Cybersecurity Tips for Kenyan SMEs
A new employee, a shared password, and one unexpected payment request reveal how everyday habits shape an SME’s security—and how to improve them affordably.
A new employee, a shared password, and one unexpected payment request reveal how everyday habits shape an SME’s security—and how to improve them affordably.
On Brian’s first day at a growing distribution company, his manager sends him the password for the shared sales email through WhatsApp. The password is easy to remember because the team has used it for several years. It also unlocks a shared cloud folder containing customer contacts and invoices.
Nobody is trying to be careless. The team is trying to help a new employee begin working quickly.
Six months later, Brian moves to another company. His email access is removed, but nobody remembers the shared password or every folder connected to it. The business has not suffered an incident, yet it no longer knows exactly who can reach some of its most important information.
This fictional story captures a common cybersecurity problem: risk grows quietly through everyday convenience. Protecting a business is not only about stopping sophisticated hackers. It is about making ordinary work safer without making it impossible.
A shared account makes accountability difficult. If an unusual message is sent or data disappears, the business cannot easily determine whose access was used. When employees leave, changing every shared password is disruptive, so access often remains open longer than intended.
Individual accounts are a better foundation. Each employee should use their own login, receive only the access required for their work, and lose that access through a documented offboarding process when their role changes.
The password for each account should be unique. Remembering dozens of strong passwords is unrealistic, which is why a password manager is more practical than asking employees to create clever variations of the same word.
Multi-factor authentication adds another barrier. If a password is stolen through phishing or reused from a breached service, the attacker still needs a second form of verification. Business email, cloud storage, banking, social media, and administrative systems should be the first accounts protected.
The safest password is not the one your whole team can remember. It is the one only the correct person can use—and that is not enough by itself.
One afternoon, Brian receives a WhatsApp message that appears to come from a senior manager. A supplier needs an M-Pesa payment immediately. The profile photograph is correct, and the writer knows the name of the project.
Brian hesitates. During onboarding, the company told him that urgent payment requests must be confirmed by calling a known number. He makes the call and discovers that the manager sent no such message.
The technical control in this story is simple: verification through a second channel. The more important control is cultural. Brian feels permitted to slow down and question authority when money or sensitive information is involved.
Staff awareness should not be a frightening annual presentation filled with technical language. A short, regular conversation about one realistic scenario can be more useful. Show employees how to inspect an unexpected link, where to report a suspicious message, and how to confirm a payment change.
When somebody reports a false alarm, thank them. A team that fears embarrassment will hide the message that eventually matters.
Customer names, telephone numbers, addresses, identification details, and transaction records can spread across email, WhatsApp, spreadsheets, laptops, and personal phones. Once copied, that information is difficult to control.
Begin by asking why each type of data is collected. If the business does not need it, do not store it. If it is required, decide where the official copy belongs, who may access it, and when it should be deleted.
Access should follow job responsibilities. A salesperson may need contact details without needing payroll records. A temporary contractor may require one project folder rather than the entire company drive. This principle limits how much information is exposed when an account is compromised.
Websites and business applications should use encrypted connections, represented by HTTPS in the address bar. Sensitive records should not move casually through personal accounts or unsecured devices simply because those channels are convenient.
If your organization handles personal data, security also forms part of responsible data protection. The appropriate controls depend on the information, the risk, and the obligations that apply to your organization.
Software updates often arrive at inconvenient times, so employees postpone them. Yet many updates repair known security weaknesses. Once those weaknesses become public, attackers can search for devices that remain unpatched.
Choose a predictable maintenance routine. Work computers, phones, browsers, office applications, routers, and website software all need attention. Remove applications and remote-access tools the company no longer uses; every forgotten service can become another doorway.
Updates should be paired with reliable backups. Keep protected copies of critical information and test that they can be restored. A green “backup complete” message is encouraging, but a successful recovery is the evidence that matters.
Imagine that Brian clicks a suspicious link despite the training. What happens next?
If he hides the mistake, an attacker has more time. If he reports it immediately, an administrator may be able to reset the account, end active sessions, inspect mailbox rules, and warn affected colleagues.
Every SME needs a simple incident path. Employees should know whom to contact and what information to provide. The responsible person should know how to secure an account, contact financial providers, preserve evidence, assess exposed information, and obtain technical help.
The plan does not need to be a fifty-page document. One page with names, telephone numbers, system owners, and first actions is a meaningful beginning.
An SME does not need to copy every control used by a bank. It needs to understand its own most important risks. For one company, that may be fraudulent supplier payments. For another, it may be customer records, an online store, intellectual property, or the cloud system used by every employee.
Start with identities, money, critical data, devices, and recovery. Give each area an owner. Review progress regularly as the team and systems grow.
Professional support becomes valuable when the business is adding many accounts, processing significant transactions, storing sensitive records, or depending on systems nobody internally knows how to secure. A practical review should prioritize the changes that reduce the most risk—not simply produce a long list of technical findings.
AvaBerg offers cybersecurity services in Kenya for SMEs, including security reviews, Microsoft 365 hardening, and staff awareness. You can also read why Kenyan SMEs are being targeted by hackers to understand how criminals turn ordinary business trust into an opportunity.
Book a security consultation and let us look at how your team actually works.
Explore related services
Need help implementing this?
Our team helps Kenyan businesses with software, security, and IT every day.
A familiar payment request, one convincing email, and a growing business can suddenly be in crisis. Here is why Kenyan SMEs are being targeted and how to respond.