doesn't protect you |
|---|---|---|
Phishing and fake invoices | A “CEO” wire-request email, a fake printer invoice, a spoofed vendor update | Phishing runs on volume; every scraped address receives the same email |
Exposed remote access | A router's admin page or remote desktop service reachable from the internet | Scanners probe every address equally and never check your headcount |
Neglected updates and shared logins | An aging server, a shared admin password, laptops nobody restarts | Automated exploits hunt for known weak spots regardless of company size |
None of those doors requires a sophisticated attacker, and all three are closed by fundamentals: spam filtering, multi-factor authentication, managed updates, and unique accounts for each person. That is exactly why I keep telling clients that office network security basics outperform wishful thinking — they address how untargeted attacks actually arrive, rather than the fantasy version where a criminal case-studies your company first.

What the Lie Actually Costs
A 22-person insurance agency I worked with learned this the hard way. A single compromised mailbox was used to send a fake change-of-banking-details email to one of their clients. Nobody lost the farm, but the recovery consumed weeks: forensic review, awkward client notifications, company-wide credential resets, and a tense conversation with their cyber insurance carrier. The direct dollar loss was small. The time and the trust were not.
The hidden costs compound in ways owners rarely price in. Cyber insurance applications now ask pointed questions about multi-factor authentication, backups, and endpoint protection — answer them carelessly and premiums climb or coverage narrows. Larger customers increasingly send security questionnaires before they will sign a small vendor, and “we're too small to matter” is not an answer that reassures anybody. Downtime also hits a ten-person office harder than a large one, because there is no bench of spare staff to absorb the disruption. “Too small to be targeted” becomes “too small to absorb the hit” remarkably fast.
Where to Start When You Have No Security Staff
You do not need a security department. You need a short, honest list that matches how untargeted attacks actually arrive, and someone who owns it part-time. This list is what office network security basics look like once you strip away the jargon.
Turn on multi-factor authentication for email, accounting, and remote access first — those are the accounts that get abused.
Assign one person to own updates: a recurring calendar block to patch laptops, servers, and that networking equipment nobody has logged into since installation day.
Put real backups on at least one system, and test a restore once. An untested backup is a hope, not a plan.
Run one short annual session on cybersecurity habits for employees, built around the scams your office actually receives, not generic fear clips.
Write down who to call before an incident happens: your IT provider, your insurance contact, and whoever speaks for the company.
That list will not make you untouchable — nothing will. It makes you inconvenient, and for an automated attack that has a thousand other doors to try, inconvenient is most of the game. Security gets easier when the rules make sense, and the rules make far more sense once you accept that the internet does not know how small you are.
No signals yet — transmit the first.