Cybersecurity for small businesses in Mallorca
Most incidents at small companies are not targeted attacks: they are doors left open. A router still on its factory password, a guest WiFi that reaches the admin network, a user account still active two years after the person left.

What is usually wrong in a small network
In a small business the network grows without a plan: things get plugged in when they are needed. The result is usually a flat network, where a visitor laptop, the security camera and the machine with the accounts all sit in the same place and can see each other. If something gets in, it gets into everything.
Separate it, control it, write it down
No single product solves this: it is a matter of layers. We split the network into zones that cannot see each other, control who gets in and from where, and document how it is configured, so security does not depend on somebody remembering.
What it includes
- Review of the current router and firewall configuration
- VLAN segmentation: guests, cameras, voice and data kept apart
- Firewall rules written for your case, not the factory defaults
- VPN for outside access, instead of open ports
- Review of users, permissions and access that is no longer needed
- Factory credentials changed on every network device
- Firmware updates on network equipment
- A report with what we found and the order in which to fix it
The three layers we put in place
Firewall and access
We block unauthorised access and filter traffic before it reaches the network. User management and VPN so that remote work does not open a hole.
- Rules per user and per service
- SSL or IPsec VPN instead of open ports
VLAN segmentation
Stops a compromised device from reaching everything else. We isolate guests, IoT devices, cameras and critical data on separate networks.
- Voice and data traffic separated
- Isolated guest WiFi network
Monitoring and alerts
Network equipment logs what happens and raises an alert when something looks off: a dropped link, repeated login attempts or a new device.
- Event logging and audit trail
- Email notification when an alert fires
How we approach it
- 1
Assessment
We review how the network is built right now: what equipment is there, how it is configured and what can see what.
- 2
Prioritised report
You get what we found, ordered by real risk rather than as a list of everything theoretically improvable. What actually exposes the business comes first.
- 3
Phased rollout
We apply the changes in the agreed order, and outside working hours when something has to go down. Segmenting a live network is done in stages.
- 4
Documentation and review
You are left with a written record of how everything is configured and what should be reviewed periodically.
Rather talk it through?
If it is quicker to explain over the phone than to write it down, give us a call. You get a technician directly, not a salesperson who passes it on.
Frequently asked questions
Is this not something only large companies need?
The opposite: large companies already have someone on it. Automated attacks do not pick targets by size, they look for open doors, and an unmaintained small network usually has more of them. The relative impact is also bigger: two days down hurts a small business far more.
Does everything have to be replaced?
Not necessarily. A good share of the improvements are configuration and cost no hardware. If a device cannot do what is needed, for instance a consumer router that cannot handle VLANs, we tell you why and what replacing it would cost.
Which brands do you work with?
We configure Ubiquiti, Cisco and Mikrotik equipment, which is what we most often find in small businesses and hotels on the island. The choice depends on what you already have and what you need, not on a particular brand.
Do you offer permanent network monitoring?
Network equipment can log events and send alerts continuously, and we leave that configured. Any level of monitoring and response contracted on top of that is agreed in writing with each client, because not every business needs the same thing or wants to pay for the same thing.
Are backups not enough on their own?
Backups are essential, but they are what saves you afterwards. They do not stop the business being halted, and they do not stop data being leaked. The two go together: reduce the chance of it happening, and be able to roll back if it does.
Shall we start by looking at your network?
The security assessment is a review of the current configuration: what is exposed, what can see what, and what can be fixed without buying anything. You get it in writing and prioritised.
Review my company's securityContact Us
Tell us what your business needs. We reply with an assessment and a no-obligation quote.
Send us a message
Fill in the form and we'll get back to you within 24 hours.