ISEC7 Digital Workplace Blog

Security Maturity Model Part 1: SOHO and SMB Security

Written by Remi Keusseyan | Oct 12, 2021, 7:30:00 AM

Reviewed and updated in October 2026.

Cybersecurity in a business depends on many factors: the number of employees, how the environment is deployed, likely attacks and attack vectors, the types of devices in use and the corporate device policies. On top of that comes a vast range of security solutions, each promising to protect your environment and spare you costly downtime or damage to your reputation. This two-part series shows how these solutions build on each other as an organization grows.

A security maturity model describes the stages an organization's security posture passes through as the organization grows, and which controls each stage adds to the previous one. Its value is in sequencing: it tells you what to do next instead of everything at once. Formal frameworks such as the NIST Cybersecurity Framework 2.0 with its four implementation tiers follow the same idea; the four levels in this series are a practical simplification for growing organizations.

How should your security posture grow with your business?

To show how security has to adapt as a company grows, we break our security maturity model into four levels. Not every organization fits neatly into one of them, but the progression holds. This part covers levels 1 and 2. Part 2 covers levels 3 and 4.

Level 1: Small office, home office (SOHO)

Level 1 mostly consists of small office, home office (SOHO) businesses: a very small number of employees, sometimes a single person, working from a small office or from home. There is no dedicated IT infrastructure or IT staff. The business uses free or low-cost online collaboration tools such as Gmail and unmanaged, personally owned desktops and phones.

Insure your business

Losing all your data, including customer data, can seriously damage a small business or end it. A larger organization can absorb an incident that a small one cannot. Weigh the cost of a cyber insurance policy that covers ransomware against the cost of not having one.

Protect your data

Make sure corporate and customer data is stored safely, both locally on your computer, using operating system or full-disk encryption, and at your cloud service provider. Back up or sync your data to cloud storage so you can recover it at any time. Use a password manager to store the credentials you need every day; it also helps you avoid reusing passwords or choosing weak ones. Turn on multi-factor authentication for email, cloud storage and the password manager itself wherever it is offered. Stolen passwords are far less useful to an attacker when a second factor is required.

Protect your endpoints

Run antivirus protection on every computer to block known threats. Current operating systems include a basic level of protection, such as Microsoft Defender Antivirus in Windows; make sure it is active. Install operating system and software security updates regularly to keep your computer and its data safe from known exploits.

Level 2: Small and medium-sized businesses (SMB)

Level 2 applies mainly to small and medium-sized businesses (SMB). The number of employees grows from a dozen to around a hundred, usually in one central office, with some employees working from home permanently or occasionally. One or two generalists manage IT, using online collaboration tools such as Google Workspace or Microsoft 365, and a mix of company-owned and personally owned desktops and mobile devices. Some companies also run a small local data center for specific tasks, for example a software company that builds and tests its products under real conditions.

Everything from level 1 still applies: insure your business, protect your data. The following measures are updated or added.

Protect your endpoints (updated)

Antivirus software that only reacts to known threats is no longer enough at this size. It is time to set aside a budget for next-generation protection that also detects unknown threats by their behavior: an Endpoint Protection Platform (EPP), ideally combined with Endpoint Detection and Response (EDR), on desktops and servers, and Mobile Threat Defense (MTD) on smartphones and tablets. How these product types differ is explained in Demystifying Security: EPP, EDR and MTD.

Manage your endpoints (new)

As the workforce grows, so does the number of endpoints, from desktops to smartphones and tablets, and many employees use more than one. A Unified Endpoint Management (UEM) solution becomes a must to manage all of them, desktop or mobile, company-owned or personal, and to provide users with the work apps they need. It gives them controlled access to corporate networks such as Wi-Fi and VPN and enforces security settings such as password rules and OS updates, so devices stay compliant with your internal requirements. Our article Best Practice: Get the Most out of Your UEM shows which threats a UEM can prevent on its own.

Protect your local network (new)

As soon as roaming or home-based employees need remote access to your local network, that access has to be protected. A common option is Virtual Private Network (VPN) software, usually on desktop computers, as it lets users reach most internal resources as if they were in the office. For mobile devices, the best option is usually the one offered by your UEM vendor: either the vendor's own secure connectivity infrastructure, as with BlackBerry UEM, or a VPN limited to specific work apps (per-app VPN), so security does not get in the way of the user experience.

Why the cheapest option is rarely the cheapest

Understanding your business and its operational needs is the basis for choosing a security solution that addresses your actual vulnerabilities. Some solutions cost little or nothing, but they may not protect adequately or may leave part of your organization uncovered. The savings are visible immediately; after an attack, they are gone. Read on in Security Maturity Model, Part 2, which covers larger and international organizations.

Frequently asked questions

What is a security maturity model?

A security maturity model describes the stages an organization's security posture passes through as it grows, and which controls each stage adds. It helps prioritize the next step instead of buying everything at once.

Which security measures does a small business need first?

Backups, encryption, a password manager, multi-factor authentication, active antivirus protection and regular updates. Cyber insurance is worth weighing because a small business can rarely absorb a total data loss.

When does a business need a UEM solution?

When the number of desktops and mobile devices outgrows what one person can configure by hand, and especially when company-owned and personal devices access corporate data side by side.

How does this model relate to the NIST Cybersecurity Framework?

The NIST Cybersecurity Framework 2.0 describes four implementation tiers for how rigorously an organization manages cyber risk. The four levels here are a simpler, size-based view of the same progression and can serve as a starting point for a formal assessment.

Not sure which level your organization is at? ISEC7 advises on endpoint security and endpoint management and can provide an objective assessment of what your organization needs. Contact us.