By
Logiks Lab
Published on
June 17, 2026
Updated on
August 13, 2026

Backups, MFA, messaging: the minimal cyber base for an SME in 2026

Protect cyber essentials before the incident: access, backups, messaging and recovery.

Computer in a cyber security context, illustration of the minimal cyber base of an SME.
Type
Practical guide
Level
Intermediate
Reading time
17
Progress0 %

Your cybersecurity shouldn’t start with a tool.
It begins with what allows us to hold on, resist, restart.

1. Key figures

NumberWhat to UnderstandSource
80 %In the ImpactCyber study 2025, 80 % VSEs-SMEs say they are not prepared for attacks or are unaware of it. Maturity progresses, but taking action remains fragile.Cybermalveillance.gouv.fr - ImpactCyber Memento 2026
16 %16% of the SMEs surveyed reported having experienced one or more cyber incidents in the past 12 months. The topic is no longer restricted to large groups.Cybermalveillance.gouv.fr - ImpactCyber Memento 2026
6 167 violationsIn 2025, the CNIL received 6 167 notifications of data breaches, up from 9,5 %; one in two reported incidents involves hacking.CNIL - Annual Report 2025
2 700 requestsCybermalveillance.gouv.fr lists 2 700 assistance requests related to ransomware in 2025, or +10 %, including 1 691 for professionals.Cybermalveillance.gouv.fr - Activity report 2025
128 compromisesANSSI indicates that 128 ransomware compromises were brought to its attention in 2025; SMEs, VSEs and ETIs remain the most affected category.ANSSI - Panorama of the cyberthreat 2025
42 measurementsThe ANSSI IT hygiene guide offers 42 simple security rules to strengthen an information system. An SME can use it as a roadmap.ANSSI - IT hygiene guide
$4.4 millionIBM estimates the global average cost of a data breach to be 4,4 million in 2025. This figure is not an SME cost, but it gives the economic order of magnitude of the risk.IBM - Cost of a Data Break Report 2025

2. Introduction

An SME rarely lives in a spectacular information system. It lives in an email Microsoft 365 or Google Workspace, business software, a CRM, a website, a few workstations, shared folders, service provider access, accounting files, sometimes a local server that no one really dares to touch anymore. Nothing grandiose. Everything is essential.

We defend a simple position: the cyber base of an SME is not reduced to a collection of tools. We are talking about an architecture of continuity. It protects what allows you to work Monday morning, send an invoice, respond to a customer, restore a file, remove access, contain an attack, speak clearly to your teams.

The drive problem often comes down to a few symptoms: reused passwords, missing double authentication, backups never restored, exposed messaging, old active service provider accounts, postponed updates, no procedure if a workstation behaves badly:
The SME is working, but it does not yet know if it can restart.

Without a tested backup, recovery remains theoretical.
Without MFA, the border remains fragile.
Without an incident reflex, control disappears.

3. Symptoms: when an SME depends on digital fragile

We recognize an organization exposed to very concrete details. The manager does not know who actually administers the accounts. The service provider maintains permanent access "just in case". Employees use their email as a document safe. Important quotes sleep in a shared folder without clear rules. The CRM exports files that no one purges. The backups exist, but no restoration test has been carried out since their implementation.

On a normal day, everything seems to hold up. On the day of the incident, every approximation becomes a debt.

Phishing doesn't need a naive company. All he needs is an emergency, a credible attachment, a fake provider, a connection link, an account without double authentication. Ransomware does not need to understand your strategy. All he needs is a compromised computer and a path to the useful files.

A large organization has teams, constraints, procedures and segmentation; an SME often depends on a handful of people. This proximity can be a strength: rapide decision, shorter inventory, direct arbitrages. It can also become a fragility if no one brings up the subject.
For an SME, cybersecurity is less about sophistication than discipline.

4. Actors: ANSSI, Cybermalveillance.gouv.fr, CNIL, manager, service provider, insurer

A defensible cyber base must name the actors. Otherwise, responsibilities are diluted between "IT", "the service provider", "management" and "management". and "users".

