The question is not “if”, but “when”
Every business, of any size, is a target: ransomware hits SMEs more often precisely because they are less protected. Xion IT Group handles the protection of IT systems using XSN (Xion Secured Network), a multi-layered security system far more advanced than traditional antivirus.
Cybersecurity and IT security: same thing, two terms
Anyone searching for “cybersecurity” and anyone searching for “IT security” is looking for the same service: protecting data, systems and business continuity. The difference is where the term comes from. “Cybersecurity” comes from the language of regulations and tenders — NIS2, national cyber perimeters, technical specifications — and is used more often by those with a formal compliance requirement. “IT security” is the term used by those with a practical problem: an attack suffered, a backup they do not trust, a supplier who is not responding.
It is worth saying because it changes the right question to ask. If the starting point is a regulatory requirement, the first thing to define is the scope: which services are critical, who is responsible for what, and with what recovery times. If the starting point is an incident or a concern, the first thing is to verify the real state of play — what is exposed on the internet, whether backups are actually restorable, and who holds accounts with administrative privileges.
The technical result is the same. The order of priorities is not.
How much it changes from one sector to another
Priorities are not the same for everyone. In logistics and transport the worst damage is operational downtime: a warehouse unable to ship for two days costs more than the ransom, and management systems are often connected to customers’ systems, widening the attack surface across the whole supply chain. In manufacturing the risk shifts to production machinery, which tends to have long life cycles and operating systems nobody updates. In professional practices the issue is responsibility for third-party data: a data breach affects not only the firm, but all its clients.
These are three different approaches to the same job. It makes sense to start from your own sector, not from a generic list of products.
Multi-layered defence
Linux and Unix based firewalls
The firewall creates filters on inbound and outbound connections, carrying out traffic control, modification and monitoring. It is the first barrier between your network and the outside world, configured specifically for your organisation.
Content filtering
Content filtering systems block access to websites considered harmful or unrelated to work activity - games, online casinos, pornographic sites and other configurable categories. Two benefits: fewer web-borne threats and fewer distractions during working hours.
Proxy systems
Corporate proxies perform five key functions:
- Connectivity - controlled internet access for private networks;
- Caching - temporary storage of requests for faster browsing;
- Monitoring - tracking of activities carried out;
- Control - enforcement of the company’s administrative rules;
- Privacy - masking of clients’ real IP addresses.
Security is a process, not a product
Installing protection and then forgetting about it is the best way to get hit. That is why we support technology with continuous monitoring and update services: defences are kept aligned with threats, and every anomaly is handled by technicians specialised in security.
Today’s threats, in practical terms
The threat landscape evolves faster than the defences of those who do not deal with it full time. These are the threats we most often see affecting Italian businesses:
- Double-extortion ransomware — data is copied before being encrypted: on top of the disruption comes the blackmail of publication;
- AI-enhanced phishing — emails perfectly matching the style of a supplier or colleague, almost impossible to recognise at a glance;
- Credential theft — from reused passwords to session cookies: anyone logging in with valid credentials triggers no alarm at all;
- Supply chain attacks — a smaller supplier is targeted to reach a larger client;
- Unpatched vulnerabilities — most incidents exploit flaws for which a fix had existed for months.
Defence in depth: the layers that matter
No single technology stops everything: serious protection is built on independent layers, each ready to stop what escaped the previous one.
- Perimeter — a firewall that is configured and maintained, not installed and forgotten;
- Email — anti-phishing and anti-spoofing filters, the entry channel for 80% of attacks;
- Endpoints — modern protection (EDR) on every PC and server, able to detect abnormal behaviour;
- Identity — MFA everywhere, password managers, least-privilege access;
- Internal network — segmentation: getting into one area must not mean being able to move everywhere;
- Data — off-site, versioned backups, the final line that turns catastrophe into inconvenience;
- People — continuous training, because the human layer is the first target.
With XSN these layers are designed, integrated and maintained over time — with continuous monitoring and updates.
Email is the main entry point, not the network
In the vast majority of incidents we see, the attack does not come in by forcing a firewall: it comes from an email opened by someone doing their job. That distinction matters, because it shifts the centre of gravity of defence from appliances to procedures.
The three forms we encounter most often:
The invoice that looks genuine. It arrives from a real supplier, with an attachment that opens. It is genuine-looking because that supplier’s mailbox was compromised first, and the attack travels inside an existing conversation. The spam filter does not stop it: there is nothing obviously abnormal to block.
