Security for sub-100-seat teams

What you actually face on the cloud — and the four defaults that close most of the gap.

Phishing, ransomware, and credential theft aren't enterprise-only problems — the same kits hit teams of twenty and teams of two thousand the same way. Security isn't a product, it's a baseline. Here is the baseline we ship into every Helmswell customer, written for the IT lead, the founder still on-call, and the finance person who has to answer the auditor.

For the deep dives on threats and the baselines, see Security fundamentals for small businesses and Compliance basics for sub-100-seat businesses on the Learn hub.

The threats

What you're up against.

The three categories that account for most incidents at sub-100-seat companies. The signature of each has shifted in the last two years — the answers below name the shift.

Threat 1 of 3

Phishing

Phishing is no longer a "dirty inbox" problem. Roughly one in three breaches at sub-100-seat companies starts with a message someone trusted enough to click, and the kit authors have moved on from Nigerian-prince grammar to real branding, real conversation threads, and real urgency.

The signature move today is to move off-channel — "open this PDF, then text me on WhatsApp" — precisely to dodge the mail filter. The mitigation isn't a tighter spam rule; it's treating every payment change, every vendor banking update, and every "can you reset my login" as a request that has to be verified out-of-band before anything moves.

Pair that with monthly phishing simulation: short, low-stakes, and tracked. The metric to watch is the click-and-report rate over raw click rate — a team that catches the bait and reports it halves your real-incident odds, even if some clicks still happen.

Threat 2 of 3

Ransomware

Modern ransomware crews don't race to encrypt. They live inside your environment for a median of about thirty days — mapping shared drives, finding the backup volumes, and reading the change-control docs — then detonate when they know an offline copy is gone. The recovery math you wrote last year is no longer the recovery math you face.

The defense isn't a single product; it's layered. Immutable, off-host backups (S3 Object Lock or equivalent — not just "a NAS in a closet"); application allow-listing on endpoints so unsigned binaries don't run; least-privilege identity so a single impersonated admin can't find every share; and a restore drill you measure in hours.

We treat ransomware as an exercise, not a hope. Quarterly tabletop with the leadership, monthly restore drill against a real backup snapshot, and a pre-staged communications template so the hour of the breach isn't also the hour of writing the press release.

Threat 3 of 3

Credential theft

Stolen passwords are still the most common breach vector at every tier — sub-100-seat included — not because the attackers are clever, but because reused credentials survive breaches of consumer sites for years and almost every business app accepts them as the front door. Pair that with no MFA and one stolen account pivots into email, cloud, finance, and your customers' data.

The core default is straightforward: SSO for every business app, hardware-key or platform passkey MFA on the SSO front door, and conditional access so a sign-in from a new country at 3am prompts a challenge before it grants a token. Service accounts get the same treatment — long-lived API keys are how a lot of "we had MFA" stories actually start.

We rotate secrets on a schedule, retire personal API keys in favour of short-lived roles, and instrument the SSO so a leaked credential trips a high-fidelity alert inside minutes — not politely gets logged into a SIEM nobody reads.

The baseline

Four defaults that close the gap.

Ship all four across a quarter and the median sub-100-seat incident rate drops meaningfully — without buying a product the auditor hasn't asked for. Order them however fits your team; the point is that they all land.

Practice 1 of 4

Multi-factor authentication everywhere

MFA is the single highest-ROI control a sub-100-seat team can ship. It blocks the overwhelming majority of automated credential-stuffing and opportunistic break-ins, and it costs roughly the same as the SaaS tools you already pay for.

Two practical rules: enforce it on the SSO front door (so coverage is one toggle, not fifty), and prefer phishing-resistant factors — hardware keys, platform passkeys, or the manager-approval push that comes with your IdP. SMS one-time codes are a fallback, not a default.

Practice 2 of 4

3-2-1 backups with restore drills

The 3-2-1 rule — three copies, on two media, with one off-site and immutable — is well-known enough that attackers assume you've heard of it and plan around the loophole. The loophole is almost always the off-site copy that turns out to be writable, vendor-managed, or unmetered.

Make the off-host copy immutable (S3 Object Lock in compliance mode, or a tape-out service that physically leaves the building) and prove it with a restore drill run against a real snapshot every month. Recovery time you haven't measured isn't recovery time you have.

Practice 3 of 4

A monthly patching cadence

Most ransomware crews rely on the same handful of known CVEs that have had a patch out for over a year. A monthly patch cycle — OS and browser on endpoints, OS and libraries on servers, dependencies in your build pipelines — closes the door on the vast majority of "commodity" attacks without making the engineers' lives miserable.

Pair the cadence with a short, CIS-style baseline: secure boot, account is admin only when the work requires it, application allow-listing on the laptops that touch finance data. Theos-grade hardening isn't the goal; "boring defaults that the auditor can't fault" is.

Practice 4 of 4

Annual security training plus phishing simulation

Annual security awareness training is the regulatory table-stakes — SOC 2, HIPAA, PCI, and most cyber-insurance carriers expect to see the roster and the completion rate. The mistake is treating it as the goal rather than the floor.

Layer in a quarterly phishing simulation so the muscle memory stays fresh, and review the misses in a thirty-minute post-mortem with the relevant team rather than as a punitive scoreboard. A team that learns from the bait is the team that reports the real one.

Go deeper

The two guides behind the baseline.

The anatomy of each threat, and the workbook for staging the four defaults at your shop — both reviewed this quarter and annotated by the engineers who run them against real customer environments.

Security
9 min readagent · Bastion

Security fundamentals for small businesses

Phishing, ransomware, credential theft — and the four defaults that close most of the gap for a sub-100-seat team.

Read the guideReviewed Aug 2026
Compliance
7 min read· Adjacent guide

Compliance basics for sub-100-seat businesses

SOC 2, HIPAA, GDPR — which ones your sub-100-seat company actually needs, and what the minimal posture looks like.

Read the guideReviewed Aug 2026

Want hands-on help?

Walk through the baseline with our team.

One thirty-minute call is enough to see where your environment is against the four defaults and the three threats — and we’ll send a written follow-up so the conversation survives the call.