Radium Technologies

Cyber security guidance for SMEs

The 3 biggest cyber security risks SMEs should address now.

Payment fraud, weak Microsoft 365 access controls and excessive administrator privileges can create disproportionate business risk. Here is where to focus first and what practical controls to review.

8 minute read Reviewed by Radium's cyber security team
01

Payment fraud

Verify changes
02

Identity and MFA

Strengthen access
03

Privileged accounts

Reduce exposure

Executive summary

Start with the controls that reduce financial, identity and administrator risk.

Cyber security improvement does not need to begin with a long technology shopping list. For many SMEs, the strongest first step is to close a small number of high-impact control gaps and make responsibilities clear.

01

Payment fraud

False bank-detail changes, urgent transfers and invoice redirection.

First control: independent verification
02

Weak access controls

Password-only access, incomplete MFA and permissive sign-in rules.

First control: consistent MFA
03

Privileged access

Routine use of Global Administrator and unnecessary local admin rights.

First control: least privilege

Risk 01 | Financial control

Payment fraud and invoice scams.

A finance user, manager or director receives an apparently genuine request to change supplier bank details, redirect an invoice or make a confidential payment quickly.

These messages are effective because they imitate a real supplier, colleague or senior decision-maker and create urgency. The technology may only be one part of the attack. The final target is a business process and a payment decision.

Typical warning signs
  • An unexpected bank-detail change.
  • Pressure to act quickly or confidentially.
  • A request that bypasses the normal approval process.
  • Subtle changes to a sender name, domain or reply address.
Practical first controls
  • Verify payment changes through a separate trusted channel.
  • Use known supplier contact details, not those in the request.
  • Require clear approval for exceptional or urgent payments.
  • Give finance teams a simple escalation route for suspicious requests.

The simple rule: when money or bank details change, confirm the request outside the email conversation.

Reduce avoidable payment risk

Review the technical and human controls around payment requests.
Discuss Payment-Fraud Controls

Risk 02 | Identity security

Weak access controls and missing MFA.

Microsoft 365 often sits at the centre of an SME's email, files, collaboration and identity. Password-only access or inconsistent controls can leave too much resting on one credential.

Multi-factor authentication is an important starting point, but the review should go further. Sign-in policy should reflect the sensitivity of the account, the device being used and the circumstances of the login.

UserKnown identity
VerificationMFA challenge
ContextDevice and location
AccessMicrosoft 365

Access-control questions worth asking.

  • Is MFA applied consistently across users and administrator accounts?
  • Can unmanaged or untrusted devices reach sensitive business data?
  • Are high-risk sign-ins blocked or challenged appropriately?
  • Are legacy authentication and weaker sign-in methods still available?
  • Can the business see unusual sign-in activity and respond to it?

Microsoft 365 security

Check whether identity controls match the way your team now works.
Check Your Microsoft 365 Controls

Risk 03 | Administrative control

Privileged access misuse.

Using broad administrator rights for normal work increases the effect of a mistake, malicious action or compromised account.

This includes people working day to day as Microsoft 365 Global Administrators and users retaining local administrator rights on laptops when the role does not require them. The objective is not to remove the ability to administer systems. It is to separate that ability from routine email, browsing and document work.

Higher exposure One account for everything

Email, web browsing, daily work and broad administration.

Better separation Standard and privileged accounts

Normal work stays separate from approved administrator tasks.

Apply least privilege in practical terms.

  • Remove day-to-day Global Administrator use.
  • Use separate privileged accounts for administrative work.
  • Assign the narrowest suitable role for each task.
  • Remove unnecessary local administrator rights.
  • Review privileged access regularly and after role changes.

Reduce the blast radius

Separate routine work from powerful administrator access.
Review Privileged Access

A practical SME action plan

Seven sensible actions to prioritise.

These actions provide a focused starting point for reducing common cyber security exposure without turning the programme into a disruptive transformation project.

  1. 01
    Verify payment changes outside email.

    Use a known phone number or another trusted communication route.

  2. 02
    Enforce MFA across Microsoft 365.

    Include administrator and other high-impact accounts.

  3. 03
    Review sign-in and Conditional Access controls.

    Consider devices, locations, risk and business requirements.

  4. 04
    Stop routine Global Administrator use.

    Keep broad privilege away from daily email and browsing.

  5. 05
    Remove unnecessary local admin rights.

    Retain them only where a defined business or technical need exists.

  6. 06
    Separate privileged accounts.

    Use protected accounts only for approved administrative tasks.

  7. 07
    Review who has access and why.

    Update permissions as roles, systems and working practices change.

Microsoft 365 security review

Identity security is business risk management.

Microsoft 365 can hold customer communications, commercial documents, shared files, meeting data and the identities used to access connected services. That makes authentication and privileged access relevant to leadership, finance, operations and compliance, not only the IT team.

A useful review should identify control gaps, prioritise practical remediation and document the agreed position. It should not rely on a product badge or imply that risk has been eliminated.

Arrange a Microsoft 365 Security Review
AuthenticationMFA and sign-in policy
AccessRoles and permissions
DataDevices and sharing
VisibilityReview and reporting

Frequently asked questions

Cyber security risks for SMEs.

What is the biggest cyber security risk for SMEs?

Payment fraud, weak access controls and privileged access misuse are three high-priority risks because they can lead directly to financial loss, data exposure and operational disruption.

Why is multi-factor authentication important for SMEs?

Multi-factor authentication adds a second verification step, reducing reliance on a password alone when protecting Microsoft 365 and other business systems.

Why should staff not work day to day as Microsoft 365 Global Administrators?

Global Administrator access provides broad control over a Microsoft 365 environment. Separate privileged accounts and least-privilege roles can reduce the impact of mistakes or account compromise.

Why are local administrator rights risky?

Local administrator rights may allow software installation, security control changes and wider system modification. They should be limited to people and tasks that genuinely require them.

How can an SME improve cyber security without making work difficult?

Start with clear payment verification, multi-factor authentication, sensible sign-in controls, separate administrator accounts and regular access reviews.

Need a second pair of eyes?

Turn the three priority risks into a practical security review.

Tell Radium about your Microsoft 365 environment, access concerns or current security priorities. Service scope and recommendations are agreed around your requirements.