The bank account change. No malware, no attachment: just an email from a supplier’s accounts department stating new bank details. It is the most profitable attack of all and it is defended against with a procedure, not software — verification through a different channel from the one that delivered the request.
The fake login page. A link leads to a screen identical to the corporate email login page. Whoever signs in hands over their credentials, and from that moment the attacker reads email without anything appearing broken. This is exactly where multi-factor authentication makes the difference between inconvenience and disaster.
Multi-factor authentication is the single most effective measure
If we had to name just one measure with the best ratio between cost and risk avoided, this would be it. A stolen password on its own is no longer enough to get in: the attacker also needs that person’s phone.
It costs little, can be enabled in a few hours, and should be applied, in order of priority, to email, remote access and administration panels. In most of the companies we visit, email has it and the other two do not — which is the wrong order, because remote access is how attackers reach servers.
The first forty-eight hours of an attack
Knowing what to do before you need it is half the defence. The correct order is counterintuitive, because the first instinct — switch everything off and restore — often makes the situation worse.
- Isolate, do not power off. Disconnecting the network stops the attack spreading; abruptly shutting systems down destroys information needed to understand what happened and how the attacker got in.
- Do not restore immediately. If you do not know how the attacker got in or how long they have been inside, restoration reintroduces the problem. In most cases the attacker had been inside for days or weeks before revealing themselves.
- Check backups before touching them. You need to verify which copy is intact, and protect it before doing anything else.
- Change the highest-privilege credentials, from a clean machine.
- Document while you work. It helps you, and it matters if the incident has to be notified — which GDPR requires within seventy-two hours when personal data is involved.
This sequence cannot be improvised at three in the morning: it has to be written down in advance, and knowing who calls whom is the part most often missing.
How far an attack can spread
A practical example
One client received an email “from their long-standing supplier” with new bank details, perfect in every respect. The email security filter flagged it as suspicious because of a technical anomaly in the domain; the out-of-band verification procedure — introduced during training — did the rest. Damage avoided: the value of three supply orders. Cost of the defence that stopped it: a fraction of that.
What to ask anyone selling you security
The cybersecurity market is full of acronyms, and acronyms are the fastest way to avoid being understood. Four questions bring the conversation back to what matters.
Who looks at alerts, and when? A protection system generates alerts. If nobody reads them outside office hours, then protection only works in office hours — and attacks do not. The question is not which technology you use, but who is watching it at two in the morning.
What happens when an alert is triggered? There needs to be a written procedure with names and times, not a promise to intervene. Who isolates the machine, who informs the company, who decides whether to stop systems.
How often is restoration tested? An untested backup is not a defence. It is the question that most quickly exposes proposals made up only of products.
What is not covered? It is the most useful question and the one nobody asks. The most expensive grey area sits between monitoring and response: many contracts say they will notify you, not that they will intervene.
Security is also organisation, not just technology
Half of the critical issues we find in assessments are not solved by buying anything:
- accounts belonging to people no longer working in the company, still active because nobody keeps track of who can access what;
- permanent supplier access, opened for maintenance and never closed;
- administrator privileges given to everyone, so nobody has to be called to install software;
- shared passwords on a sheet of paper, in a mailbox or on a note;
- nobody knowing who to call if something happens outside office hours.
All of these can be fixed with a procedure and an afternoon’s work, and they reduce risk more than many purchases. That is why our starting point is always an assessment and not a quotation: first you look, then you decide what is really needed.
Who is responsible for what, within the company
There is a common and costly misunderstanding: cybersecurity is seen as a technical matter, and therefore delegated entirely to whoever manages the systems. In reality there are three roles, and they remain distinct even when management is outsourced.
The data controller — the company — decides purposes and means and remains legally responsible; it cannot delegate that responsibility, only choose carefully who carries out the work. The data processor is the supplier handling data on behalf of the controller, and its duties must be set out in writing in a contract. The system administrator is the person with privileged technical access, must be formally appointed in writing, and their activities must be logged.
Clarifying these three roles is not bureaucracy: it is what determines, on the day of an incident, who was supposed to do what. We also cover this on the practical GDPR page.
Where to start
If you did only three things this month: enable MFA on email and remote access, verify that your backup is off-site and tested, and have a vulnerability assessment carried out on exposed systems. These are the three measures that stop most real-world attacks — and they are exactly the starting point of our security assessment.
Microsoft 365 and the first hours of an attack
Two related resources: Microsoft 365 security, where default settings leave three important gaps, and incident response, with the sequence to know before you need it.