Small businesses aren't too small to be attacked. They may be too small to absorb the damage.

A lot of business owners still tell me, why would anyone come after us, we're too small.

The problem is that most cybercrime doesn't work that way anymore. Attackers don't sit in a room researching your 20-person company. Automated attacks, stolen passwords, phishing emails, and unpatched software can expose businesses of almost any size. According to Verizon's 2025 Data Breach Investigations Report, ransomware showed up in 88 percent of confirmed SMB breaches, compared with 39 percent at large organizations, and small and mid-sized businesses saw roughly four times more confirmed breaches than large companies over the same period.

The better question isn't why would someone target me. It's what would happen to my business if they succeeded. For a smaller company, three days without email, customer files, scheduling, or accounting can become a very big problem.

This isn't just about hackers

  • One employee leaves and nobody knows the administrator password
  • Someone accidentally deletes an important folder
  • A laptop with company information disappears
  • An employee clicks a convincing phishing email
  • A Microsoft 365 or Google Workspace account gets compromised
  • Your internet goes down at the worst possible time
  • Your backup has run every night for years, but nobody's ever tested whether it can actually restore the business

Those are business risks that happen to involve technology. Most of them don't require a sophisticated attacker. They just require nobody having a plan.

That's what managed IT should actually address

I don't believe IT support for small businesses should simply mean unlimited help desk calls. A good IT relationship should be able to answer questions like these: Are we protected? Can we recover? Who has access to our information? Are we paying for technology we aren't using? What happens when an employee leaves? What happens if our most important computer fails tomorrow? Can we safely use AI with our company information? And, perhaps most important, if something goes wrong, who's responsible for getting us running again?

What this looks like day to day

In practice, that means someone is watching your systems before you notice anything's wrong, not after. It means your Microsoft 365 or Google Workspace setup is actually configured correctly, not just turned on with default settings. It means when an employee leaves, their access gets shut off the same day, not whenever someone remembers. And it means your backups get tested on a schedule, so the first time you find out whether they work isn't during an actual emergency.

Security should be the baseline, not the upsell

You shouldn't have to understand every cybersecurity acronym. But someone should. Your IT provider ought to explain what you're protecting, what the realistic risks are, what's being done about them, and what risk remains, in plain English. That's how I believe IT services for small businesses should work.

And now there's AI

Businesses are experimenting with ChatGPT, Microsoft Copilot, Claude, and dozens of other tools. There's real opportunity there. There's also a new question worth asking first: what company information are employees putting into those systems?

Before chasing AI tools, I want a business to know where its data lives, who has access to it, and which processes are actually worth improving. Sometimes AI is the answer. Sometimes a simple process change is better, and I'm perfectly comfortable telling a client they don't need the technology I'm evaluating with them. You can read more about how I approach that in our AI consulting guide.

What a real relationship looks like

The businesses I work with best aren't the ones chasing the newest tool. They're the ones who want a technology partner they can call with a plain question and get a plain answer. That means fewer surprises on the invoice, fewer surprises when something breaks, and a lot less time spent wondering whether your systems are actually okay.

Start with a conversation

I founded Ask Erik Computer Services in 2006 and have spent decades helping people make better decisions about technology. Today, I work with established businesses in Eugene, Springfield, and throughout Lane County that want technology to become less of a distraction and more of an asset.

If you're wondering whether your IT and cybersecurity are where they should be, start with a 30-minute consultation. You don't need to know what to ask. That's part of what I'm here for.