10 September 2026

Cybersecurity is often sold as a product. For most small and mid-sized organisations, the first losses come from ordinary gaps: a shared mailbox, a laptop without a lock, a backup that has never been restored, or a former contractor who still has access.

Start with identity. Every person who can see financial, customer or staff data should have their own account. Shared logins make it impossible to know who did what, and they make it painful to revoke access when someone leaves. Multi-factor authentication on email and finance tools is one of the highest-leverage changes available.

Then prove that you can recover. A backup that has never been tested is a story you tell yourself. Know what is backed up, where it lives, who can restore it, and how long the business can operate if the primary system is unavailable. That conversation belongs to leadership, not only to whoever happens to manage IT.

Keep software current, especially anything exposed to the internet. Unmaintained sites, plugins and servers are a common way organisations are compromised. If nobody is responsible for updates, the organisation has already chosen a security posture — an accidental one.

Write down the basics. Who can approve payments. Who can export customer lists. What happens if a device is lost. Policies do not need to be long. They need to be followed. Training is part of that: staff should know that unexpected payment-change emails and urgent credential requests are treated as suspicious until verified on a known channel.

Pentacom treats security as part of how software is designed and hosted, not as a certificate on a homepage. If you are unsure where you stand, an assessment that names the actual gaps is more useful than a stack of tools you will not operate.