The email looked exactly right. Same supplier, same logo, same signature — just a polite note that bank details had changed for the next invoice. The accounts officer at a Lagos distribution firm paid it. Fourteen million Naira, gone. The attacker had been sitting quietly inside a compromised mailbox for five weeks, reading everything, waiting for an invoice large enough to be worth cashing out.
That breach didn't start with genius hacking. It started with a reused password. After twelve years securing systems for over 250 clients across Nigeria and the UK, we can tell you that almost every incident we get called into traces back to one of five boring, entirely preventable mistakes. Here they are — why they happen, what they really risk, and how to close each one.
Mistake 1: Weak or reused passwords, and no MFA
Why it happens: Password fatigue is real. Staff juggle dozens of accounts, so they reuse one memorable password everywhere — office email, the CRM, their personal Facebook. When any one of those services gets breached (and breaches of big platforms happen constantly), that password ends up in criminal databases within days.
The real risk: Attackers run "credential stuffing" — automatically trying leaked email-and-password pairs against business email systems. One hit and they're inside your mailbox, which is exactly how the invoice fraud above began. Business email compromise is one of the most financially damaging attacks in Nigeria today, and it rarely trips any alarm because the attacker logs in with valid credentials.
The fix: Two moves. First, roll out a password manager company-wide so every account gets a unique, generated password nobody has to remember. Second — and this is the single highest-value security control available — turn on multi-factor authentication (MFA). Start with email, banking, and admin accounts this week. Prefer an authenticator app over SMS codes, since SIM-swap fraud is a live threat here. Microsoft's research suggests MFA blocks the overwhelming majority of account-takeover attempts. It costs almost nothing.
Mistake 2: Outdated and unpatched software
Why it happens: "It works, don't touch it." Updates feel like a nuisance that might break something during a busy week, so they get postponed indefinitely. Some businesses also run unlicensed software that can't receive updates at all, or old machines still on Windows 7 or Server 2012 — systems that stopped receiving security fixes years ago.
The real risk: When a vendor publishes a patch, attackers immediately reverse-engineer it to learn exactly what hole it fixes, then scan the internet for anyone who hasn't applied it. The WannaCry ransomware outbreak spread through a vulnerability Microsoft had patched two months earlier — the victims were simply those who hadn't updated. Running unpatched software is like publishing your office key-cutting pattern and hoping nobody local reads it.
The fix: Turn on automatic updates for operating systems, browsers, and antivirus. Put a monthly patch check in someone's actual job description — unowned tasks don't happen. Inventory every system past its end-of-support date and budget its replacement; an old server that "still works" is a liability, not a saving.
Mistake 3: No staff awareness or phishing training
Why it happens: Owners assume security is the IT department's problem, and that firewalls and antivirus handle it. But most attacks don't target your firewall — they target Chidi in accounts on a Friday afternoon, with an urgent, plausible email.
The real risk: The large majority of successful breaches begin with a human being tricked, not a system being hacked. One click on a fake "shared document" link harvests credentials; one convincing "urgent payment" message from a spoofed MD's address moves money. Technology cannot fully compensate for a team that has never seen what an attack looks like.
The fix: Short, regular training beats an annual lecture — fifteen minutes a quarter showing real phishing examples your industry actually receives. Run occasional simulated phishing tests, and treat failures as teaching moments, not punishments. Most importantly, set one hard rule: any change to payment details or any unusual payment request gets verified by phone, using a number you already have on file — never one from the email itself. That one rule would have saved the firm in our opening story ₦14 million.
Mistake 4: No backups — or backups nobody has ever tested
Why it happens: Optimism, mostly. Nothing bad has happened yet, so backups slip down the list. The subtler version is worse: a backup was configured years ago, it runs silently (or silently fails), and nobody has ever tried restoring a single file from it.
The real risk: Ransomware encrypts everything and demands payment; a stolen laptop or a burnt-out office server does the same damage without the ransom note. We have sat with a business that discovered, mid-crisis, that its backup job had been failing quietly for eight months. An untested backup is not a backup — it's a hope.
The fix: Follow the 3-2-1 rule: three copies of your data, on two different types of storage, with one copy offsite (cloud backup handles this well, and works even with Nigeria's power realities since it doesn't depend on an office server staying on). Then schedule a restore test every quarter: actually recover a folder and open the files. Put it in the calendar. Under the Nigeria Data Protection Act, losing customer data isn't just an operational disaster — it can mean regulatory penalties running into millions of Naira, so provable recoverability matters legally too.
Mistake 5: Everyone has access to everything — and leavers keep theirs
Why it happens: In a growing business, giving everyone admin rights is simply easier than thinking through who needs what. Shared logins ("the office password") spread for the same reason. And when someone resigns, HR handles the paperwork but nobody owns disabling their accounts.
The real risk: Over-broad access means one compromised (or disgruntled) account can reach payroll, customer records, and financials at once. Shared logins destroy accountability — when something goes wrong, the audit trail says "admin". And ex-employees with live credentials are a documented source of data theft, especially when they leave for a competitor and your customer database goes with them.
The fix: Apply least privilege: each person gets access to what their role requires, nothing more. Kill shared accounts. Build a one-page offboarding checklist — email, CRM, accounting software, social media, Wi-Fi, door codes — and disable everything on the leaver's last working day, not "sometime after". Then audit all access quarterly; you will be surprised what you find the first time. Our cybersecurity services team runs exactly this kind of access audit for clients, and the first one almost always turns up accounts belonging to people who left over a year ago.
Where to start (without an enterprise budget)
You don't need a bank's security budget to stop being an easy target. Attackers are opportunists; they take the unlocked doors first. This week: enable MFA on email and banking. This month: deploy a password manager, switch on automatic updates, and run one backup restore test. This quarter: hold your first phishing-awareness session and write the offboarding checklist.
If you'd rather have professionals assess where you actually stand — what's exposed, what's overkill, what to fix first — book a free demo with WebMotion HQ. We'll review your setup against these five mistakes and give you a prioritised fix list, whether or not you ever hire us.
Common questions
What is the most common cybersecurity mistake small businesses make?
Reused passwords without multi-factor authentication. It gives attackers a valid login rather than something they have to hack, which is why business email compromise and invoice fraud so often start there. Enabling MFA on email and banking is the single fastest fix.
Is MFA really necessary for a small business?
Yes. Attackers automate credential attacks, so size is no protection — small firms are targeted precisely because their defences are weaker. MFA blocks the overwhelming majority of account-takeover attempts and costs little or nothing to enable.
How often should we test our backups?
Restore-test at least quarterly: actually recover a folder and confirm the files open. A backup that has never been restored is unverified, and silent backup failures that run for months are one of the most common discoveries we make during audits.
How much should a small business budget for cybersecurity?
The essentials — MFA, a password manager, automatic updates, cloud backup, and basic staff training — cost very little compared to a single incident. A reasonable starting point is a small monthly per-user spend plus an annual security review, scaled up as you handle more sensitive data.
What should be on an employee offboarding security checklist?
Disable email, CRM, accounting and admin accounts on the last working day; revoke social media, cloud storage and Wi-Fi access; recover company devices; change any shared credentials the person knew; and log the completed checklist so nothing is left to memory.