Build
Automate
Secure
Scale
62 B2B services across 12 practice areas — all scoped, priced and delivered from Kentucky.All services Packages & pricing
Platform categories
More categories
Featured products

Ready-to-deploy B2B software

25 platforms deployable in days, customisable to your process, and available as a subscription or a one-time licence with source code.

Browse software
Industries
More industries
Evidence
Company
Services
Software Solutions
Industries
Resources
Company
Pricing & PackagesContact
Get AccessRequest a quote
Cybersecurity10 min read2026-07-08

A cybersecurity checklist for growing companies

Twelve controls, ordered by risk reduction per dollar. Most breaches at mid-market companies exploit the absence of items one through five.

Cyntra Security
Security practice

Security advice for mid-market companies tends to arrive as a list of forty controls with no ordering, which produces either paralysis or expensive work on the wrong things. What follows is ordered by risk reduction per dollar spent, based on what we actually find during assessments.

1. Multi-factor authentication everywhere, no exceptions

Credential compromise is the entry point in the majority of incidents we investigate. MFA on email, cloud infrastructure, VPN, financial systems and any administrative interface eliminates most of that risk for close to zero cost. The exceptions people carve out — the shared account, the executive who finds it inconvenient, the legacy system — are precisely where attackers enter.

2. Remove access that is no longer needed

Every assessment finds active accounts for departed staff, contractors with production access from a project two years ago, and service accounts with administrative rights nobody can explain. Run an access review quarterly and document it. This costs staff time and nothing else, and it removes a large share of your attack surface.

3. Patch on a schedule, and know your inventory

You cannot patch what you have not inventoried. Build an asset register first, then a patch cadence with tested maintenance windows. Internet-facing systems need the fastest cycle. Automated patching for workstations, scheduled for servers, and an exception register for anything that cannot be patched with a documented compensating control.

4. Test your backups by restoring them

Configured backups and working backups are different things. We routinely find backup jobs that have failed silently for months, or backups stored where the same ransomware event would encrypt them. The control is: at least one immutable off-site copy, and a restore test performed and documented quarterly. A backup you have not restored is a hypothesis.

5. Train people on the attacks they will actually face

Not generic awareness videos. Specific, current scenarios: invoice fraud and payment redirection, credential phishing on your actual login pages, and voice-based social engineering of your finance team. Combine short training with periodic simulation, and measure the click rate over time rather than the completion rate.

6. Enforce device encryption and basic hardening

Full-disk encryption on every laptop and phone. Automatic screen lock. Remote wipe capability. This turns a lost device from a potential breach into an inconvenience, and modern device management makes it enforceable rather than advisory.

7. Segment your network and limit lateral movement

Flat networks mean one compromised workstation reaches your file server, your finance system and your backups. Segmentation limits blast radius. For most mid-market companies, separating user devices, servers, guest access and any operational technology is sufficient and achievable with existing equipment.

8. Log centrally and review what matters

Logs that exist only on the compromised system are useless post-incident. Centralise authentication events, administrative actions, and access to sensitive data. Then define a small number of alerts you will actually act on — impossible-travel logins, privilege escalation, bulk data access. Ten tuned alerts beat five hundred ignored ones.

9. Secure the software you build or buy

If you develop software, add dependency scanning to your pipeline, keep secrets in a managed vault rather than configuration files, and perform authenticated penetration testing before major releases. If you buy software, assess vendor security posture before signing and record it in a third-party risk register.

10. Write an incident response plan and rehearse it

Not a document filed and forgotten. A plan naming who decides, who communicates, which systems get isolated first, and what your legal notification obligations are. Then run a tabletop exercise annually. The first time you use the plan should not be during an actual incident.

11. Manage third-party and supply-chain risk

Your vendors' security is part of yours. Maintain a register of who holds your data and what access they have, require security evidence proportionate to that access, and ensure contracts include breach notification obligations. Integration credentials should be scoped narrowly and rotated.

12. Get an independent assessment

Internal teams cannot easily see their own blind spots, and clients increasingly require third-party evidence. A focused external assessment — ours starts at $1,499 — produces a prioritised, validated finding list. The value is in the ordering as much as the findings.

What this does not cover

This list addresses common risk, not specialised exposure. Regulated industries, operational technology environments and companies holding large volumes of consumer data need controls beyond it. But a mid-market company with all twelve in place is substantially harder to compromise than most of its peers — and the first five cost almost nothing but discipline.


cybersecuritycontrolscompliancerisk

Want this applied to your operation?

A free 45-minute discovery call will establish whether the framework above applies to your situation, and what it would cost to act on it.

Continue reading

Related insights

SaaS Strategy9 min read

What actually belongs in a SaaS MVP

Most MVPs are too big in features and too small in engineering. The correction is uncomfortable: cut the feature list, but do not cut multi-tenancy, billing or auth.

Cyntra EngineeringRead