When people talk about cybersecurity, the popular imagination often pictures sophisticated attacks carried out by experts. In practice, the vast majority of incidents we observe stem from simple oversights, largely avoidable with a minimum of organizational rigor.

Access management tops the list of these oversights: former employees' accounts never deactivated, passwords shared among several people, absence of multi-factor authentication on sensitive systems. These flaws require no particular technical skill to exploit.

Second commonly overlooked point: backups. Many organizations back up their data without ever testing actual restoration. A backup that has never been tested through restoration is, in practice, only a backup hypothesis — not a guarantee.

The good news is that fixing these oversights generally doesn't require a considerable budget: an audit of existing access, a planned restoration test, a clear password management policy. These are concrete actions, quick to implement, that significantly reduce risk even before considering heavier security investments.