Improving your cyber resilience: how do you choose the right cybersecurity solution? As an SME owner reading this article, you already know it is time to strengthen your cyber resilience, whether because your customers are asking for it or because you are considering the potential risks. In this article, we discuss how to choose the best solution for your business. After all, you need to do enough to protect your business while keeping costs as low as possible.
In this article, we explore the cybersecurity solutions available and explain which are best suited to different types of businesses. We spoke to two experts:
It all starts with a thorough understanding of your current situation. Marcel Spruit emphasises the importance of identifying your risks: "What are your crown jewels? Who has access to what, and can we control that? What would you definitely not want to happen?"
For SMEs in manufacturing, this may mean taking a critical look at your production processes, customer data and intellectual property. Which systems are crucial to your daily operations? Which data would have catastrophic consequences if it fell into the wrong hands?
Risk evaluation is a crucial step in assessing your cybersecurity position. This involves business risks as well as technical risks. Raymond Bierens explains that a business’s risk depends on many factors:
Although we are discussing SMEs as if they were a homogeneous group, nothing could be further from the truth. Raymond Bierens prefers to distinguish between businesses with low, medium and high levels of maturity. A business with a single computer on the factory floor that is not connected to the IT network, and whose staff mainly need access to email, Word and PowerPoint, might only need the Microsoft 365 cloud solution. “That is actually the simplest option. The cloud is so much more secure than you can make an IT network yourself. It is almost impossible to match. You still need to decide which cloud solution is right and secure for you, but that is an easier choice to make," he says.
We will say little about highly mature SME teams in this article, as these businesses have their own security teams. “The most difficult group sits in the middle: medium maturity. There are many of these at Greenport [the horticultural cluster in North Holland, the Netherlands]. These businesses have OT software that is sometimes connected to the IT network. They also have an IT server in the basement and a cloud solution. They need to ask themselves: how important is IT to my business, and do I need everything I currently use?” He recommends that these businesses seek out a trusted adviser who can help.
Alongside their level of maturity, factors they will consider include:
Marcel Spruit argues that using technology starts with understanding it. "If you do not even know there are cables where you would not expect them, or if maintenance engineers are moving between computers and automated systems with USB sticks, you still have a lot of work to do."
He continues: "Next, you need to recognise that computers and automated systems are not inherently cybersecure. You have to work on that. The Digital Trust Centre (DTC) has set out five steps for securing computers and automated systems. If you have done little or nothing in this area, those are the first things you need to address.”
What stands out about these steps is that they do not immediately focus on technical products you need to buy:
Clearly, technological solutions are the final step. "First, you need understanding and awareness. Then you need to organise cybersecurity, and only after that do technical tools come into play. These might include firewalls, anti-malware, anti-spam and automated patching."
What types of cybersecurity solutions are available, and does your business need them? We have listed them in the table below. Does your business need all of these solutions to stay secure? Probably not.
Raymond Bierens warns: "You can choose an impressive SIEM solution, but it is expensive and complex. It only really works if everything else is already very well organised." If you do not know exactly what a solution does, you probably do not need it. Everything starts with a risk assessment, which should establish what you do and do not need to protect.
The following overview lists the main technological solutions, the risks they address and when they are less relevant.
| Solution | Description | Problems and risks addressed | Less relevant for: | Example suppliers: |
|---|---|---|---|---|
| Antivirus | Basic anti-malware software | Protects against viruses, malware and other malicious software. Risk without it: infections can lead to data loss, theft of business information or systems becoming unusable. | Bitdefender is included as standard with Microsoft 365. |
|
| Firewall | Basic network security | Blocks unauthorised access to the network. Risk without it: hackers can gain access more easily and steal sensitive data or damage systems. | Businesses without their own network. |
|
| VPN | Secure remote access | Provides a secure connection for remote workers. Risk without it: insecure connections can allow business data to be intercepted. | Businesses without remote workers or remote access to business systems, or those that work exclusively in the cloud. |
|
| Cloud storage | Secure file storage and sharing | Prevents data loss and enables secure sharing. Risk without it: loss of important documents if a device fails, and insecure sharing of sensitive information. | Businesses with highly sensitive data that must remain on-premises. |
|
| Password manager | Management of strong, unique passwords | Prevents the use of weak or reused passwords. Risk without it: accounts are easier to compromise, with a potential domino effect from a single data breach. | Very small businesses that make minimal use of online services. |
|
| Multi-factor authentication | An extra layer of account security | Prevents unauthorised access even if passwords are stolen. Risk without it: a greater likelihood of account takeovers. | Businesses without sensitive online accounts or services. |
|
| Email security | Protection against phishing and spam | Filters malicious emails and prevents phishing attacks. Risk without it: a greater likelihood of successful phishing attacks and malware infections via email. | Businesses that do not use email for communication. |
