In 2025, 61% of ransomware attacks in Brazil targeted companies with fewer than 500 employees. Average incident cost for a Brazilian SMB hit R$ 1.2M, counting downtime, recovery, LGPD fine and customer loss. For a business making R$ 5-20M/year, this is literally going out of business.
The good news: 80% of attacks are blocked by basic controls that cost little. What kills SMBs isn't lack of budget — it's not doing the basics well. This post is the technical checklist every R$ 5-100M/year company needs implemented in 2026.
1. The 2026 landscape: what changed
Three things changed in the last 18 months that SMBs haven't absorbed yet:
1. Phishing went industrial with generative AI. In 2024, a convincing phishing email took 4-6h of work. Today, models like GPT-4 and Claude generate personalized email per employee in seconds, with perfect grammar, real company context (scraped from LinkedIn) and convincing CTA. Volume increased 4x.
2. Ransomware-as-a-Service got cheaper. Groups like Lockbit 4, Akira and Black Basta sell ready kits. Criminal doesn't need to code anymore — pays US$ 200/month subscription and attacks. SMB became preferred target because they pay fast and have weak security.
3. Regulators started enforcing privacy fines seriously. In 2025, the first public LGPD fine in Brazil exceeded R$ 14M. SMB that leaks customer data without proven good practices pays proportionally. Cybersecurity became compliance, not optional.
2. The minimum checklist (10 items)
The 80/20 of SMB security. Implementing these 10 items reduces risk by 85% and costs R$ 8-25k/month depending on size. Without this, no point spending on "advanced solutions".
1. MFA everywhere (email, VPN, admin panels)
Multi-factor authentication via authenticator app (Google/Microsoft Authenticator) on all corporate logins. SMS password doesn't count (SIM swap breaks it). Apply especially to: email (Google Workspace/Microsoft 365), VPN, system admin panels, ERP, code repository, cloud console (AWS/GCP/Azure).
Cost: zero (native feature). Impact: blocks 99% of attacks starting from leaked credentials (80% of cases).
2. Corporate password manager
Bitwarden, 1Password Business or Dashlane Business. Each employee generates unique 20+ character passwords for each service. Team credential sharing becomes controlled. When someone leaves, revoke access in 1 minute.
Cost: R$ 25-50/user/month. Impact: eliminates password reuse and password-in-spreadsheet (common SMB scenario).
3. Tested 3-2-1 backup
3 data copies, on 2 different media, with 1 offline/offsite (not network-accessible). Modern ransomware encrypts online backup too — only immutable backup (object lock, S3 with versioning + MFA delete) survives.
Test restore quarterly. Backup never restored is placebo. In at least 30% of cases I've seen, backup existed but was corrupted — discovered only during incident.
Cost: R$ 500-3000/month. Impact: survives ransomware without paying ransom.
4. EDR/XDR (not traditional antivirus)
Endpoint Detection and Response on every machine (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Business). Unlike signature antivirus, EDR detects behavior: process escalating privilege, mass encryption, connection to suspicious IP. Blocks ransomware at early stage.
Cost: R$ 30-80/endpoint/month. Impact: difference between contained 1-endpoint incident and network-wide ransomware.
5. Disciplined patch management
OS, servers, third-party apps — all patched within 30 days of critical patch release. CVE exploited in the wild: 14 days. Inventory of what's in production (do you know how many different PHP versions run in your fleet? And Node? And Apache?).
Cost: 4-8h/month of SysAdmin + tool (WSUS, Ansible, etc — can be free). Impact: closes 50% of CVEs exploited in real attacks.
6. Recurring phishing training
Monthly simulations with platforms like KnowBe4, Phished or Mimecast. Employee who clicks gets contextualized micro-training. Metric to pursue: click rate below 5% in 12 months.
Phishing is the vector of 80% of successful attacks. Tech helps, but humans are the last line. Annual 1h training with corporate video doesn't do anything — needs to be continuous, simulated and contextual.
Cost: R$ 15-40/employee/month. Impact: reduces click rate by 60-80%.
7. Least privilege principle
Nobody uses admin account daily. HR has no DB access. Intern has no production permission. Access reviewed every 90 days. When someone leaves, off-boarding revokes EVERYTHING within 24h (not 30 days).
Cost: 16h initial mapping + 4h/month review. Impact: limits damage when an account gets compromised.
8. Network segmentation
Production server doesn't live in same VLAN as HR PC. IP cameras, smart AC, IoT — separate network. If IoT gets compromised (happens often), doesn't reach ERP.
Cost: firewall with VLAN (already in most business routers) + 8-16h config. Impact: prevents lateral movement, how ransomware spreads.
9. Centralized logging + alerts
System, authentication, firewall, WAF logs — centralized in a SIEM (Wazuh is open source and good to start, or Microsoft Sentinel). Alerts for: off-hours login, geographically impossible login, brute force attempts, privilege escalation.
Cost: R$ 1500-5000/month (SaaS) or 1 server + time (open source). Impact: detection time drops from 200 days (avg without SIEM) to hours.
10. Documented and tested incident response plan
Short document (2-4 pages) answering: who calls whom if 1) email compromised, 2) ransomware, 3) data leak, 4) site down. Contacts: tech team, legal, comms, regulator (if leak), cyber insurance if any.
Test 1x/year with tabletop exercise. Team that never trained improvises worse under real stress.
Cost: 16-40h initial consulting. Impact: reduces containment time from 7 days to 8 hours.
