Thinking "We are too small to be a target" is already the first mistake.
And even if you think you are protected what would you do when your anti-virus & firewall fail and operations get stuck or data starts to leak?
- Your incident response plan is just a paper?
- Your decision-making seems more like panic-making?
- No competent employees to respond?
- Communications drown in chaos?
- Compliance is successfully overlooked?