
The attack that takes the money is not a virus
A fake invoice arrives from an address that looks like your supplier's. It refers to a real order, quotes a real amount, and carries one change: new bank details, with a line explaining that the old account is being audited. The accounts team pays it. Nothing was infected, no alarm went off anywhere, and the money is gone before the real supplier calls to ask about the payment. This is business email compromise, and it is the attack that empties an account rather than the one that locks a laptop.
It defeats antivirus because there is nothing for antivirus to find. No attachment, no link, no malware: a person was persuaded by a convincing document. Often the criminal has read months of the supplier's real correspondence first, because it was the supplier's mailbox that was broken into, not yours. That is why the email matches the order, the tone and the timing so precisely.
What stops it is not another scanner. It is a written rule that a change of bank details is never accepted by email, and is confirmed by calling a number you already had on file rather than one printed on the new invoice. The rule costs nothing and outlives every tool you replace. And if a supplier sends new bank details and presses for speed, that is the moment to pick up the phone, not the moment to pay.
- 01A mailbox is broken intoUsually the supplier's, not yours. The criminal reads real orders and learns the tone.
- 02An invoice arrives on timeReal order, real amount, the right names, sent in the week one was expected.
- 03Only the bank details changedWith a reason attached: an audit, a new branch, a frozen account.
- 04Accounts pays itNothing looked wrong, because nothing was wrong except one field.
- 05The real supplier callsWeeks later, asking about an invoice you already paid to somebody else.
Ransomware does not decide the outcome, your restore does
Ransomware encrypts your files and asks to be paid to unlock them. Everything written about preventing it is worth doing, and none of it changes the one fact that decides how the week ends: whether you can restore. A company that restores has a bad two days. A company that cannot restore is negotiating with criminals for its own files.
The trap is that nearly every business already has backups, and having backups is not the same as being able to restore from them. The backup report lands every morning in a mailbox nobody opens, so a job that has been failing for months still sits in the list looking like it ran. A backup drive left permanently connected to the server is encrypted along with the server. A backup nobody has ever restored from is a hope rather than a plan. The old habit of keeping three copies, on two kinds of storage, with one of them off the site, exists because each of those three failures happens on its own.
So the question is not whether you have backups. It is when somebody last restored a real file from them, and how long it took. If nobody can answer that with a date, the honest answer is that you do not know what you have.
A firewall guards a door these attacks do not use
A firewall sits at the edge of your network and decides what crosses it, and it earns its place in every office. It does not open the invoice in an employee's inbox to see whether the supplier really sent it. It does not know that whoever signed in with the correct password is not the person the password belongs to. Both attacks above walk through the front door holding a valid ticket.
This is why asking which firewall is best for a small business is the wrong first question, even though it is the one most often asked. The right first question is who can sign in to your company email, and with what. An attacker holding a stolen password and meeting nothing in the way needs no exploit and no malware; they simply log in. Multi-factor authentication closes that path. It is already sitting in Microsoft 365 and Google Workspace waiting to be switched on, it takes hours rather than a project, and it only works if you apply it to every account rather than the owner's alone.
The firewall's real job starts after that: separating the network so a compromised laptop cannot reach the server, the cameras and the accounting PC as though they were all one room. That is a networking decision as much as a security one, and it is far cheaper to make while the office is being cabled than afterwards.
The order to close them, cheapest and most effective first
Nobody does the whole list at once. Taken in this order, each step removes more risk, and costs less effort, than the one that follows it, which is the only sequence a busy company ever finishes.
Notice what is not at the top: no purchase. The first three steps are a setting, a rule and a test. Buying tools first is how a company ends up paying every month for a product that guards a door nobody was using.
- 01Turn on multi-factor authenticationEvery account, not the owner's alone. A stolen password stops being enough by itself.
- 02Write the bank-details ruleNever accepted by email. Confirmed by phone, on a number already on file.
- 03Restore something todayPick a real file, restore it, time it. Now you know what you actually have.
- 04Protect the machinesEndpoint protection on every laptop and server, monitored rather than installed and forgotten.
- 05Filter the mail, then teach the teamThe filter removes most of it. People catch what no filter can judge.
- 06Separate the networkA compromised laptop should not be able to reach the server and the cameras.
What the UAE data protection law expects of you
Every business holds personal data: staff files, customer contacts, copies of passports and visas. The UAE's federal personal data protection law, Federal Decree-Law No. 45 of 2021, governs how that data is handled, requires it to be protected with appropriate measures, and requires a breach to be reported to the regulator. What applies to you in detail depends on your activity, and the place to read it is the current official text rather than an article that will outlive the detail.
The practical point is that this does not add a separate project. The steps above are the same ones a regulator expects to see: access limited to the people who need it, a record of what you hold, backups you can restore from, and the ability to say what happened if something goes wrong. A company that can restore a file and name everyone holding administrator access is most of the way there. A company that can do neither has a compliance problem it will discover at the worst possible moment.
Where to start this week
Three checks, none of which needs a purchase or a consultant. First, write down everyone who can sign in to company email and confirm multi-factor authentication is on for each of them, including the accounts that belong to nobody in particular: the enquiries mailbox, the accounts mailbox, the shared inbox no single person owns. Second, ask whoever handles payments what they would do if a supplier emailed new bank details today, and write the answer down as a rule if there is not one already. Third, pick a file that matters, restore it from your backup, and note how long it took.
What those three turn up is your real security position, and it is usually not the one described on the invoice from your IT provider. If you would rather somebody went through it with you, that is what a cyber security assessment is: what is protecting you today, what is not, and the order to fix it in, written down so you can hand it to whoever does the work.