ActorRoleWhat needs to be clarified
LeaderArbitrate risk, budget, business continuity.Critical data, acceptable downtime, level of tool dependency.
Internal referentMonitors accounts, procedures, alerts, service provider requests.Who validates new access, who closes an account, who triggers the alert.
IT service providerConfigures stations, accounts, backups, messaging, security.Contractual scope, response times, evidence, reports, admin rights.
ANSSINational framework, guides, recommendations, threat overview.Hygiene measures, backups, access, incidents, mapping.
Cybermalveillance.gouv.frAssistance to victims, practical resources, ExpertCyber connection.Diagnosis, good practices, certified service providers, SME trends.
CNILProtection of personal data, violations, controls and sanctions.Data security, notification, RGPD, subcontractors, evidence.
Cyber insurerPartial transfer of financial risk under conditions.Exclusions, prerequisites, declaration, security proofs, franchise.
Editors SaaSMicrosoft, Google, CRM, business tools, backup, email security.MFA, logs, recovery, roles, backup, reversibility.

ANSSI provides the backbone, Cybermalveillance.gouv.fr provides the field reflex. The CNIL recalls the security obligation, the service provider must produce proof. The insurer promises coverage, the manager must understand the conditions.
Responsibility cannot be entirely outsourced. She gets organized.

5. Definition: what is a minimal cyber base

The minimum security base designates the set of priority measures which allow an SME to limit the most common compromises, protect its critical data, maintain controlled access and resume its activity after an incident.

This definition matters. It excludes two symmetrical errors: reducing cybersecurity to an antivirus, or transforming it into an inaccessible program. This base lies between the two. It does not claim to cover all scenarios. It first addresses high probability and high impact risks: loss of access, email compromise, file encryption, data leak, business interruption, loss of trust.
The minimum base does not promise invulnerability. It creates a capacity for resistance.

6. Why this is becoming a priority in 2026

80 % of VSEs-SMEs surveyed by the ImpactCyber study 2025 declare that they are not prepared for attacks or are unaware of them (Cybermalveillance.gouv.fr, ImpactCyber Memento 2026). This figure does not mean that leaders are losing interest in the subject. He says something more precise: consciousness progresses faster than execution.

The threat does not wait. Cybermalveillance.gouv.fr indicates that support requests related to data breaches have jumped from 107 % to 2025, all audiences combined. The CNIL notes a record of 6 167 violations notified, with piracy in one out of two reported cases. ANSSI is still observing 128 compromises by ransomware brought to its attention, with SMEs, VSEs and ETIs as the most affected category.

The cultural context has also changed. The customer is less accepting of digital amateurism. The employee wants to know what to do. The partner sometimes asks for guarantees. The insurer questions backups, access, MFA. The service provider himself must document his interventions. The subject leaves the technical back kitchen.
It becomes a condition of seriousness.

7. The five pillars: backups, MFA, messaging, updates, response

The minimum base stands on five pillars. Not because the rest would be useless, but because these five areas concentrate the prevention and recovery capacity.

PillarObjectiveExpected proof
BackupsRestart after crash, error, theft, encryption or deletion.Plan 3-2-1, offline copy, restore test dated, responsible identified.
M.F.A.Prevent a stolen password from being enough to enter.Double authentication required on messaging, cloud, CRM, admin, bank, CMS.
MessagingReduce the risk of phishing and account compromise.Filtrage, SPF/DKIM/DMARC, awareness, reporting, forwarding rules monitored.
UpdatesCorrect flaws before exploitation.Software inventory, patch schedule, tracking of obsolete equipment.
ReactionKnow what to do during the first few hours.Reflex sheet, contacts, handbook, service provider, complaint, CNIL notification if necessary.

These five pillars are not a substitute for a comprehensive cyber strategy. They give a starting plan. In an SME, starting from there has a rare merit: management understands it, the service provider can execute it, the team can verify it.
This is not a catalog. It's a foundation.

8. Recommended method: 9 blocks to build a defensible base

The method recommended below is not a proprietary method Logiks. It is based on the ANSSI guides, the Cybermalveillance.gouv.fr resources, the security obligations of RGPD and good business continuity practices.

