Most small business breaches aren’t discovered by the owner. They’re discovered by a customer who got a phishing email “from” the business, or a bank that flagged suspicious transactions, or — worst case — by ransomware announcing itself on every screen in the office Monday morning.
By the time it’s obvious, the attacker has usually been in the system for weeks or months. That gap between compromise and discovery is where the real damage happens — data exfiltration, credential harvesting, backdoor installation. The loud ransomware attack is often the last thing they do, not the first.
Knowing what to look for earlier in that timeline matters.
Performance Signs That Something’s Wrong
Computers Are Significantly Slower Than Normal
Some slowdown is normal as machines age and accumulate software. Sudden, unexplained slowdowns — especially if they affect multiple machines at once — are different. Malware, cryptomining software, and data-exfiltration tools all consume CPU and memory. If your machines are running hot and sluggish for no apparent reason, that’s worth investigating rather than ignoring.
Unusual Network Activity
If your internet seems consistently slower than usual, especially at odd hours or after business hours, that can indicate outbound traffic you didn’t authorize. Data exfiltration — an attacker copying your files to an external server — generates network traffic. So does a compromised machine being used as part of a botnet.
Most small businesses don’t have network monitoring in place, which means they’d never see this. It’s one of the concrete benefits of managed cybersecurity services — someone is watching the traffic patterns so you don’t have to.
Programs Crashing More Than Usual
Malware that’s poorly written or conflicts with existing software can cause instability. Random crashes, programs that won’t open, or a machine that reboots unexpectedly more than once or twice could be software conflicts — or could be something worse. Worth checking rather than assuming.
Account and Access Red Flags
Login Attempts You Didn’t Make
Microsoft 365, Google Workspace, and most business software send alerts for sign-ins from new locations or devices. If you’re getting those notifications and the login wasn’t you — take it seriously immediately. Change the password and enable multi-factor authentication if it wasn’t already on.
If MFA was already enabled and you received a MFA prompt you didn’t initiate, that means someone has your password and is trying to push through. Don’t approve it. Report it.
Password Resets You Didn’t Request
Getting a password reset email you didn’t ask for might just be a glitch — or it might mean someone is attempting to take over your account and triggered the process. Same with “your email was changed” notifications or “a new device was added” alerts. These are the warnings your systems are designed to send. Don’t dismiss them.
Emails Your Employees Are Getting Complaints About
If customers or contacts are telling you they received strange emails from your address — phishing messages, spam, requests to pay invoices to new accounts — your email account may be compromised. This is a serious situation. It means an attacker has access to your email and is actively using it to target your contacts.
Compromised business email is one of the most financially damaging attacks on small businesses. Business Email Compromise (BEC) scams — where attackers impersonate a business to redirect payments — cost US businesses over $2.9 billion in 2023 according to FBI IC3 data.
Financial and Operational Anomalies
Unexpected Charges or Transfers
Unauthorized transactions on a business credit card or bank account might be the first visible sign of a compromise. Attackers who get into business systems often look for saved payment credentials, connected financial accounts, or ACH information. If you see transactions you don’t recognize, that warrants checking whether it started as a digital compromise before calling it simple fraud.
New Software or Browser Extensions You Didn’t Install
Log into a computer and see a program you don’t recognize? A browser extension that appeared without being installed? That’s a sign something ran on that machine without user initiation. Legitimate software doesn’t install itself.
Antivirus Disabled or Missing
Sophisticated malware disables security software as part of its initial execution. If you check a machine and find that its antivirus is turned off — especially if no one turned it off — something may have done it deliberately. This is one of the indicators that suggests you’re past the “maybe it’s just a glitch” stage.
Ransomware: When It’s No Longer Subtle
Ransomware announces itself — files renamed with unfamiliar extensions, a message on the screen demanding payment, documents that won’t open. At this point the attacker has encrypted your data and is demanding payment to restore it.
Do not pay immediately. That doesn’t guarantee recovery and funds further attacks. Disconnect the affected machines from the network immediately to prevent spread. Call a cybersecurity professional before touching anything else. Preserve what you can document about what happened and when.
If you have clean, current backups, recovery is painful but possible. If you don’t — this is when people find out their backup hasn’t been working for six months. A proper cloud backup setup with tested restore procedures is what separates “bad week” from “potentially business-ending.”
What to Do If You Suspect a Compromise
The instinct is to keep things running and figure it out while the business operates normally. Resist that. A live compromise gets worse the longer the attacker has access.
First, disconnect the suspected machine(s) from the network — both WiFi and ethernet. This contains the problem. Do not turn the machine off; that can complicate forensic investigation.
Change passwords for critical accounts — email, banking, business software — from a device that wasn’t involved in the suspected compromise. Use a phone if your computers are suspect.
Contact IT support immediately. Not tomorrow. A cybersecurity incident response needs to start quickly to be effective.
Document everything — what you noticed, when, what machines were involved, what accounts were affected. This matters for insurance claims, regulatory notifications, and figuring out what the attacker had access to.
Why Most Businesses Don’t Catch This Earlier
The honest reason is visibility. Without monitoring tools, you’re relying on users noticing something wrong and reporting it — which they often don’t, either because they don’t recognize it as unusual or because they don’t want to be the one who “broke something.”
Professional security monitoring watches for the things users miss: unusual login patterns, anomalous network traffic, file system changes, process activity that doesn’t match normal behavior. It’s not foolproof, but it shrinks the detection window from weeks to hours or days.
A cybersecurity health check is a reasonable starting point if you’ve read this and realized you have no idea whether your business is currently compromised. It’s not about finding problems to sell you — it’s about establishing a baseline so you actually know where you stand.
If something’s already wrong, contact us directly. Don’t wait for it to get more obvious.
