Article

Cybersecurity mistakes businesses should stop making

Most security incidents in small and mid-sized organisations exploit ordinary gaps, not sophisticated weaknesses. Stopping ten common mistakes, such as relying on passwords alone, delaying updates and never testing backups, closes the doors attackers use most.

The short answer

If you do nothing else, stop making these ten mistakes:

  1. Relying on passwords alone.
  2. Delaying updates or running unsupported software.
  3. Treating antivirus as enough.
  4. Keeping backups you have never restored.
  5. Letting everyone be an administrator.
  6. Assuming your cloud provider handles security.
  7. Having no incident response plan.
  8. Treating security training as a once-a-year event.
  9. Forgetting your suppliers.
  10. Believing you are too small to be a target.

Internationally recognised good practice, such as the NIST Cybersecurity Framework, addresses almost all of them, and it is a sensible reference for any Nigerian organisation that wants a structure to work from. Local bodies such as ngCERT publish advisories on threats affecting Nigeria.

1. Relying on passwords alone

Passwords get phished, guessed and reused. Do instead: require multi-factor authentication on email, remote access, cloud applications and administrator accounts, and use a password manager so people can have unique passwords everywhere. Prefer phishing-resistant methods such as security keys or passkeys for high-risk accounts. Be careful with SMS codes alone: SIM-swap fraud is a real risk, so favour authenticator apps or hardware keys for important accounts.

2. Delaying updates or running unsupported software

Attackers move quickly once a vulnerability is public, and unsupported software is exposed to flaws that will never be patched. Do instead: turn on automatic updates where practical, patch internet-facing systems first, track end-of-support dates for operating systems and key applications, and budget to replace them in time. Pirated or unlicensed software is a particular risk because it often cannot be updated safely and may arrive with malware already inside.

3. Treating antivirus as enough

Traditional antivirus looks for known malware. Many attacks now use legitimate tools and stolen credentials that signature-based products do not flag. Do instead: use endpoint detection and response (EDR), which records behaviour and can isolate a device, and make sure someone watches and acts on the alerts, around the clock if possible. See EDR vs antivirus.

4. Keeping backups you have never restored

A backup that has never been restored is a hope, not a plan. Ransomware also targets connected backups. A widely used rule is the 3-2-1 approach (three copies, on two types of media, one off site), with offline or immutable copies that are only connected when needed, and routine testing of recovery. Power cuts and unstable links make testing even more important: a restore that fails halfway because of an outage is better discovered in a drill than in an incident. Do instead: keep an offline or immutable copy, test restores on a schedule, and know how long a full recovery would take. See why a backup is not a recovery plan.

5. Letting everyone be an administrator

When staff use administrator accounts for daily work, one malicious click can compromise the whole device or network. Do instead: apply least privilege. Give administrator rights only to those who need them, use separate admin accounts for admin tasks, and review access when people change roles or leave.

6. Assuming your cloud provider handles security

Cloud providers secure their infrastructure, but you remain responsible for your data, user access and configuration. Under software as a service, the customer still manages user access and data, and your organisation stays accountable for its information however much of it sits in the cloud. Do instead: configure Microsoft 365, Google Workspace and other SaaS tools securely, turn on audit logging, and back up critical SaaS data separately.

7. Having no incident response plan

Without a plan, the first hours of an incident are lost to confusion. Do instead: write a short plan naming who decides, who investigates, who communicates and who calls your legal adviser and insurer. Include how you will assess and report personal data breaches: under the Nigeria Data Protection Act 2023 (NDPA), a breach likely to risk people's rights and freedoms must be notified to the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of it, and affected people must be told without undue delay where the risk is high (NDPC). Regulated sectors such as banking may have further reporting duties to their sector regulator. Keep the plan available offline and rehearse it once a year.

8. Treating security training as a once-a-year event

A single annual video changes little. Do instead: run short, regular training and phishing simulations based on real threats, make it easy to report suspicious messages, and thank people who report. See building a security awareness training program.

9. Forgetting your suppliers

IT providers, software vendors and contractors often have remote access to your systems or hold your data. Do instead: keep a list of suppliers with access, require multi-factor authentication and security commitments in contracts, remove access that is no longer needed, and ask how they would notify you of an incident.

10. Believing you are too small to be a target

Many attacks are automated and opportunistic. They scan for any exposed system or stolen password, regardless of company size. Smaller organisations are often easier to compromise and can be a route into larger customers. Do instead: use a recognised baseline as a checklist and fix the gaps in order of risk.

Quick self-assessment

  • MFA is required for email, remote access, cloud apps and admins.
  • Updates install automatically or within an agreed window.
  • We know which systems reach end of support in the next 18 months.
  • EDR is deployed and alerts are monitored.
  • We have an offline or immutable backup and tested a restore this quarter.
  • Daily work is done without administrator rights.
  • SaaS security settings and audit logs have been reviewed.
  • We have a written, rehearsed incident response plan.
  • Staff receive regular training and can report phishing easily.
  • Supplier access is listed and reviewed.

Limitations

This list is a starting point, not a full security programme. Regulated sectors (health, finance, education) and organisations holding sensitive data usually need more, such as formal risk assessments, network segmentation and centralised logging, and may have sector rules to follow (for example from the Central Bank of Nigeria for banks and payment service providers). This is general information, not legal advice.

Next step

A security assessment shows which of these gaps apply to you and which to fix first. Our cybersecurity services then help close them, with 24/7 monitoring and support for managed-service clients.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Cybersecurity Framework, National Institute of Standards and Technology (NIST)
  2. #StopRansomware, Cybersecurity and Infrastructure Security Agency (CISA)
  3. ngCERT, Nigeria Computer Emergency Response Team

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in NGN before any work starts