You have finally set money aside for security, and every vendor you speak to has a product that belongs at the front of the queue. Before you buy any of them, there are three things that come first. Skip them and you will remain on the vulnerable side even after the purchase. Here is how to prioritize your first Cyber budget.

Prioritize by what it costs you to ignore it
Most security advice for small companies is a list of EVERYTHING. A list of everything is useless. You can't do everything.
So start with the most important, and go from there. For each product / service you consider, ask yourself: what would it cost me to ignore this?
Based on my experience, here's what I would recommend as the very first steps in improving your security posture.
First: Multi-Factor Authentication (MFA)
Turn on multi-factor authentication everywhere before you buy anything else. On most apps, this is a free setting you just need to take a few minutes to set up.
Meyer et al., Microsoft: MFA reduced the risk of compromise by 99.22%, and by 98.56% for accounts whose passwords had already leaked.
Start with email, then your bank, your accounting software, and anything that can move money or reset another account's password.
Bonus tip: An authenticator app beats SMS, and a hardware key beats an authenticator app
Second: backups
Buy the backup, then spend one afternoon proving it comes back.
Sophos, The State of Ransomware 2026: of organisations whose data was encrypted, 66% got it back from their own backups — up twelve points on the year before.
Keep one copy offline or immutable, then restore it onto a clean machine and open the files. The one-page plan behind that afternoon is in why untested backups fail.
Third: a phone call before any payment change
When a supplier's bank details change, call them on a number you already had on file.
A phone number that arrives with the request belongs to whoever sent it, so don't trust it!
Most people ignore this, but it is where the money actually is, and hackers know this.
FBI Internet Crime Complaint Center, 2025 Annual Report: business email compromise cost reporting victims $3.05 billion in 2025, second only to investment fraud, and 86% of it moved by wire transfer or ACH.

There's nothing you buy to prevent this. It is a process you need to enforce inside your company. The malicious email is a correct-looking invoice carrying someone else's account number, with no attachment, no link, and no malware for a filter to catch.
Hence, the control is a rule you write down. Pick an amount. Anything above that requires a second pair of eyes and a call-back on a trusted number from your own records before the payment goes out.
Make the rule apply to you as well as to your bookkeeper. Attackers ask for an "urgent exception", usually in the founder's name, and a rule the founder can wave through is not a rule at all.
Already clicked "send"? Act fast: you don't have much time
Speed is the only control left. In 2025, the FBI's Recovery Asset Team was asked to freeze $1.16 billion across 3,900 incidents.
FBI IC3, 2025 Annual Report: the Financial Fraud Kill Chain froze $679,013,183 — a 58% success rate.
Call your bank first and use the word recall — you are asking them to pull the wire back, which is a different request from reporting a fraud. Ask what indemnification paperwork they need and provide it the same hour, because the recipient bank can only freeze what has not yet moved on.
Then file the transaction details with law enforcement — in the US that is ic3.gov, and the FBI asks victims to file regardless of the amount, because a freeze request on a recipient account also catches the next victim paying into it.
When to start buying the tools
If you have the three controls above in place, congratulations! You have a floor to stand on.
Now, yes, the next spend is worth a proper list: essential cyber hygiene.
Written for enterprises with limited IT and security expertise by the Center for Internet Security, it is a free guide you can use to help you figure out what to improve next.
Let's be honest: have you set up MFA everywhere?
Whether those controls would actually hold on a bad day is the question we help teams answer, we're around.
References
- How effective is multifactor authentication at deterring cyberattacks? — Meyer et al., Microsoft, arXiv:2305.00945
- The State of Ransomware 2026 — Sophos
- 2025 IC3 Annual Report — FBI Internet Crime Complaint Center
- CIS Critical Security Controls Implementation Group 1 — Center for Internet Security
- Why Untested Backups Fail — Panke