3. In-house vs outsourced SOC: how to decide
SOC (Security Operations Center) is the team monitoring 24/7 and responding to incidents. SMB has 3 paths:
In-house SOC: only makes sense with 200+ employees and R$ 200k+/month budget. Needs at least 4 analysts to cover 24/7. Don't recommend below that size.
Outsourced SOC (MSSP): Tempest, Tivit, Algar Cyber, NTT — paid per monitored endpoint or capacity. Good for R$ 20-200M SMB. Cost: R$ 15-60k/month.
Hybrid SOC with managed EDR: CrowdStrike Falcon Complete, SentinelOne Vigilance or Defender for Business with retainer. MSP team responds, you have no internal analyst. Best option for SMB up to R$ 50M. Cost: R$ 50-150/endpoint/month.
Most Brazilian SMBs fit Option 3. Don't try in-house SOC if you don't have 4 dedicated analysts — it'll fail.
4. How much to invest in security (% of revenue)
Global benchmark: 0.5-3% of gross revenue in information security. Brazilian SMB typically sits at 0.1% — hence the incident level we see.
Healthy security budget distribution:
- 40% in tools (EDR, MFA, password manager, backup, SIEM)
- 30% in people (training, consulting, outsourced SOC)
- 20% in processes (audit, annual pentest, response plan)
- 10% reserve for incident (cyber insurance, ransom fund)
For a R$ 30M/year company, that's R$ 150-900k/year. Sounds like a lot until you compare with the cost of ONE incident.
5. ROI: how to justify to CEO
Technical argument doesn't sell. What sells is numbers.
Expected incident cost without basic controls (Brazil average 2025):
- 5-10 day downtime: R$ 200-800k direct loss
- Technical recovery cost: R$ 80-300k
- Potential LGPD fine: 2% of revenue (R$ 50M cap)
- Customer notification + PR: R$ 40-150k
- Post-incident churn: 5-15% of base
Investing R$ 200k/year in controls that reduce 85% of risk when the event would cost R$ 1-3M is an easy decision. The hard part is not doing it.
6. What NOT to do (common myths)
"I'm too small to be a target". Wrong. SMB is the PREFERRED target. Weak security + ability to pay ransom = high ROI for criminal. Fortune 500 today has 50+ people in security. SMB is the field where attacks pay off.
"I have antivirus, I'm protected". Signature antivirus against modern ransomware is like driver's license for F1 pilot. Useful but insufficient. You need behavioral EDR.
"Google Drive backup solves it". No. Ransomware syncs encrypted data to cloud. You need immutable backup (write-once) or offline.
"I'll buy cyber insurance and relax". Cyber insurance in 2026 only pays if you prove basic controls implemented. Without MFA, tested backup and EDR, policy excludes claim.
"LGPD compliance keeps me safe". LGPD is privacy compliance, not security. You can be 100% LGPD-compliant and get hacked tomorrow. Different layers.
Want a diagnosis of your exposure level?
In 1h we assess your 10 basic controls and deliver a report with quick-win prioritization. No cost.
Talk to ReikoConclusion: do the basics, do them well
SMB cybersecurity is an execution problem, not advanced technology. The 10 controls in this checklist solve 85% of risk and cost less than 2% of revenue. What I see in practice is companies skipping the basics to buy "AI-powered solution" they won't use.
Start with items 1, 3 and 4 (MFA, backup, EDR). It's the tripod. Solves 70% of the problem in 30 days. Then implement the rest in quarterly waves. In 12 months your company moves from "easy target" to "target that takes effort" — and criminal moves on.
Frequently asked questions about SMB cybersecurity
What is the minimum security investment for an SMB?
For a R$ 10-30M/year company, viable minimum is R$ 8-15k/month covering: MFA (free), password manager (R$ 1k/month), EDR on 30 endpoints (R$ 2-4k), 3-2-1 backup (R$ 1-3k), basic SIEM (R$ 2-5k) and phishing training (R$ 1-3k). Without this minimum, any larger investment has dubious return.
Is cyber insurance worth it in 2026?
Yes, if you have basic controls. Insurers today require minimum checklist (MFA, backup, EDR, training) to issue policy. Without it, either denied or expensive. With controls in order, annual premium is 0.3-1% of contracted limit. Common SMB limits: US$ 500k to 5M, covering ransom, recovery, lost revenue and liability.
Do I need an in-house CISO?
For SMB up to R$ 200M/year, full-time in-house CISO rarely makes financial sense. Better option: outsourced vCISO (Virtual CISO), working 8-20h/month defining strategy, policy and reviewing incidents. Cost: R$ 8-25k/month. Above R$ 200M or in regulated sector (financial, healthcare), in-house CISO becomes mandatory by compliance.
How do I know if I've already been breached?
Common signs: customer emails complaining about strange messages you didn't send; unknown processes in Task Manager; general slowness without cause; encrypted or renamed files; logins at unusual hours in your panels. Average detection time without SIEM is 200 days. If you don't have centralized logging, it's statistically likely something is in progress and you don't know yet.
What to do in the first 24h after detecting an attack?
First hour: isolate affected machines from network (don't turn off — loses forensics). Trigger technical contact from response plan. Notify leadership. First 24h: hire forensic if value justifies; preserve evidence; start recovery from immutable backup; engage legal to assess regulator notification (72h deadline if leak). Don't pay ransom without consultancy — in 40% of cases the key doesn't work or gets resold.