Home › Blog › Cybersecurity
CybersecurityCybersecurity for SMEs in Colombia: 8 measures you can apply this week
Two-step verification, passwords, backups and more: 8 simple measures to protect your company and comply with Colombia's Law 1581 without a large budget.

Many small and medium-sized businesses think that cyberattacks are a problem for large corporations. The reality is the opposite: small and medium-sized businesses are an attractive target precisely because they often have less protection. A repeated password, a well-crafted fake email, or an outdated computer can be enough to lose information, money, or the trust of your customers.
The good news: most risks can be reduced with simple measures that do not require a large budget. Here are 8 that you can apply this week.
Why cybersecurity matters in a small business
- Your information is valuable: customer databases, quotes, bank data, and conversations.
- An incident is costly: days without operating, payments to criminals, lost customers, and time to recover.
- You have legal obligations: in Colombia, Colombia's Law 1581 of 2012 requires protecting the personal data you handle. If you collect customer data, you must take care of it and have a data processing policy.
8 measures you can apply this week
1. Enable two-step verification everywhere
Email, WhatsApp Business, social media, banking, and your company's panels. With two-step verification, in addition to the password, a code that changes every 30 seconds is requested (for example, with Google Authenticator). Even if someone steals your password, they will not be able to enter.
It is the measure with the best effort-benefit ratio: it takes 5 minutes per account.
2. Use a password manager
A different and long password for each service, stored in a password manager (such as Bitwarden or 1Password). Never share passwords via WhatsApp or store them in a spreadsheet.
3. One account per person, with just the right permissions
Each team member should have their own user account, with access only to what they need for their work. This way, if someone leaves the company, you deactivate their account and that's it; and you always know who did what.
4. Learn to recognize phishing
Most attacks start with a fake message: a "bank" asking to update data, an "invoice" with an attached file or an urgent link. Warning signs:
- Urgency or threats ("your account will be blocked today").
- Senders or links that do not match the real company.
- Requests for passwords, codes, or unexpected payments.
In case of doubt, do not click: enter the official page directly or call the entity.
5. Keep everything updated
Operating system, browser, website plugins, and applications. Many updates fix security flaws that attackers already know. Enable automatic updates whenever possible.
6. Make backups (and test them)
Follow the 3-2-1 rule: three copies of your information, in two different locations, one of them outside your office or in the cloud. And most importantly: test that you can restore them. A backup that has never been tested is not a reliable backup. If the backup contains customer data, encrypt it with a password.
7. Protect your website and automations
- Always use HTTPS (the lock in the browser).
- Protect forms against spam and bots.
- Store the keys and tokens of your integrations encrypted on the server, never in the code or in the browser.
- Monitor that your systems are working: if an automation stops or a connection fails, you need to know immediately. If you use automations, check our guide to processes you can automate with n8n, where we explain how to monitor them.
8. Have a plan for when something happens
Write on a page what to do in case of an incident:
- Who to notify first.
- How to change critical passwords and close open sessions.
- Where the backups are and how to restore them.
- How to inform customers and, if applicable, the Superintendence of Industry and Commerce.
Having it written down beforehand avoids hasty decisions when there is more pressure.
A quick list to review today
- ☐ Two-step verification in email, WhatsApp Business, and banking.
- ☐ Password manager for the team.
- ☐ Individual users and no shared accounts.
- ☐ Automatic updates enabled.
- ☐ Recent and tested backup.
- ☐ Data processing policy published on your website.
How we apply it at VALNET IA
The systems we build include these measures from the design: users with roles and permissions, two-step verification with Google Authenticator, encrypted passwords, blocking after failed attempts, encrypted backups, and alerts when something fails. Security should not be an extra: it should be included.
In summary
You don't need a large budget to protect your business. With two-step verification, well-managed passwords, individual accounts, updates, backups, and a response plan, you reduce most risks.
Do you want to know how protected your business is? Contact us and we will do an initial review at no cost. Also, get to know who we are.



