Let me ask you something: If your business lost access to its email, files, customer records, and accounting systems tomorrow, how long could you keep operating?
Missouri businesses reported 516 cybercrimes and $47.6 million in losses in 2025, according to reporting based on FBI Internet Crime Complaint Center data. That is not an abstract national problem. That is money leaving businesses in your state.
And here’s the uncomfortable part: many small businesses around St. Louis are still relying on untested backups, password-only email, and the hope that criminals will choose someone else.
It makes sense. You are busy serving customers, managing employees, and keeping cash flow moving. Cybersecurity can feel like something to handle later.
But Cybersecurity Awareness Month is a good reminder that “later” is often the most expensive time to prepare.
If you are looking for St. Louis IT support for small business, start with these five steps this week.
First, understand what the Missouri loss number really means
The FBI’s 2025 IC3 Annual Report recorded more than 1 million cybercrime complaints nationwide and approximately $20.9 billion in reported losses.
The Missouri business figure is a warning, but it is not a complete measurement of the damage. Many organizations do not report incidents because they feel embarrassed, do not know where to report, or are still trying to determine what happened.
So the real total may be higher.
The FBI also reported more than 3,600 ransomware complaints nationally in 2025, with reported ransomware losses exceeding $32 million. Those figures generally do not include every hour of downtime, lost wages, recovery work, lost customers, or reputational damage.
And here’s where it gets scary: ransomware is no longer just an encryption problem.
It is an extortion problem.
Attackers may steal your data before encrypting it. Then they can threaten to publish customer information, employee records, financial documents, or proprietary files even if your backups work perfectly.
Backups matter. They are not enough by themselves.
Step 1: Turn on MFA for business email and critical accounts
Start with email.
A stolen email password can give an attacker access to customer conversations, invoices, password resets, payment requests, and sensitive attachments. From there, a criminal may impersonate you or watch quietly until the right opportunity appears.
Multi-factor authentication, or MFA, adds another verification step after your password. Think of it as adding a second lock to your office door.
According to the SerenIT Small Business IT Benchmarks Report 2026, roughly 57% of small businesses still lack MFA on business email. That means more than half may be leaving one of their most important entry points protected by only a password.
This week, enable MFA for:
- Microsoft 365 or Google Workspace email
- Banking and payment accounts
- Payroll and accounting systems
- Remote access and VPN accounts
- Cloud storage and backup platforms
- Administrator accounts
Use an authenticator app or hardware security key where possible. Text-message MFA is better than no MFA, but stronger methods provide better protection against account takeover.
If your team uses shared passwords or old administrator accounts, this is also the time to remove them.
Step 2: Test whether your backups can actually restore
When was the last time you restored a real file from your business backup?
Not checked a dashboard. Not received a “backup completed” notification. Actually restored a file, opened it, and confirmed it was usable.
Only about 29% of small businesses have tested backup restoration within the last 12 months, according to the same SerenIT report.
That is a serious readiness gap.
A backup that cannot be restored is like a spare key that has never been tested. It may look useful in a drawer, but you do not want to find out during an emergency that it does not fit the lock.

This week, restore:
- One important customer or financial file
- One shared folder
- One Microsoft 365 mailbox or folder
- One application database or virtual machine, if possible
Then ask simple questions:
- Does the file open normally?
- Is it the correct version?
- Are permissions still intact?
- How long did recovery take?
- Could your team work if the main network were unavailable?
For a step-by-step process, read our guide to backup testing for St. Louis small businesses.
Your goal is not just to have backups. Your goal is to know that you can recover.
Step 3: Separate and protect your backups from ransomware
Here’s the problem: ransomware can search for connected backup systems just like it searches for business files.
If attackers compromise an administrator account, they may be able to delete, encrypt, or alter backup data before demanding payment. That is why your recovery plan needs protected copies that attackers cannot easily reach.
Review whether your business follows a practical 3-2-1-1-0 backup strategy:
- Keep at least three copies of important data.
- Use at least two different storage types.
- Keep one copy off-site.
- Keep one copy offline or immutable.
- Maintain zero unverified backups.
An immutable backup cannot be changed or deleted during its protected retention period. An offline backup is disconnected from the network, making it much harder for an attacker to reach.
You should also check whether your backups include more than shared files. What about email, calendars, contacts, permissions, accounting data, line-of-business applications, and cloud-stored records?
Our data recovery services can help you evaluate what is recoverable and where gaps may exist. You can also review our ransomware protection guide for practical preparation steps.
Step 4: Close the easy doors
You do not need to fix every technology issue this week. Start with the openings criminals commonly exploit.
Ask your IT provider or internal administrator to review:
- Unpatched operating systems and applications
- Unsupported computers and network equipment
- Unused employee and administrator accounts
- Remote desktop access exposed to the internet
- Weak or reused passwords
- Missing endpoint protection
- Flat networks with no separation between systems
- Personal devices accessing sensitive business data
Network segmentation is especially valuable. It creates barriers between parts of your environment so one compromised computer does not automatically provide access to everything else.
A professional network design and infrastructure review can identify weak points and improve reliability at the same time.
This is where local support matters. Your needs may look different if you operate in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, or the Metro East.
The right Missouri managed IT services partner should understand your people, your applications, your office layout, and your tolerance for downtime, not just sell you a generic checklist.
Step 5: Give your team a simple response plan
Most people do not click a dangerous link on purpose.
They see an invoice from a familiar vendor. They receive a message that appears to come from the owner. They get an urgent request to change payment instructions. They open an attachment while trying to help a customer.
It is not about blame. It is about awareness.
This week, give your team three clear rules:
- Verify payment or wire-transfer changes by phone using a trusted number.
- Do not approve unexpected MFA prompts or share verification codes.
- Report suspicious messages immediately, even if someone already clicked.
Then write down what happens if an incident occurs:
- Who should employees contact first?
- Who can disconnect a device from the network?
- Who contacts your IT provider?
- Who communicates with customers or vendors?
- Who reports the event to law enforcement and insurers?
- Where are emergency credentials and recovery instructions stored?
Speed matters. The earlier you isolate a compromised account or device, the more likely you are to limit the damage.
What local businesses should look for in an IT partner
Whether you need St. Louis cybersecurity, St. Charles County IT support, Chesterfield IT services, Clayton IT consulting, O’Fallon IT support, or Metro East IT support, look for a partner that combines prevention with recovery.
That should include:
- Proactive patching and update management
- Email security and MFA enforcement
- Endpoint monitoring and threat detection
- Backup management and restoration testing
- Secure cloud configuration
- Network design and segmentation
- Employee security awareness
- Incident response planning
- 24/7 IT support for emergencies
Platinum Web Services helps small businesses build practical cyber security solutions for small business without turning technology into another full-time job. We provide managed IT services, cybersecurity solutions, cloud services, and data protection planning for businesses across the St. Louis region and Missouri.
The goal is simple: reduce risk, protect your information, and help you keep working when something goes wrong.
Start this week, not after an incident
Missouri’s reported cybercrime losses are a reminder that small businesses are not invisible to attackers. But you do not need to solve everything at once.
Start with MFA. Test one backup. Protect your backup system. Close one easy opening. Teach your team how to report a suspicious request.
Five practical steps can create meaningful progress.
Platinum Web Services provides 24/7 IT support for businesses that need dependable technology and stronger ransomware protection. You can reach us at support@platinumwebservices.net.
Our office is located at 7827 Town Square Ave, 104-1184, O’Fallon, MO 63368. Business hours: 24/7.
Your business may have locked doors, alarms, and cameras. This week, make sure your digital doors are protected too.


0 Comments