Ask five different providers what security your business needs, and you'll often get five different answers, some wildly expensive, some barely adequate. That's because a lot of security advice isn't actually built around your business. It's built around a generic template, sold the same way to a five-person shop and a five-hundred-person enterprise.
Neither end of that spectrum is actually protection. It's just spend in the wrong place.
The Overkill Problem
It's entirely possible to be "secure" on paper and still be poorly protected in practice. Enterprise-grade tooling sold to a small business often brings enterprise-grade complexity with it: dashboards nobody has time to monitor, alerts nobody's trained to act on, licences for features that never get switched on. The result isn't better security. It's a bigger bill and a false sense of coverage, because owning a tool isn't the same as using it properly.
The Underprotection Problem
The opposite mistake is just as common, and often more dangerous because it's less visible. A business assumes a basic antivirus and a firewall from a decade-old router setup counts as "covered," without ever assessing what data they actually hold, what an attacker could actually reach, or what a breach would actually cost them. This is where the real damage happens, not because nobody tried, but because nobody actually measured the risk before deciding what to spend on it.
What "Right-Sized" Actually Means
Proper security starts with a genuine question, not a product list: what are you actually protecting, and what's it worth to someone who wants it? A GP practice holding patient records has a fundamentally different risk profile to a small retailer with a till system, even if both are technically "small businesses." The right level of protection follows from that assessment, not from a generic package sold identically to both.
In practice, that usually means:
- Understanding what data you hold and where it actually lives, not just what you assume
- Matching protection to genuine risk, not to what sounds impressive in a sales pitch
- Choosing tools your team will actually use and understand, not ones that sit unmonitored
- Reviewing and adjusting as the business grows, rather than setting it once and forgetting it
Actively Managed, Not Just Installed
The other half of "right-sized" is ongoing attention. A firewall configured correctly on day one and never touched again drifts out of date the same way anything else does. Security that's actively managed means someone is actually watching for the warning signs, reviewing what's changed, and adjusting as new threats and new parts of the business appear, not just installing something once and calling it done.
Getting an Honest Read on What You Actually Need
If you're not sure whether your current setup is overkill, underprotected, or somewhere in between, that's exactly the kind of thing a proper review answers, not with a generic checklist, but by actually looking at what you have and what you're trying to protect.