In the workshop, we move forward as if we were setting up a kitchen: identifying critical products, tidying up the work surface, locking access, checking the cold, preparing for the next day's service. No theater. Gestures that stick.

8.1. Identify critical data and services

Start with the most direct question: what do you absolutely need to recover to work tomorrow? Customer file, accounting, quotes, orders, emails, business software, contracts, product catalog, HR data, e-commerce site, banking access, CRM.

ANSSI reminds that each entity has sensitive data and that it is necessary to identify where it is located to protect it. This mapping can be kept simple. Above all, it requires regular updating.
Without inventory, a backup feels like a prayer.

8.2. Setting up backups 3-2-1

The ANSSI guide dedicated to VSEs-SMEs recommends applying the rule 3-2-1: 3 backup copies, on 2 different media, including 1 offline. He also insists on regular restorations.

The important point is not just to save. It must be restored. An SMB may cro have technical assurance but only have a silent disk, a poorly configured cloud option, or a synchronized copy that will encrypt the same files as the compromised computer.
An untested backup remains a hypothesis.

8.3. Enable MFA on critical accounts

Double authentication must primarily cover messaging, administrator accounts, the cloud, CRM, financial tools, CMS, social networks, advertising accounts and service provider access.

Cybermalveillance.gouv.fr recommends activating double authentication whenever possible. ANSSI formulates the same priority in its golden rules. For an SME, MFA is less about comfort than about minimal barriers. It mechanically reduces the domino effect of a compromised password.
The password alone belongs to another era.

8.4. Secure messaging

Messaging constitutes the central workshop of the SME: quotes, invoices, customer requests, attachments, connection links, bank exchanges, reminders. It therefore concentrates phishing, theft, transfer fraud and account compromise.

The check should cover anti-spam filtrage, MFA, auto-forwarding rules, delegated accounts, shared mailboxes, SPF, DKIM and DMARC settings, and the ability of employees to report a suspicious message.
We cannot secure an SME if its messaging remains like a swinging door.

8.5. Manage passwords with a vault

A password manager should replace Excel files, notebooks, post-its, phone notes and lazy reuse. It makes it possible to generate unique secrets, share certain accesses without circulating them in the clear and to properly withdraw rights when leaving.

This measure lacks spectacularity. It remains structuring. It reduces dependence on individual habits and provides a basis for moving to cleaner accesses.
Hygiene often starts with stopping tinkering with secrets.

8.6. Reduce rights and delete dormant accounts

Administrator accounts, service providers, former employees, interns, third-party tools and connections API must be inventoried. ANSSI recommends nominative accounts, the distinction between user and administrator roles, as well as the regular review of sensitive access.

In an SME, the danger hides in convenience: a shared account to save time, admin access retained for troubleshooting, a generic mailbox known to three service providers, a bank account without strong validation.
Minimum privilege is not a theory. It’s hygiene.

8.7. Update workstations, servers, CMS and SaaS

The updates correct flaws that attackers know how to industrialize. The difficulty is not in principle. It is located in the inventory: computers, mobiles, browsers, extensions, plugins, CMS, routers, NAS, business software, remote management tools.

There are three rhythms: critical updates to be applied quickly, routine updates to plan, obsolete equipment to replace. An old NAS forgotten in a closet doesn't become less vulnerable because it's discreet.
The invisible heritage always ends up speaking.

8.8. Prepare the incident reflex sheet

The ANSSI guide intended for VSEs and SMEs invites you to prepare before the incident, to know how to disconnect equipment, not to turn off compromised equipment, to maintain a handrail and to file a complaint. These gestures cannot be improvised under pressure.

The reflex sheet must fit on one page: who to call, what to cut, what to preserve, where to find backups, how to contact the service provider, who notifies management, who speaks to customers, when to evaluate a CNIL notification.
Calm in crisis is created before the crisis.

8.9. Test, document, redo

This database only has value if it is tested: restoration of a file, recovery of an account, deletion of an old access, reporting of a suspicious e-mail, resuming on an emergency station.

