Why endpoint security is the SMB battleground
Your servers are in a data centre. Your data is in cloud apps. But your endpoints — laptops, desktops, mobile phones — are everywhere: in cafes, on planes, at home networks with default router passwords. Attackers know this. The endpoint is where 70%+ of successful breaches start.
For an SMB in Kosovo, defending every endpoint with enterprise-grade controls is now achievable and affordable — if you know what to ask for. Here's the list.
1. Asset inventory — know what you have
You cannot protect devices you don't know about. An automated agent on every endpoint reports back: hostname, OS, installed software, last check-in. Anything not on the list is unmanaged — and unprotected.
If your IT provider can't produce a list of every device on your network in under 60 seconds, your inventory is broken.
2. Automated patching — within 7 days of release
Most ransomware exploits vulnerabilities that already have a patch. The patch exists — it just wasn't applied. Automated patching for OS and third-party software (browsers, PDF readers, Office plugins) within 7 days of release removes the biggest attack surface.
3. EDR — not just antivirus
Antivirus matches files against a database of known-bad signatures. EDR watches behaviour: process trees, network calls, registry changes. It catches zero-days and fileless attacks that signature-based tools miss entirely. Modern endpoint security means EDR — full stop.
4. Multi-factor authentication on every account
99% of compromised M365 accounts had no MFA enabled. Skipping MFA is the single biggest security mistake a business can make. Enable it on every account — including service accounts, including the admin account, including the CEO's personal Microsoft account.
5. Verified backups — daily, off-site, tested
Backups only count if you can restore from them. Daily automated backups to off-site (Kosovo or EU) with at least one immutable copy, plus monthly restore tests. If your provider can't show you a recent test restore log, the backup is not real.
6. DNS-level filtering
Block known-malicious domains before they load. DNS filtering catches phishing links, malware downloads, and command-and-control callbacks. It costs almost nothing and blocks threats that other layers miss.
7. Email security with phishing simulation
Email is the #1 attack vector. Multi-layered filtering (spam, phishing, malware, BEC) catches most attacks. But your last line of defence is the human — run monthly phishing simulations and train the clickers.
8. Disk encryption on every device
BitLocker on Windows, FileVault on macOS, device encryption on mobile. If a laptop is stolen, encrypted disks mean the data is safe. Unencrypted disks mean breach notification obligations and reputation damage.
9. Application allow-listing
By default, only approved software can run. This stops 80% of common malware before it executes. Maintenance overhead is real but manageable with a modern management platform.
10. USB and removable media controls
Disable USB drives by default. Air-gapped attackers still use USB. Whitelist specific devices for specific users — don't rely on policy that users can bypass.
11. Centralised logging and alerting
Every endpoint sends logs to a central platform. Automated alerts flag anomalies — a laptop logging in from two countries in two hours, a sudden spike in failed login attempts, an unknown process calling out to a suspicious IP. Without this, attacks go unnoticed for months.
12. Quarterly review with documented evidence
Once per quarter, your provider sits down with you and walks through: which items are passing, which are failing, what changed, what to fix next. With evidence — screenshots, dashboards, test logs. If they can't show evidence, the controls don't exist.
Common gaps we see in Kosovo SMBs
Most often: no MFA on a few accounts (usually a founder's), patches delayed more than 30 days, backups never tested, no DNS filtering, no centralised logging. Each gap is a 30-minute conversation. Each fix is an hour or less of work. The cost of not fixing is 10–100x higher.
How KPX delivers every item on this list
We include all 12 items in our standard managed services — not as add-ons. Datto RMM or NinjaOne for inventory and patching. SentinelOne or Datto EDR for endpoint protection. Acronis or Veeam for backups. DNSFilter for content filtering. Monthly reports with evidence. Quarterly reviews with you.
