By Marie Skov Lillelund, Billund Business & Henrik Zankel, Jysk IT

Cyber ​​threats and attacks are not just something that affects large companies. Cybercriminals have also set their sights on SMEs, where even simple attacks can wreak havoc and cause irreparable damage to data, reputation and trust. There is increased activity especially on weekends and holidays – and if a dutiful employee checks work emails from the slopes, sunbed or sofa, the attention is rarely the same as on Tuesday morning in the office.

In recent years, the media has repeatedly reported on companies being forced to turn the key after being hit by a devastating attack. The incidents are rarely due to advanced hacking, but rather to timing, lack of basic security and digital hygiene. Fortunately, there are practical and effective actions that can increase security, so that both employees and owners can take time off with a clear conscience.

Multi-factor login increases security
Even large companies with solid IT systems and expensive licenses don't always manage to get the most basic security measures set up correctly - even though they're right in front of them. Two-factor authentication and multi-factor login (MFA) are something most people are used to when it comes to all communication with banks and the public sector - but not everyone has implemented them in the workplace, even though they are one of the most effective measures.

Where security used to be about long and complex passwords, today it's more important to focus on this extra security measure. One extra step. One authentication on your phone. It rarely gets more complicated than that.

Store your data in more than one place
Even if things go wrong and cybercriminals gain access to your company's data, it's still important to have exercised due diligence. JF Kennedy said in his 1962 State of the Union address that the right time to fix your roof is while the sun is shining.

A 2026 counterpart could be that it is important to back up your company's data before an attack takes place. Therefore, have a clear backup strategy for your data. You should have at least two copies of your company's data - stored on two different types of media - data for daily use in the cloud and backup in another data center. Backing up critical data on an external hard drive is also a good idea, but not an optimal solution for everyone.

Hackers use your boss and HR as weapons
Just as the rest of the world has embraced AI tools, cybercriminals have also learned to optimize their attacks, making it harder to immediately tell if the sender is who they say they are. Often, the sender pretends to be a manager or HR representative, asking the recipient to open a link, download a file, or transfer money.

Often, nothing has changed except the order of the initials in the sender's email address or sender account, which makes it all look credible at first glance. Therefore, you should always ask yourself if it is the right email and what type of content it is. If in doubt, you should contact the sender via another communication channel, e.g. phone call, text message or by visiting the person at work and asking if it is a genuine email.

If this is not the case, the incident should be reported immediately to the IT department or vendor so that colleagues are warned that there is a phishing email in circulation.

Once you have taken these precautions, your company's digital defenses will be improved, and you can turn on auto-responders and take a well-deserved Easter vacation – without checking your work email.

Digitization check
As a member of Billund Erhverv, you can get a free digitalization check at any time.

Contact business developer Lars Gadgaard at lg@billunderhverv.dk or +45 92 15 11 42 to hear more about the possibility of a digitalization check of your company.