5 Security Holes We Find in Almost Every SMB Network
Ammon Gleason
Director of AI & Engineering
June 19, 2026
4 min read
5 Security Holes We Find in Almost Every SMB Network
When we run a security assessment on a new client's network, we already have a rough idea what we're going to find before we even start. Not because every business is the same, but because the same five gaps show up over and over, regardless of industry, size, or how "careful" the owner thinks they've been.
None of these are exotic. They're not zero-day vulnerabilities or nation-state attack techniques. They're everyday oversights that pile up while people are busy running their business, and they're exactly what an attacker looks for first.
The good news is you don't need us to tell you whether you have them. You can check your own network for these in about a minute with our free security scan. But let me walk you through what we typically find, so you know what you're looking at.
1. No MFA on Email or Remote Access
This is the single most common gap, and it's the one that causes the most damage. If an employee's email password gets phished or shows up in a data breach dump somewhere, and there's no multi-factor authentication behind it, that's the whole ballgame. The attacker logs in like they're supposed to be there.
From inside a mailbox, an attacker can reset other passwords, dig through old messages for banking details, and send invoices or wire instructions to your customers that look completely legitimate because they're coming from your real account.
MFA does not stop every attack, but it stops the easy ones, and the easy ones are what most small businesses actually face.
2. Unpatched or End-of-Life Software Still Running
We routinely find servers, workstations, or line-of-business applications running versions that stopped receiving security updates months or years ago. Sometimes it's an old version of Windows Server nobody wanted to touch because "it works." Sometimes it's a piece of industry software the vendor abandoned.
Once software stops getting patched, every known vulnerability in it stays open forever. Attackers don't need to discover anything new. They just run tools that check for known, published weaknesses, and end-of-life systems light up like a target.
3. A Flat Network With No Segmentation
Most small business networks are built the same way: everything plugs into the same switch, gets the same IP range, and can talk to everything else. The guest Wi-Fi, the office printer, a security camera, and the server holding customer records are all sitting on one flat network with nothing separating them.
That matters because a lot of breaches don't start with the server. They start with something small and overlooked, like a smart camera or an old printer with a default password, that has known vulnerabilities of its own. On a flat network, once an attacker is in that printer, they can see everything else too. Segmentation just means putting walls between systems that don't need to talk to each other, so a compromise in one corner doesn't hand over the whole building.
4. Weak or Shared Admin Passwords
We still find shared logins constantly. One admin password that three or four people know. A password that hasn't changed since the system was set up years ago. Passwords reused across multiple accounts because it's easier to remember one.
The problem with shared credentials isn't just that they're easier to guess. It's that when something goes wrong, you have no way of knowing who did what. And if that password leaked once, anywhere, it's leaked everywhere it's reused. Attackers buy and trade lists of exposed username and password combinations, then simply try them against other logins. It works far more often than it should.
5. Backups That Have Never Been Tested for Restore
This is the one that hurts the most when it's discovered too late. A business has backups running every night, the software reports success, and everyone assumes they're covered. Then ransomware hits, and when it's time to restore, the backup is corrupted, incomplete, or was never actually capturing the right data in the first place.
A backup you haven't tested isn't a backup. It's a hope. The only way to know it will work when you need it is to actually restore from it and confirm the data comes back clean.
Check Your Own Network Right Now
You don't have to guess whether any of these apply to you. Run the free scan and it'll check your network for exactly this kind of exposure in about a minute, no obligation and no sales pitch required to get the results.
Bottom Line
None of these five gaps are hard to fix once you know they're there. The problem is almost never that business owners don't care about security. It's that nobody's had the time to look, or the results have never been put in front of them plainly.
That's what we do at G8. If your scan turns something up, or you'd just rather have someone walk the network with you, talk to us and we'll help you close the gaps before someone else finds them first.

Ammon Gleason
Director of AI & Engineering
Graduate student in Artificial Intelligence at the University of Utah, building on a BS in Computer Science with an emphasis in Machine Learning. 5+ years of hands-on IT experience and 4+ years of programming and ML engineering — leading G8's AI automation, custom software, and applied machine-learning practice.
Talk to a human about this.
We do the work the article describes. Two ways in: