Updated October 2026. Originally published January 30, 2025.
Most breaches still start with the basics: an unpatched system, a stolen password or a convincing message. Verizon’s 2026 report found that exploiting vulnerabilities is now the most common way attackers get in, at 31% of breaches, with credential abuse at 13% (Verizon DBIR). The six tips below, drawn from our video conversation with Adam from Starfish Computer, cover the controls that close those doors for most businesses.
Six tips that stop most attacks
Turn on multifactor authentication everywhere. With MFA, a stolen password alone isn’t enough to get in. Use it on email, remote access, banking and every cloud app. CISA calls phishing-resistant MFA, such as FIDO security keys, the gold standard; app-based codes or push notifications with number matching are the next best option for smaller businesses, and text-message codes should be a last resort (CISA).
Use long passphrases, not complicated rules. Password advice has changed. NIST’s current guidelines require at least 15 characters for a password used on its own, drop forced complexity rules and scheduled password changes, and call for checking new passwords against lists of known compromised ones. A password should be changed when there’s evidence it was compromised (NIST). A password manager makes a unique passphrase for every account practical.
Move from basic antivirus to managed detection and response. Built-in tools like Microsoft Defender are a starting point, but a centrally managed endpoint detection and response (EDR or XDR) platform watches for suspicious behavior, can isolate an infected computer, and gives your IT team one view of every device. That matters when ransomware is involved in 48% of breaches (Verizon DBIR).
Filter email and train people to spot what gets through. Business email compromise cost U.S. victims more than $3 billion in 2025, out of $20.9 billion in total reported cybercrime losses (FBI IC3). Good filtering removes most spam and malicious attachments before anyone sees them. Attackers are also shifting to phone calls and text messages, where simulated attacks succeed more often than email does (Verizon DBIR), so training should cover those channels too.
Keep backups offline and test them. CISA recommends offline, encrypted backups of critical data and regular testing to confirm they can actually be restored, because many ransomware strains hunt for connected backups and destroy them (CISA). A backup you’ve never restored from is a hope, not a plan.
Assess, scan and patch on a schedule. Regular IT assessments and network vulnerability scans, by your own team or a third party, find weaknesses before attackers do. Speed matters: only 26% of the most critical known-exploited vulnerabilities were fully fixed in 2025, and the median time to fix them grew to 43 days (Verizon DBIR).
Layers, not a single product
No single control stops everything, which is why these tips work best together. MFA protects you when a password leaks. Detection and response catches the phishing email that slipped past the filter. Backups bring you back when everything else fails. Review each layer at least once a year, and whenever your business changes: new employees, new cloud apps, new locations or new vendors.
Strengthen your security with Starfish Computer
Whether you’re revisiting your defenses or putting them in place for the first time, Starfish Computer can help you implement all six of these practices and keep them working. Contact our team to review where you stand today and build a plan to close the gaps.
Protect your business: start with an assessment
The question isn’t whether your business will face a cyber threat, but whether you’ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:
Assess current security posture and risk
Plan a cybersecurity roadmap aligned to NIST CSF 2.0
Implement the right tools and processes for your size and budget
Train your team on today’s threats, including AI-driven scams
Support and improve your security over time
Call (440) 808-0468 or visit starfishcomputer.com to schedule a security assessment.
About the author
R.J. Arhar is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of Attack or Defend – When is Enough Cybersecurity Enough?
This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.