|
| Secure backups | Regular backups of important data | Protects against data loss caused by ransomware, system failures or human error. Risk without it: permanent loss of critical business data. | Businesses without their own digital data, or those that work entirely in the cloud with built-in backup. |
|
| Security awareness training | Employee education | Reduces the risk of human error in cybersecurity. Risk without it: employees remain the weakest link in security. | Sole traders with no employees. | Both free and paid training courses are available online, as well as bespoke training. |
| Updating and patching | Automatic software updates | Closes known software vulnerabilities. Risk without it: systems remain vulnerable to known exploits. | Businesses without their own IT infrastructure, or those using fully managed services. | This is usually handled by an internal IT team or the IT administrator. |
| Endpoint protection | Basic protection for computers and mobile devices | Protects against malware, ransomware and other threats on end-user devices. Risk without it: a greater likelihood of successful attacks on individual devices. | Businesses without their own devices, or those using only thin clients. | Depends on requirements. |
| MDR (Managed Detection and Response) | Outsourced security monitoring and response. Can be viewed as an outsourced form of SOC services that uses SIEM technology. | Provides round-the-clock monitoring and rapid expert response to threats. Risk without it: slower detection and response to attacks, potentially resulting in greater damage during an incident. | Businesses with a minimal digital presence or non-critical data. | SBL Cyber Monitoring |
| SIEM (Security Information and Event Management) | A centralised system that collects, analyses and correlates security data from different sources across a network to detect and respond to threats. Can be used by an internal SOC or an external MDR service. | SIEM addresses delayed or missed detection of complex cyberattacks through real-time monitoring, analysis and security incident alerts across the entire IT infrastructure. | Small businesses with simple IT infrastructure, a limited digital presence or non-critical data. |
|
| SOC (Security Operations Centre) | An outsourced security centre. A SOC is an overarching security function (a team) that often uses a SIEM system as one of its main tools. | A central point for security operations, incident response and compliance. Risk without it: a lack of a coordinated approach to security incidents and possible failure to meet sector-specific regulations. | Small businesses without complex IT environments or specific compliance requirements. |
|
Before making a final decision, it is sensible to test potential solutions. This can help you determine whether a solution actually fits your business processes and whether your team can work with it.
After selecting and implementing a solution, ongoing monitoring and evaluation are crucial. Marcel Spruit emphasises: "Whatever solutions you choose, monitoring and maintenance are needed to keep them working to the required standard. The director is responsible for the organisation and therefore also for the solutions it uses. The director can of course delegate this, but only to an employee who has sufficient knowledge and time, and who keeps the director informed. The director must continue to take an interest in this subject."
Choosing the right cybersecurity solution for your manufacturing SME is no simple task. It requires a thorough analysis of your current situation, a clear understanding of your risks and security objectives, and careful consideration of the different solutions.
Raymond Bierens sums it up neatly: "The answer is always: 'it depends'. Are we talking about the cloud? Are we talking about management? Do you handle it yourself, or does someone else?"
Marcel Spruit emphasises the importance of a holistic approach: "Cybersecurity starts with simple measures, but as automation becomes larger, more complex and more important, more extensive and complex measures are needed to remain cybersecure."
Ultimately, the aim is to choose a solution that fits your specific situation and strengthens your cyber resilience without disrupting your business processes. By following expert advice and taking a step-by-step approach, you can make an informed decision that protects your business against continually evolving cyber threats.
Would you like advice, with no obligation, on your IT and OT infrastructure and whether it is properly secured? Get in touch. At SBL Cyber Monitoring, we are always available to offer advice without obligation, even if it turns out that your business does not need an MDR solution.
Get advice, with no obligation →
Raymond Bierens is a leading cybersecurity expert and strategic adviser with more than 20 years of experience in the sector. As a board member of the Dutch Institute for Vulnerability Disclosure (DIVD) and Chair of the Connect2Trust Foundation, he advises public and private sector organisations on digital risks and cybersecurity strategies, particularly during major digital transformations. In his role as a researcher at Vrije Universiteit Amsterdam, Bierens is developing a digital risk management framework to support leaders and supervisory bodies. His research focuses on the complex relationship between executives and technical teams, with an emphasis on improving mutual understanding and effective collaboration in managing digital risks.
Marcel Spruit is Professor of Cyber Security & Safety at The Hague University of Applied Sciences, with more than 30 years of experience in the field. He leads a research group studying the human factor in cybersecurity, focusing on cybersecurity governance and awareness. His research centres on non-profit organisations such as municipalities, water authorities and hospitals, exploring how people and organisations can be effectively motivated to implement cybersecurity measures. Spruit’s work highlights the crucial role of human behaviour and organisational processes in strengthening cybersecurity alongside technical solutions.