Back to BlogBusiness Growth

Cybersecurity Checklist for Ethiopian Businesses: What You Need in Place

17 April 2026

Get a Free Quote

Tell us what you need — we'll reply within one business day.

Cybersecurity Checklist for Ethiopian Businesses: What You Need in Place

Most Ethiopian businesses discover their cybersecurity is inadequate after an incident, not before. A phishing email reaches a staff member, a password gets stolen, ransomware encrypts the server, or a client phones to ask about a suspicious payment request that came from your email address.

By that point, the cost is already real: lost data, downtime, damaged client relationships, and recovery work that nobody planned for.

This checklist covers the practical controls that stop the most common attacks. None of them require an enterprise IT budget. All of them are achievable for Ethiopian SMEs.

Email security

Email is the entry point for the majority of cyberattacks. These controls significantly reduce what reaches your staff:

  • SPF record configured — tells receiving mail servers which servers are authorised to send email from your domain. Reduces spoofing.
  • DKIM configured — cryptographically signs outgoing email so recipients can verify it came from you. Reduces email fraud.
  • DMARC policy set — tells receiving servers what to do with email that fails SPF or DKIM. Set to at least "quarantine".
  • Anti-phishing filter — filters suspicious emails before they reach inboxes. Available in Microsoft 365 Defender and Google Workspace.
  • Malicious attachment scanning — scans attachments for malware before delivery.
  • Staff training on phishing — once a year at minimum. Show staff examples of phishing emails that look like Ethio Telecom, their bank, or a colleague.

Endpoint protection

Every device your staff use is a potential entry point. Basic antivirus is not enough:

  • EDR (Endpoint Detection and Response) on all devices — monitors device behaviour, not just known malware signatures. Detects unusual activity and can isolate a compromised device.
  • Operating system patches up to date — unpatched Windows or macOS is the easiest way into a network. Set automatic updates.
  • Application patches up to date — especially web browsers, Microsoft Office, and PDF readers, which are the most-exploited applications.
  • Full disk encryption — on laptops especially. If a device is stolen, encrypted data is unreadable.
  • Screen lock enabled — 5 minutes of inactivity maximum. Basic but often not enforced.
  • USB restriction — consider blocking unmanaged USB storage on company devices. USB drives are a common malware vector.

Access controls

Most security incidents involve an attacker using stolen or weak credentials. These controls make credential theft much less useful:

  • Multi-factor authentication (MFA) on all business accounts — email, banking, cloud systems, remote access. MFA stops most account compromise attacks even if a password is stolen.
  • Unique passwords for each business system — password reuse means one stolen password compromises everything. Use a password manager.
  • Admin accounts separate from daily-use accounts — IT administrators should have a standard account for daily use and a separate admin account for administrative tasks.
  • Regular access review — remove access for staff who have left or changed roles. Check quarterly.
  • No shared accounts — every person should have their own login. Shared accounts have no accountability.

Backups

Ransomware only works if you have no backup. Backups also protect against hardware failure, accidental deletion, and human error:

  • Automated daily backups — manual backups do not happen reliably. Automate them.
  • Backups stored offsite or in the cloud — a backup on the same server as the data it is backing up is not a backup. It gets encrypted by ransomware along with everything else.
  • Backup tested — a backup that has never been tested may not restore. Test a restore at least every three months.
  • 3-2-1 rule — 3 copies of data, on 2 different media, with 1 stored offsite. This is the minimum standard.
  • Backup access restricted — if ransomware can reach the backup system, it will encrypt the backups too. Restrict backup access to specific admin accounts.

Network security

  • Firewall configured and reviewed — most businesses have a firewall but have never reviewed what it is actually blocking.
  • Guest WiFi separate from business network — visitors and personal devices should not have access to your business servers and file shares.
  • Remote access via VPN — staff accessing business systems remotely should do so through a VPN, not by exposing servers directly to the internet.
  • Unused ports closed — if a service is not needed, close the port. Exposed RDP (port 3389) is one of the most common entry points for ransomware attacks on business servers.
  • Default passwords changed — routers, switches, CCTV cameras, and other network devices often ship with default admin passwords. Change them.

When things go wrong — having an incident response plan

Most Ethiopian businesses have no incident response plan. When a cyberattack happens, the response is improvised, which makes it slower and more expensive.

A basic incident response plan answers these questions:

  • Who do you call first? (An IT contact who can help, not a general support line)
  • What systems do you isolate immediately? (Infected devices should be taken off the network before they spread)
  • Who has authority to make decisions? (Do not let one technical person make decisions alone during an incident)
  • How do you communicate with clients if their data is involved?
  • What are your backup restoration procedures?

Write this down. One page is enough for a small business.

What to do in the first hour of an active incident

  • Disconnect the affected device from the network — do not power it off, as this can destroy forensic evidence.
  • Reset passwords for the affected user and any account they touched, starting with email.
  • Notify your bank if any payment information was exposed.
  • Document everything — times, screenshots, suspicious messages — before memory fades.
  • Engage a qualified responder; do not attempt to "clean" the system yourself.

Where to start if your current security is weak

If your business has none of the above in place, start here:

1. Enable MFA on email and banking accounts — this week 2. Configure SPF, DKIM, and DMARC on your email domain 3. Deploy EDR on all staff devices 4. Set up automated cloud backup for your critical data 5. Book a security audit to understand what else you need

We will assess your current setup against this checklist, tell you where your biggest risks are, and give you a clear remediation plan.

Frequently asked questions

We are a small business of 10 people. Do we need all of this?

You need the basics: MFA on all accounts, email authentication (SPF/DKIM/DMARC), decent endpoint protection, and a tested backup. A small business is a more attractive target than many people think — attackers know small businesses have weaker defences.

What does a cyberattack actually cost an Ethiopian business?

The cost varies widely. Ransomware recovery — even if you pay nothing — typically costs several days of IT time, possible data loss, and staff downtime. Business email compromise (where an attacker uses your email to redirect payments) can result in direct financial losses. Reputational damage with clients is harder to quantify but real.

We already have antivirus. Is that not enough?

Basic antivirus catches known malware. EDR detects suspicious behaviour even from new malware that antivirus has never seen. Email security stops most attacks before antivirus is ever involved. They do different jobs.

How do we know if our email authentication is set up correctly?

There are free online tools that check SPF, DKIM, and DMARC records for your domain. Send an email to your IT contact and ask them to check. If they cannot, contact us.

Ready to Upgrade Your IT Infrastructure?

Get a free consultation on cloud hosting, software, cybersecurity, networking, and data management for your Ethiopian business.

Get a free consultation

Share a few details and we'll reach out within one business day.