A Cyber Security Checklist for Kenyan SMEs
Small and medium businesses are prime targets for cyber attacks. Here are the essential, affordable protections every Kenyan SME should have in place.

Cyber attacks are no longer a big-company problem. Attackers increasingly target small and medium businesses precisely because they tend to have weaker defences and assume they're too small to be noticed. In reality, much of today's attacking is automated — it scans for easy targets rather than choosing them by name. The good news is that most breaches exploit basic, well-understood gaps, so a handful of practical controls dramatically reduces your risk without a big budget. Use this checklist as a starting point, and treat it as something you revisit, not a box you tick once.
The essentials
These are the controls that stop the majority of common attacks. If you do nothing else, do these.
1. Strong authentication everywhere
Enable multi-factor authentication (MFA) on email, banking, cloud services, and any admin account. A stolen password alone should never be enough to get in. Encourage a password manager so staff can use long, unique passwords without trying to memorise them — reused passwords are one of the easiest ways for an attacker to move from one compromised account to the next.
2. Keep software updated
Most attacks use known vulnerabilities that already have fixes available. Turn on automatic updates for operating systems, browsers, and business apps, and don't forget the devices people overlook — routers, firewalls, and phones. Software that's no longer supported by its vendor should be replaced; once updates stop, every newly discovered flaw stays open forever.
3. Reliable, tested backups
Backups are your safety net against ransomware, hardware failure, and simple human error. Follow the 3-2-1 rule: three copies of your data, on two types of media, with one kept off-site or in the cloud. Then test a restore — a backup you've never recovered from is a hope, not a plan. Keep at least one backup copy offline or otherwise out of reach, so an attacker who gets into your systems can't encrypt or delete it too.
4. Email and phishing protection
Phishing is the most common entry point for attacks. Use email filtering to catch the obvious threats, and train staff to spot the rest: suspicious links, unexpected attachments, urgency, and — especially — requests to change bank or payment details. A quick phone call to verify a payment change on a known number has saved many businesses from a costly fraud.
5. Endpoint protection
Install reputable anti-malware on every device, and keep it turned on and updated. Encrypt laptops and phones so a lost or stolen device doesn't become a data breach, and make sure devices lock automatically after a short period of inactivity. The more staff work remotely or on the move, the more this matters.
6. Least-privilege access
Give staff access only to what they genuinely need to do their jobs, and review those permissions periodically. Keep everyday work off administrator accounts. Crucially, remove accounts and revoke access promptly when people leave — dormant accounts with live credentials are a favourite way in.
Building a security culture
Technology alone isn't enough; most incidents involve a person being tricked, rushed, or unaware. Short, regular staff awareness sessions — how to recognise phishing, how to handle sensitive data, how to report something that looks wrong — are among the cheapest and most effective controls you can put in place. Make it safe to report mistakes quickly; an employee who feels able to say "I think I clicked something" gives you the chance to contain a problem before it spreads. Security that people understand and buy into works far better than rules they quietly route around.
Know your response plan
Even well-defended businesses can be hit, so decide in advance what you'll do. Write down who to call, how to isolate an affected machine from the network, how to reach your IT support, and how you'll communicate with staff and, if needed, customers. Know where your backups are and how quickly you can restore from them. A calm, rehearsed response limits the damage; panic and improvisation make it worse. Review the plan periodically so it stays accurate as your systems and team change.
A quick self-assessment
Ask yourself honestly:
- Is MFA on for email, banking, and admin accounts?
- Are all our devices and systems getting security updates?
- Do we have tested backups, with one copy out of an attacker's reach?
- Have staff been trained to spot phishing in the last year?
- Does everyone have only the access they actually need?
- Do we know exactly what we'd do in the first hour of an incident?
Any "no" is a priority worth addressing.
Getting help
If you'd like a professional assessment of where you stand, our cyber security team can review your environment, benchmark it against these essentials, and prioritise the fixes that matter most for your business. Get in touch for a conversation.