Most SMB security incidents don’t start with a novel attack. They start with something an MSP could have flagged months earlier — a missing control, an unowned risk, a policy nobody enforced. If you’ve been doing client assessments for a while, the same seven issues probably keep turning up. Here’s the shortlist worth checking on every account.
1. Treating security as a one-time setup
A lot of SMBs bought a firewall or antivirus years ago and consider the job done. Security isn’t a purchase, it’s an ongoing process — new staff need onboarding, new threats need new controls, and configurations drift over time. If a client’s last security conversation happened at the point of sale, that’s the first thing to change.
Frame this as a recurring review rather than a one-off project when you talk to clients. It’s an easier sell than a big bang overhaul, and it keeps you in the account.
2. No filtering at the DNS or email layer
Endpoint protection catches a lot, but by the time malware reaches the endpoint, the user has already clicked something. DNS and email filtering stop the bad link or attachment before it gets that far. SMBs without this layer are relying entirely on user judgement and reactive tools — which works until it doesn’t.
This is also one of the easiest upsells you’ll find. It’s low-friction to deploy, doesn’t require much end-user retraining, and the value is easy to explain in plain language.
3. Multi-factor authentication with gaps
Almost every SMB owner will tell you they
