
Many small and medium-sized enterprises (SMEs) still believe:
โWeโre too small to be an interesting target for hackers.โ
โ That assumption is dangerous.
In my daily work as an IT service provider, I repeatedly see that SMEs are affected particularly often โ usually because basic security measures are missing or have never been reviewed.
In this article, I highlight the five most common IT security mistakes I encounter in companies and explain how they can be avoided with reasonable effort.
โถ โWe have backupsโ โ but nobody checks them
๐ด One of the most common statements I hear.
In many companies, backups exist โ but:
- they are never tested
- they are stored on the same system
- they are affected in an incident as well
Why this is dangerous
In real emergencies, I often see companies realize too late:
The backup is incomplete, outdated, or unusable.
โฑ๏ธ The result: downtime, data loss, and costly emergency solutions.
โ How I avoid this mistake
โ๏ธ I rely on automated, regular backups
โ๏ธ I ensure separate backup targets (offline or cloud-based)
โ๏ธ I test data restoration at least once per year
โท Weak passwords & no multi-factor authentication (MFA)
๐ Weak or reused passwords are still very common.
Why this is dangerous
In my day-to-day work, I repeatedly encounter:
- compromised email accounts
- unauthorized logins from abroad
- unnoticed access over long periods
Often, a single stolen password is enough to cause serious damage.
โ How I avoid this mistake
โ๏ธ I recommend strong, unique passwords
โ๏ธ I use password managers
โ๏ธ I enable multi-factor authentication (MFA), especially for:
- email accounts
- VPN access
- cloud services
- administrative accounts
โธ Updates? โWeโll do it laterโฆโ
๐งฉ One of the most dangerous phrases in IT.
Why this is dangerous
I frequently encounter:
- outdated servers
- unpatched firewalls
- software without security updates
Attackers specifically exploit known vulnerabilities, often in an automated way.
โ How I avoid this mistake
โ๏ธ I schedule regular maintenance windows
โ๏ธ I keep operating systems and applications up to date
โ๏ธ Unsupported or outdated systems are replaced in time
โน Employees are not sufficiently aware
๐ง Even the best technology is ineffective if people are not prepared.
Why this is dangerous
In many incidents I support, the initial trigger was:
- a phishing link
- a malicious attachment
- a manipulated invoice
โ How I avoid this mistake
โ๏ธ I define clear rules for handling emails
โ๏ธ I make it clear that asking questions is always encouraged
โ๏ธ I promote an open error culture โ reporting instead of hiding mistakes
โบ No incident response plan โ โWeโll deal with it if it happensโ
๐จ Many companies assume it wonโt affect them.
Why this is dangerous
Without a plan, I regularly observe:
- chaos
- loss of valuable time
- wrong decisions under pressure
โ How I avoid this mistake
โ๏ธ I create a simple IT incident response plan
โ๏ธ I ensure important information is available offline
โ๏ธ I review the plan on a regular basis
๐ง Conclusion: IT security is a responsibility โ not a product
๐ To me, IT security does not mean:
โBuy a piece of software and youโre done.โ
It means:
- clear processes
- continuous maintenance
- informed employees
- realistic emergency planning
๐ My experience shows:
Even small, well-planned measures can significantly improve a companyโs security posture.
๐ค Free initial consultation
If you are unsure
how well your company is currently protected,
I would be happy to offer you a free and non-binding initial consultation as an IT service provider.
During this conversation, we can clarify:
- where potential security gaps exist
- which risks are realistic for your business
- and which measures are both effective and economically reasonable
๐ฌ No obligation โ but a clear and honest assessment.

