In cybersecurity you hear about artificial intelligence, advanced attacks and expensive solutions. The reality of most incidents is boring: the same short list of omissions every time. The Pareto principle applies here - a small group of measures decides most of the risk. Let us go through it.

Why attackers need so little

Common attacks are not the work of a genius who picked your company. They are mass and automated: bots continuously scan the internet, try known vulnerabilities in unpatched systems and test millions of leaked passwords. How exactly such attacks unfold is described in how hacker attacks work.

That is actually good news: the attacker looks for the easiest prey, not the most interesting one. A company with the basics covered is expensive for them, and they move on. That is precisely why a few basic measures stop most attacks.

The five measures that decide

1. Updates - enabled and not postponed. A large share of breaches exploits holes for which a fix has long existed. Automatic updates of the system, browser and applications are the cheapest protection there is. Why they must not be postponed is covered in updates: why not to put them off.

2. Two-factor authentication (2FA) on important accounts. E-mail, bank, cloud, social media, website administration. A stolen password without the second factor is not enough for the attacker - this single step neutralises whole categories of attacks. See our guide to a password manager and two-factor authentication.

3. A password manager and unique passwords. The most common way an attacker gets “in” is a password leaked from another service that the victim uses everywhere. A password manager solves the whole problem at once: every service gets its own long password and you remember one.

4. Backups - regular and tested. A backup is the last resort against ransomware, theft and plain human error. The key word is “tested”: a backup you cannot restore from does not exist. See how to back up data correctly and, for companies, ransomware protection.

5. Vigilance against fraudulent messages. Most attacks on companies start with an e-mail. Teach yourself and your colleagues to recognise a fraudulent e-mail and adopt a simple rule: any request for a payment, password or data gets confirmed through another channel.

Notice what is not in the five: expensive boxes, “AI protection” or complex projects. These basics are cheap, available to every company and cover the biggest share of real risk. Antivirus makes sense as another layer, but on its own it is not enough.

Careful: 80/20 says where to start, not where to stop

This is where the Pareto principle breaks in security, and it needs saying bluntly: an attacker needs a single hole. You cannot have 2FA on four out of five important accounts and call it done. You cannot back up 80% of your data.

Use the 80/20 rule in security like this:

  • Prioritisation: the basic five comes before anything advanced. Do not buy an “AI firewall” before you have tested backups.
  • Completeness within a measure: whatever you roll out, take it to 100% - all accounts, all machines, all data.
  • Further layers according to value: the remaining 20% of risk (targeted attacks, insider threats) is handled with additional layers according to what you protect. See the overview in cybersecurity essentials.

How we see it

When we do a security review for a company, we do not start with technology but with questions: where are the passwords, where is 2FA, when was a restore from backup last tested and what lands in employees’ inboxes. The answers almost always reveal two or three omissions from the basic five - and fixing those reduces risk more than any purchase. Only then does it make sense to talk about further layers.

Conclusion

Most attacks are not repelled by expensive technology but by mastered basics: updates, two-factor authentication, a password manager, tested backups and vigilance against fraud. Start with them and take them to one hundred percent - and remember that in security the 80/20 rule is a compass for setting priorities, not a licence to leave holes.

Want to know where your company has holes?

We will review the basics for you: accounts, passwords, backups and updates. No scare tactics and no unnecessary purchases - just what genuinely reduces risk.

Get in touch

This article is part of the cybersecurity overview.