TL;DR
The short answer
Small business cybersecurity is not only about keeping outsiders out. Plan how authorised people regain access after a lost 2FA phone or an unavailable administrator.
Use the detail below to choose the right next step.
| Topic | small business cybersecurity |
|---|---|
| Region | Kerkrade · Zuid-Limburg · Netherlands & Belgium |
| Current status | Reviewed and kept up to date: 4 September 2026 |
| Next step | Scope first, then a clear price direction |
I recently paid €235 to get back into my own home.
I had not lost the key somewhere in town, and the lock was not broken. I had simply stepped outside and pulled the door shut while the key was still inside. The door was held by the latch, but I had not turned the key.
When the locksmith arrived, I told him about the protected cylinder and security fittings on the door. In this situation, they made little difference. He opened the door without damage in about five minutes.
I asked what would have happened if I had actually locked it. That would have been a much harder job. It would probably have taken longer, damaged some of the hardware and cost considerably more.
There is an odd contradiction here. The better I protect my home from a stranger, the harder it becomes for me to get back in when my key is unavailable. The same thing can happen with small business cybersecurity.
A good lock solves only half the problem
Strong passwords and two-factor authentication are necessary. The Dutch Chamber of Commerce, KVK, describes 2FA as an extra lock on an account.
Business owners also need to know how an authorised user will regain access when that extra lock is unavailable. A phone can be lost or damaged. An old telephone number may remain configured as the recovery method years after it was replaced. An employee may leave, while the only administrator could be ill or unreachable during a holiday.
At that point, a failed login becomes a business continuity problem. Employees cannot reach email or the CRM. Nobody can update the website, renew the domain or access the documents and backups needed to keep working.
The Netherlands’ National Cyber Security Centre treats access management and preparation for recovery as separate parts of digital resilience. Keeping an outsider out is one part of security. Getting the company working again is another.
Sometimes the digital keys still belong to a former supplier
I have taken over projects where important digital assets depended on one person or a former web developer. A domain, hosting account or website administration panel might be connected to the supplier’s personal email address.
The company uses and pays for the website, but cannot manage it independently without the person who originally built it. As long as the relationship is good and the supplier responds, this dependency is easy to miss. It becomes visible when the supplier stops working, loses the account or cannot help quickly. The business is then locked outside its own digital front door.
The owner does not need to manage the hosting or understand every technical setting. That is a specialist’s job. The company should still retain control: it needs to know who owns the accounts, who has administrator rights and how management can be transferred to another specialist.
Lost your 2FA phone: what happens to the working day?
An employee knows their password, but the phone with the Authenticator app is gone. What happens next?
In a poorly prepared company, nobody can log in. There are no recovery codes, no second administrator and the helpdesk may take days to respond. The security control has done its job, yet the employee cannot do theirs.
In a well-prepared company, an authorised administrator verifies the employee’s identity. The lost authentication method is disabled and a new device is enrolled securely. The system records who restored access and when.
The recovery route should not be one office password shared by everybody. A hidden administrator account with widely known credentials is not a solution either. Access recovery needs a controlled procedure that is only used when necessary. Think of a spare key: not under the doormat, but not inside the locked house either.
The only administrator can become unavailable too
Many small companies have one person who knows everything. This administrator controls email, domains, the CRM, website, automations and cloud storage. It may be the owner, an employee or an external IT specialist.
The arrangement feels efficient while that person is available. Its weakness appears on the day the administrator cannot log in or cannot help anyone else. The NCSC specifically advises businesses to keep access rights current and to prepare for the unexpected departure of a system administrator. In practical terms, a critical service should not depend entirely on one individual.
A backup administrator does not need to use every service each day. That person must exist, have proper authority and know the agreed recovery procedure. Otherwise, the backup only exists on paper.
A backup is only useful if you can restore it
Backups often create the same false confidence. The dashboard shows a green “backup completed” message, so the matter appears settled. But where is the copy stored? Who can access it? Does recovery depend on the same phone or account that has been lost? Who holds the encryption key? Has anyone ever restored the website or administration from that backup?
A company may have a complete copy of its website and database but no longer be able to enter the cloud storage. The password might be inside the account of a former employee. An automated process could also create damaged backups for months without anyone noticing.
The NCSC therefore recommends both creating backups and testing the restoration process regularly. You need the copy and a working route for putting it back into use.
Check the five services your company cannot work without
You do not need technical training for an initial check. Choose five services the company cannot afford to lose for long: business email, the domain, the website, the CRM or accounting system, and cloud documents.
Each service needs clear answers:
- Who owns the main account?
- Who currently has administrator access?
- Who can restore access after a phone is lost?
- What happens if the usual administrator is unavailable?
- Where are the recovery codes, and are the recovery details current?
- Can another specialist take over without help from the former supplier?
- Has anyone tested a real restoration from backup?
The owner does not have to perform every technical task. The answers simply cannot exist only in one IT specialist’s head or personal account.
Cybersecurity also protects the company’s ability to continue
After the incident with my door, I did not need a weaker lock. I needed a reliable way to reach a spare key.
A company does not need to disable 2FA, simplify its passwords or give administrator rights to everybody. It needs to decide in advance how access will be restored, who controls its business accounts and what happens when an employee or supplier changes.
Good security answers two questions. How do we keep an outsider out? And how do we return access to an authorised person without creating a security hole?
If you are unsure who controls your domain, hosting, website or connected automations, we can review the situation during a consultation. I will help identify where the business depends on one person, which accounts the company actually controls and what should be addressed first.
If an unauthorised person has already gained access or the website shows suspicious activity, access management alone is not enough. Read how I approach a hacked website and technical security audit.
Frequently asked questions
Frequently asked questions
What matters most when it comes to small business cybersecurity?
The direct answer is: Small business cybersecurity is not only about keeping outsiders out. Plan how authorised people regain access after a lost 2FA phone or an unavailable administrator.
Which choice fits my situation?
The right choice depends on your goal, audience, existing technology and what a visitor needs to do next. The rest of this article makes that trade-off concrete.
What determines the price and timeline?
Price and timing depend on scope, content, technology and the materials available. You receive clarity on the route before anything is built or changed.
Can OROS help businesses in Zuid-Limburg, the Netherlands or Belgium?
Yes. OROS works from Kerkrade with businesses in Zuid-Limburg, elsewhere in the Netherlands and in Belgium. Work can happen remotely or on site when useful.
A useful next step
Discuss your situation
Send a short description of your question, current website or goal. Daniel will assess the route, whether a one-week start is realistic and the expected price direction.
Request an initial assessment →
