كيف تُخترق الشركات الصغيرة فعلاً؟How are SMEs actually breached?

الإحصاءات متسقة: التصيّد الإلكتروني، كلمات مرور ضعيفة أو مُعاد استخدامها، أنظمة غير محدّثة، وموظفون لديهم صلاحيات أوسع مما يحتاجون. لا يوجد «هاكر عبقري» في معظم الحالات — بل باب مفتوح.The pattern is consistent: phishing, weak or reused passwords, unpatched systems, and employees with broader access than they need. There is no "brilliant hacker" in most cases — just an open door.

الضوابط العشرة الأساسيةThe ten essential controls

١) تحقق متعدد العوامل للبريد والحسابات الحساسة. ٢) مدير كلمات مرور للفريق. ٣) تحديثات تلقائية للأنظمة والبرامج. ٤) نسخ احتياطي خارجي مُختبر شهرياً. ٥) مضاد فيروسات محدّث ومركزي. ٦) جدار حماية مُفعّل ومضبوط. ٧) صلاحيات بأقل قدر لازم. ٨) تدريب توعوي سنوي على التصيّد. ٩) سياسة استخدام مقبولة موقّعة. ١٠) خطة استجابة للحوادث ولو بسيطة.1) Multi-factor authentication for email and sensitive accounts. 2) A team password manager. 3) Automatic system and software updates. 4) Offsite backup tested monthly. 5) Updated, centrally managed antivirus. 6) An enabled and configured firewall. 7) Least-privilege access. 8) Annual phishing awareness training. 9) A signed acceptable-use policy. 10) An incident response plan, even a simple one.

ما تكلفة هذه الضوابط؟What do these controls cost?

معظمها منخفض التكلفة: التحقق متعدد العوامل ومدير كلمات المرور باشتراك شهري بسيط لكل مستخدم، والتحديثات والنسخ الاحتياطي أدوات مدمجة أو رخيصة، والتدريب التوعوي يمكن أن يكون داخلياً. الاستثمار الأكبر هو الانضباط لا المال.Most are low cost: MFA and a password manager are a small monthly subscription per user, updates and backup use built-in or inexpensive tools, and awareness training can be delivered internally. The bigger investment is discipline, not money.

الأخطاء التي تُلغي كل شيءMistakes that undo everything

نسخ احتياطي موجود لكن لم يُجرَّب استرجاعه، حسابات مشتركة بين عدة موظفين، صلاحيات مدير عام للجميع، ومضاد فيروسات منتهي الترخيص على نصف الأجهزة. هذه الأخطاء تعطي إحساساً زائفاً بالأمان.A backup that exists but has never been test-restored, shared accounts across employees, administrator rights for everyone, and expired antivirus on half the devices. These create a false sense of security.

إذا حدث اختراق — ماذا تفعل؟If a breach happens — what do you do?

افصل الأجهزة المصابة عن الشبكة، غيّر كلمات المرور الحساسة من جهاز نظيف، لا تحذف الأدلة، بلّغ الجهات المختصة عند وجود بيانات شخصية (وفق نظام حماية البيانات PDPL)، وأبلغ العملاء المتأثرين بشفافية. التصرف السريع يقلّل الضرر أكثر من أي أداة.Isolate affected devices from the network, change sensitive passwords from a clean device, do not delete evidence, notify the competent authority where personal data is involved (under the PDPL), and inform affected customers transparently. Fast action reduces damage more than any tool.

متى تحتاج دعماً متخصصاً؟When do you need specialist help?

إذا كنت تتعامل مع بيانات عملاء حساسة، أو تعمل مع جهة حكومية، أو تحتاج الامتثال لضوابط NCA، أو تعرّضت لحادث سابق. في هذه الحالات، مراجعة أمنية من مختص أوفر من تكلفة حادث واحد.If you handle sensitive customer data, work with a government entity, need NCA compliance, or have suffered a prior incident. In these cases, a specialist security review costs less than a single incident.