An IT incident often starts with a detail: a reused password, a postponed update, an attachment opened too quickly. The cybersecurity of an SME or a public administration therefore does not rest first on costly equipment. It rests on habits. Here are ten of them, accepted by all specialists, which you can start on without delay.
Protecting access
1. Long, unique passwords. A phrase of several words is easier to remember and holds up better than a short word. A password is used for one service only. A password manager avoids writing them in a notebook or in a file.
2. Two-factor authentication. In addition to the password, the service asks for a code displayed on the phone or a physical key. Enable it first on email, online banking and administration accounts.
3. Access rights kept to what is needed. Everyone has access to what they need in order to work, and no more. Administrator accounts remain few, named and reserved for technical tasks.
Keeping equipment up to date
4. Updates, without postponing them. They fix known vulnerabilities. This applies to computers, phones and software, but also to the router and networked printers. A simple inventory of your equipment lets you know what is up to date and what no longer is.
5. Rules for personal devices. A personal phone or computer used for work carries the organisation's data. Set clear rules: screen lock, updates, separation of accounts, immediate reporting in the event of loss or theft.
Preparing for failure and attack
6. Backups, and tested backups. Keep several copies of your important data, including one off your premises and one disconnected from the network. A backup that nobody has ever tried to restore remains a hypothesis: carry out the exercise at regular intervals.
7. A reflex in the event of an incident. Everyone must know whom to alert, on which number, and what to do in the meantime: unplug the workstation from the network, delete nothing, note down what happened. One page displayed in the offices is enough.
Training and organising teams
8. Learning to recognise phishing. A phishing message imitates a trusted contact in order to obtain a password, a payment or the opening of a file. A few signs should raise the alarm.
- Unusual urgency, or a threat to block an account.
- A sender address close to the usual address, but different.
- A request for a password, a code or a payment.
- An attachment or a link you were not expecting.
If in doubt, check through another channel: call the person on a number you already know.
9. Preparing for a staff member's departure. An account left active after a departure is an open door. Keep a checklist.
- Disable the accounts and remove access on the day of departure.
- Recover equipment, badges and keys.
- Change the passwords of shared accounts.
- Transfer the files and the work mailbox to a manager.
10. Appointing a person in charge and talking about it regularly. Security needs a name: a person who keeps the inventory, tracks updates and receives reports. A short, regular reminder to teams is better than a long training session forgotten the following month.
Where to start this week
Ten measures at once is a lot. Three of them protect the essentials straight away.
- Enable two-factor authentication on the email of senior management and the finance departments.
- Check that a recent backup exists, and try to restore a file.
- Draw up the list of active accounts, then close those of people who have left.
A backup that nobody has ever tried to restore remains a hypothesis.
These measures reduce the risks. They do not remove them: no organisation is safe from an incident. That is why measures 6 and 7 matter as much as the others. If your organisation processes personal data, our article on Law 29-2019 sets out the Congolese framework.
When to seek support
These habits do not replace an outside view. To find out where you stand, MOKILIX AUDIT IT examines infrastructure, network, security, applications and compliance in 2 weeks. You receive a report, a map of your information system, a risk matrix and a prioritised action plan over 12 months. The entry price is stated as from 2,500,000 FCFA excl. VAT.
For the most exposed organisations, MOKILIX SHIELD brings together firewall, workstation protection, continuous monitoring, business continuity plan and team awareness, from 18,000,000 FCFA excl. VAT, over 6 to 10 weeks. The precise costing is drawn up after scoping, which is priced according to the analysis of your need.


