Cybersecurity Basics for African SMEs: What to Fix Before You Get Hit
"We're too small to be a target" is the single most dangerous sentence in African SME security, and it's wrong on both counts. Attackers don't manually pick targets one business at a time — they run automated scans across thousands of systems looking for the easy ones: default passwords, unpatched software, exposed databases. Small businesses aren't ignored because of their size; they're targeted because of their size, precisely because they tend to have the weakest defences and the least capacity to respond.
We've walked into businesses across Zimbabwe and South Africa where the entire admin panel of their business system was protected by a password shared across five staff members, unchanged since the system was built three years earlier. That's not a hypothetical risk. That's a business one disgruntled former employee or one phishing email away from a serious problem.
The State of SME Security Across the Region
Most African SMEs run some combination of the following, often without realising each one is a real exposure:
- One shared login for a POS system, accounting software, or admin dashboard — used by every staff member, never rotated, sometimes written on a sticky note
- No backups, or backups that exist but have never been tested to confirm they actually restore
- Software running years out of date because "it still works," with known security patches never applied
- Customer data — names, phone numbers, ID numbers, sometimes payment details — stored in spreadsheets on a single laptop with no encryption and no access control
- Free or personal email accounts used for business banking, mobile money admin, and domain registration, all without two-factor authentication
None of this requires a sophisticated attacker to exploit. Most of it can be exploited by anyone who guesses a weak password, buys a leaked credential list off the dark web for a few dollars, or simply asks nicely over the phone pretending to be IT support.
Why This Is Getting Worse, Not Better
As more African SMEs move core operations onto digital systems — mobile money, cloud accounting, customer databases, WhatsApp business tools — the amount of valuable data sitting behind weak security grows every year. Attackers have taken notice. Ransomware groups that used to focus exclusively on large enterprises in the US and Europe increasingly run automated campaigns that don't care what country or company size they hit — if the system is reachable and vulnerable, it's a target.
What actually happens in practice: most SME "breaches" we see aren't dramatic hacking scenes. They're a staff member's shared login used to quietly export a customer database before they leave for a competitor. They're a ransomware email opened on a laptop with no backup, followed by every file on the business being encrypted and a payment demand appearing. They're a WhatsApp Business account taken over because 2FA was never turned on, then used to scam the business's own customers. Boring, avoidable, and expensive.
The Non-Negotiable Basics
1. Every Person Gets Their Own Login
Shared accounts are the single biggest fixable risk in most SMEs. Every staff member should have their own username and password for every business system. This isn't bureaucracy — it means when someone leaves, you revoke one account instead of changing a password everyone else also has to relearn. It also means you can actually tell who did what, which matters enormously when something goes wrong.
2. Two-Factor Authentication on Anything That Touches Money or Customer Data
Banking, mobile money admin portals, email, cloud accounting, and your core business system should all require a second factor — a code from an app or SMS — in addition to a password. This single control blocks the overwhelming majority of account takeover attempts, even when a password has been stolen or guessed.
3. Backups That Are Actually Tested
A backup you've never tried to restore is not a backup — it's a guess. Automated daily backups, stored somewhere separate from the main system (a different server, a cloud provider, not just another folder on the same machine), with an actual restore test done at least quarterly. Ransomware's entire business model depends on you not having a working backup to fall back on.
4. Software That Gets Patched
Security patches exist because a vulnerability was found and fixed. Running unpatched software means running with known, publicly documented holes in it. This applies to your operating systems, your website's plugins and frameworks, and any custom software your business runs — someone needs explicit responsibility for keeping it updated.
5. Access Control That Matches Roles
Not every staff member needs access to everything. A cashier doesn't need admin rights to your inventory system's pricing engine. A driver doesn't need access to customer financial records. Limiting access to what a role actually requires means a single compromised account causes far less damage.
POPIA and Zimbabwe's Data Protection Act: The Basics
If your business collects customer personal information — names, ID numbers, phone numbers, health records, financial details — you're very likely covered by data protection law, whether you've thought about it or not.
South Africa's POPIA (Protection of Personal Information Act) requires businesses to process personal information lawfully, secure it against loss or unauthorised access, only collect what's necessary for a stated purpose, and report data breaches to the Information Regulator and affected individuals when they occur. Non-compliance can mean fines and, in serious cases, criminal liability for responsible parties.
Zimbabwe's Data Protection Act (2021) imposes broadly similar obligations — lawful processing, security safeguards, breach notification, and rights for individuals over their own data — enforced through the Cyber Security and Data Protection framework and POTRAZ.
For most SMEs, the practical takeaway is the same in both jurisdictions: know what personal data you actually hold, secure it properly, don't keep it longer than you need to, and have a plan for what happens if it's ever exposed. This isn't primarily a legal exercise — the security basics above are also, largely, your compliance basics.
What to Ask a Software Vendor About Security
If you're commissioning custom software or evaluating an off-the-shelf system, security shouldn't be an afterthought you raise after the system is already live. Ask upfront:
- How is customer and business data encrypted, both stored and in transit?
- Does the system support individual logins and role-based access control, or is it one shared admin account?
- Is two-factor authentication available, and is it required for admin-level access?
- What's the backup schedule, where are backups stored, and how often are restores actually tested?
- Who is responsible for applying security patches after the system goes live — us, or the developer, under what agreement?
- If there's ever a data breach, what's the notification process, and does it meet POPIA or the Data Protection Act's requirements?
- Does the vendor follow secure development practices, or is this the first time they've been asked?
What to Do in the First 48 Hours After Something Goes Wrong
Even well-secured businesses can be hit — no set of controls makes a business invulnerable, only less likely to be an easy target. What actually determines how much damage a breach does is how the first two days are handled. Isolate the affected system first, before anything else, by disconnecting it from the network to stop the spread. Change every credential that could plausibly have been exposed, not just the obvious ones. Restore from your tested backup rather than paying a ransom, which funds the next attack and offers no guarantee your data comes back intact anyway. And notify affected customers and, where legally required under POPIA or Zimbabwe's Data Protection Act, the relevant regulator — quietly hoping nobody notices is not a strategy, and delayed disclosure tends to make the eventual fallout worse, not better.
Having this plan written down before you need it, even in a simple one-page form, is the difference between a calm, controlled response and a panicked scramble while customers and staff are asking questions nobody has answers to.
Security Doesn't Have to Be Expensive
Most of what's described here isn't costly — it's disciplined. Individual logins, two-factor authentication, and a tested backup routine cost very little to implement compared to the cost of a breach, a ransomware payment, or a regulatory fine. The businesses that get hurt badly are almost always the ones that never got around to the basics, not the ones that invested in expensive enterprise security tools they didn't need.
Keep Reading
- How to Build Business Software That Survives Load Shedding
- In-House vs Outsourced Dev Team: What Growing African Businesses Should Choose
- Your Business Has Outgrown Excel: Here's What to Do Next
- Our Engineering Approach →
Not sure how exposed your business actually is?
We build business software with proper access control, encryption, and backup discipline built in from day one — and we can review what you're already running. Book a free 30-minute call and we'll give you a straight answer on where your real risks are.
Book a Free Discovery Call