Canadian cybersecurity expertise

What Running Cybersecurity Operations Taught Me About SMB Security Gaps

Damir Grubisa shares practical lessons about identity, monitoring, response ownership and recovery readiness for small and mid-sized businesses.

Practical protection for your organization

The Cyber Arm helps organizations reduce cyber risk through managed detection, security monitoring, vulnerability management, penetration testing, ransomware protection and incident response.

Security aligned to business risk

Our team combines technology, documented processes and human expertise to improve visibility, prioritize remediation and respond quickly when suspicious activity is detected.

Back to Blog

From Damir

Damir Grubisa · September 11, 2026 · 8 min read

The security problems that concern me most are rarely the most dramatic ones. They are the ordinary gaps that stay open because ownership is unclear, signals are scattered, or recovery has never been tested.

When I review security for a small or mid-sized business, I look for a practical chain of responsibility. Who can see a suspicious sign? Who decides whether it is serious? Who contains it? Who communicates with leadership? A tool can support each step, but it cannot replace clear ownership.

Identity is usually where I start

Microsoft 365, cloud applications and remote access have made identity a central security boundary. I first look at administrator accounts, multifactor authentication, access granted to former staff, risky sign-ins and the process for approving privileged access.

My goal is not to add friction everywhere. It is to make the most sensitive access deliberate, visible and difficult to abuse.

More alerts do not automatically create better security

A business can own several security products and still lack useful visibility. I want to know which alerts are reviewed, how they are prioritized, what context is available and when an issue is escalated.

Good monitoring turns signals into decisions. That requires technology, documented processes and people who understand the environment they are protecting.

Response ownership must be decided before an incident

During an urgent event, uncertainty costs time. I encourage businesses to define who can isolate a device, disable an account, contact legal counsel, notify an insurer and approve recovery actions. Those responsibilities should be written down and exercised before they are needed.

A backup is not a recovery plan

I treat recovery as an operational capability, not a checkbox. A useful plan identifies critical systems, acceptable downtime, clean restoration points and the people required to bring the business back safely. Testing exposes assumptions while there is still time to correct them.

The standard I use

I do not expect a smaller organization to operate like a global enterprise. I do expect it to know what matters most, protect high-risk access, monitor meaningful signals and assign response ownership. Security improves when those basics are consistent and measurable.

If you want a structured view of your current gaps, review our cybersecurity gap assessment or explore our 24/7 SOC and monitoring approach.