Most small and mid-sized businesses in Nigeria and across Africa do not need a huge security budget. They need to close the handful of gaps that attackers actually exploit. Here is a practical cybersecurity checklist covering the seven risks that matter most.

1. Weak and reused passwords

Reused passwords are the easiest way in. Enforce strong, unique passwords and roll out a password manager across your team.

2. No multi-factor authentication

Multi-factor authentication (MFA) stops the vast majority of account-takeover attacks. Turn it on for email, banking and every critical system today.

3. Unpatched software and systems

Attackers scan for known vulnerabilities. Keep operating systems, applications and plugins updated, and retire software that is no longer supported.

4. Phishing and social engineering

Most breaches start with a convincing email. Train your team to spot phishing, and verify payment or credential requests through a second channel.

5. Poor or untested backups

Ransomware only wins if you cannot recover. Keep offline, tested backups of critical data — and practise restoring them.

6. Over-privileged access

Give people only the access they need. Remove accounts when staff leave, and separate admin accounts from everyday use.

7. No incident response plan

When something goes wrong, minutes matter. Have a simple written plan: who to call, how to contain the issue, and how to communicate.

Where to start

You do not have to do everything at once. Start with MFA, backups and patching — the three highest-impact, lowest-cost wins — then build from there. A focused security assessment is the fastest way to find and fix what matters for your organisation.

Need help with this? Let’s talk.

If this is a challenge you’re facing, I’d be glad to help you work through it.

Work with me

More from the blog