The documentation must remain sober: dates, persons responsible, proofs, captures, links, contracts, decisions. We are not trying to produce an admirable workbook. The goal is to be able to prove, understand and repeat.
Repetition builds resilience.

9. Logiks Tips: Protect first which allows you to restart

We recommend not starting by purchasing a new tool if no one knows how to answer three questions: what data runs the business, who can access it, how can we restore it?

First tip: prioritize recovery before perfection. In many SMBs, the best initial investment is not a security dashboard. We're talking about a well-thought-out, offline, witnessed-restored backup with a real, measured turnaround time.

Second tip: impose MFA on the accounts that control the rest. Messaging, cloud, administration, banking, CRM, CMS, advertising, social networks. If the team resists, start with critical accounts. Then generalize.

Third tip: treat messaging as strategic infrastructure. It carries the commercial relationship, proof, invoices, reminders, HR requests, reset links. Its compromise often gives access to the rest.

Fourth tip: ask the service provider for proof. Not a speech. A list of accounts, a backup policy, a tested restoration date, an MFA status, a workstation inventory, a departure procedure, an incident plan.
Finally, we recommend creating a very simple control table:

  • critical data or service;
  • business manager;
  • tool concerned;
  • administrator account;
  • backup;
  • MFA;
  • date of last test;
  • next action.

This table does not replace a strategy. It avoids driving in fog.

10. Maturity grid: can your SME last 72 hours?

CriterionFragileCorrectMastered
Critical dataNot listedPartial listData, tools and managers identified
BackupsPresumedAutomated3-2-1, offline, restore tested
M.F.A.Absent or optionalEnabled on some accountsMandatory on critical and service provider accounts
MessagingFiltrage basicOccasional awareness raisingMFA, filtrage, DMARC, reporting, monitored rules
RightsShared accountsIrregular reviewNominative accounts, processed departures, limited rights
UpdatesAlong the waterInformal calendarInventory, critical prioritization, obsolescence monitoring
IncidentNobody knows what to doIdentified service providerReflex sheet, contacts, handrail, exercises
RGPDImpromptu reactionDPO or known adviceviolation procedure, evidence, notification if necessary

If backups and mail are in "Fragile", start there. The rest will make more sense later.

11. Common Mistakes: Six Costly Shortcuts

First pitfall: croire that the cloud backs up everything. Synchronization is not a backup. It can replicate a deletion, error, or encryption.

Second drift: activate MFA only for the steering. Assistants, salespeople, work-study students, agencies and service providers also handle sensitive access. The attacker often chooses the path less guarded.

Third weakness: confusing antivirus and cybersecurity. An antivirus can help. It does not replace backups, MFA, updates, or rights management.

Fourth pitfall: letting former accesses live out their retirement in the system. A service provider account, a shared mailbox, a API key or a forgotten CMS access retains the capacity to cause nuisance.

Fifth risk: writing a procedure that no one knows. In an incident situation, a file that cannot be found in an encrypted file is of no use. It must exist offline and be known to key people.

Last point: buy before arbitrage. The cyber market is full of useful tools. Without inventory, without priorities and without a manager, they become an additional layer of complexity.

12. Action Plan 30 / 60 / 90 days

12.1. Within 30 days

  • list critical data and tools;
  • identify administrator accounts;
  • activate MFA on messaging, cloud, CRM, CMS and banking;
  • check existing backups;
  • carry out a first restoration test;
  • remove access from former employees and service providers;
  • write a one-page incident reflex sheet.

We are not yet looking for elegance. We close the blind spots that can stop the activity.

12.2. Within 60 days

  • apply a rule 3-2-1 for critical data;
  • set up a password manager;
  • configure SPF, DKIM and DMARC with the service provider;
  • formalize arrival and departure procedures;
  • establish an update schedule;
  • document incident contacts: service provider, insurer, bank, CNIL if necessary;
  • raise awareness among teams with real examples.

The device begins to become visible.

12.3. Within 90 days

  • review rights to sensitive files and tools;
  • test a job or account loss scenario;
  • check connection logs on critical accounts;
  • audit unused SaaS tools;
  • provide an annual budget for maintaining security conditions;
  • ask the service provider for a sober quarterly report;
  • link this cyber base to the business continuity plan.

At this stage, the SME does not claim to have control over everything. She knows how to take it better.

13. FAQ: minimal SME cyber base

13.1. What is the first cyber measure to implement in an SME?

The first step depends on the context, but the best starting point is to identify critical data and verify backups. Without restoration possible, any other measure protects an activity which may remain paralyzed.

13.2. Is double authentication really necessary?

Yes. A stolen, reused or guessed password should not be enough to open email, cloud, CRM or administrator account. MFA doesn't prevent all attacks, but it closes one very common door.

13.3. Is a cloud backup enough?

Not alone. The ANSSI recommendation is to supplement online backups with offline or disconnected copies, according to the rule 3-2-1. The restoration should be tested regularly.

13.4. Who should raise the issue in an SME?

The management must carry the arbitrage, even if the execution is the responsibility of a service provider or an internal referent. Cybersecurity affects continuity, customers, cash flow, reputation and data. It goes beyond simple technical adjustment.

13.5. Do you need cyber insurance?

It can be useful, but it does not replace basic measurements. Before signing, you must look at the prerequisites, exclusions, deductibles, declaration deadlines and proof requested. Insurance transfers part of the risk. It does not restore unsaved data.

13.6. What to do if a position seems compromised?

It is necessary to isolate the equipment from the network, avoid destroying the evidence, notify the referent or service provider, maintain a handrail and carefully assess the impact. In the case of personal data, a CNIL notification may be necessary. In the event of a ransom, public sources recommend not paying.

14. Conclusion: the cyber base becomes a discipline of continuity

For an SME, cybersecurity does not start with fear. It begins with a manager's question: what do we need to protect to continue working?

Backups respond to recovery. MFA responds to access. The voicemail responds to the entry. Updates address known vulnerabilities. The incident sheet responds to the disorder. Together, these measures form a sober, readable, defensible architecture.

We are not seeking to transform each SME into a security operational center. We are trying to eliminate absurd fraguities: shared account, backup never tested, email without MFA, forgotten service provider, non-existent procedure.

It's no longer an IT expense.
Security becomes a discipline of continuity: protect, hold, restart.

15. Main sources

  • Cybermalveillance.gouv.fr - Activity report 2025 - published in March 2026 - https://www.cybermalveillance.gouv.fr/medias/2026/03/RA_2025_Cybermalveillance_gouv_fr.pdf
  • Cybermalveillance.gouv.fr - News activity report 2025 - published in 2026 - https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/rapport-activite-2025
  • Cybermalveillance.gouv.fr - ImpactCyber TPE-PME memento - version 2026 - https://www.cybermalveillance.gouv.fr/medias/2020/04/20260112-PM-GIP-ACYMA-MEMENTO.pdf
  • Cybermalveillance.gouv.fr - 10 essential measures to ensure your cybersecurity - updated on May 7 2026 - https://www.cybermalveillance.gouv.fr/tous-nos-contenus/bonnes-pratiques/10-mesures-essentielles-assurer-securite-numerique
  • ANSSI - Cyber threat overview 2025 - published in 2026 - https://www.cert.ssi.gouv.fr/uploads/CERTFR-2026-CTI-002.pdf
  • ANSSI - Cybersecurity for VSEs/SMEs in 13 questions - version 2024 - https://messervices.cyber.gouv.fr/documents-guides/20241212_np_anssi_guide_tpe-pme_v2.pdf
  • ANSSI - IT hygiene guide: strengthening the security of your information system using 42 measures - https://messervices.cyber.gouv.fr/documents-guides/guide_hygiene_informatique_anssi.pdf
  • ANSSI - 10 golden rules for digital security - consulted on 17 June 2026 - https://cyber.gouv.fr/securisation/10-regles-or-securite-num%C3%A9rique/
  • CNIL - Annual report 2025 - published on May 18 2026 - https://www.cnil.fr/fr/rapport-annuel-2025
  • IBM - Cost of a Data Breach Report 2025 - accessed on 17 June 2026 - https://www.ibm.com/reports/data-breach