Security and continuity · reviewed 25 August 2026

SME cybersecurity 2026: a 30-day agenda

Reviewed on 25 August 2026: INCIBE published an update to its risk-management guide for business owners on 5 February and a cybersecurity-supervision guide for non-technical leaders on 13 May. Both start with a useful SME idea: security is a business decision, not a pile of products.

Start with what can stop the business

List five services you cannot sell, collect payment or support customers without: till, bookings, email, shop, ERP, connected machinery or warehouse access. For each, name the owner, suppliers, data handled and how long you could operate without it.

You do not need a perfect mathematical score. You need to expose dependencies: a shared account, a backup never restored, a vendor nobody knows how to call, or a laptop with total access. Those dependencies are more actionable than a “high risk” label with no owner.

The one-page risk register

Use six columns: asset or process, scenario (fraud, ransomware, outage, leak), impact, current controls, owner and next test. Rank by impact on sales, operations, customers and obligations, not by how new the tool sounds.

A 30-day agenda

  1. Days 1–5: inventory accounts, devices, domains, suppliers and backups.
  2. Days 6–10: turn on MFA for email, administration and banking; remove stale accounts.
  3. Days 11–15: test a real restore and document who can perform it.
  4. Days 16–20: patch exposed systems, limit privileges and separate daily and admin accounts.
  5. Days 21–25: write a one-page response plan: who to call, what to isolate, what evidence to keep and when to notify.
  6. Days 26–30: run a phishing or lost-access drill and record what failed.

What to ask a vendor

Ask for concrete coverage: assets included, alerts, response times, backups, updates, subcontractors, log retention and exit. Ask who acts at 3 a.m. and what they need from you. “We have a dashboard” is not a continuity plan.

Fit with subsidised digitalisation

A cybersecurity solution can be part of a digitalisation decision, but the grant does not transfer risk. Keep the grant file, the contracted service and the control your team must maintain after support ends separate. A provider’s accreditation does not certify that your business is protected.

Bottom line: after 30 days you should answer four questions: what can fail, how will you know, who decides, and how do you resume operations? If not, buy focused help, not another layer of words.

Official sources checked on 25 August 2026: INCIBE · risk management, 2026 update and INCIBE · supervision for non-technical leaders. This is a working guide, not certification or legal advice.

Studio in Barcelona. Part of Clutch Developer. Oriented to Spain’s SME digitalisation programmes. Request an assessment.

Free assessment

Contact