One Monday morning, the invoicing software stops responding. Customer files are unreadable, and no one knows whether the backup works. For the head of a small business, cybersecurity suddenly takes a very concrete form: stalled orders, idle employees and a ringing phone. Looking ahead to September 2026, this is the decisive commercial test for entrepreneurs in the sector: does their offering help a business get through this situation, or does it merely add another subscription charge?
The real competition: available budget and time
Ransomware, phishing and email compromises do not affect only large corporations. Publications from ANSSI and Cybermalveillance.gouv.fr have documented small businesses’ exposure for several years. A hacked mailbox can be enough to divert a payment; a poorly secured remote connection can open a door into the IT system. It does not take a spectacular scenario to cause a loss that is hard to absorb.
Yet awareness of the risk does not automatically trigger a purchase. In an SME, the same person may manage suppliers, recruitment and IT. They must weigh additional protection against spending that delivers an immediate return. A proposal packed with acronyms, licences and options turns a worrying problem into an impossible decision.
The entrepreneurial opportunity lies in reducing this complexity, not monetising it. Customers need to understand what will be protected, what will remain their responsibility and what will happen if something goes wrong. Technology remains essential, but it becomes the means of delivering an operational promise.
Three commitments rather than fifteen features
Backups with verified recovery
“Your data is backed up” is not a sufficient guarantee. Which data? How often? With what access permissions? Cloud synchronisation can propagate a deletion or corruption. A copy accessible with the same credentials as the main system can also be compromised.
The service must therefore start by identifying critical data: accounting records, customer files, production documents and application configurations. It then establishes separate, protected copies, with an offline or immutable version where appropriate. Above all, it includes recovery tests. The commercial deliverable is not a green status light: it is a report showing what was actually recovered.
Two questions make the discussion concrete: how much work can the business afford to lose, and how long can it remain shut down? The answers determine the architecture and the price. Restoring a few documents and rebuilding a business application server require different resources and timescales.
Stronger authentication that is actually deployed
Multifactor authentication is among the priority measures, particularly for email, administrator access and remote connections. But selling licences without helping customers activate them leaves some of the risk unaddressed. Accounts must be inventoried, shared access addressed, and arrangements made for both an employee’s departure and the loss of a phone.
Security keys and passkeys can strengthen resistance to phishing where services support them. Their adoption must, however, remain suited to conditions on the ground. In a workshop or a shop, devices sometimes pass between several people. The provider must design a workable setup without letting exceptions become a permanent back door.
Someone to contact when everything grinds to a halt
Incident response is often the most abstract part of a quote, even though it can become the most reassuring. Who should you call? At what times? Who can isolate a workstation, revoke access or bring in a specialist? A short reference sheet, also available outside the IT network, is worth more than a procedure that cannot be found on the day of an outage.
Promises require care: a quick acknowledgement is not a guarantee of recovery. The contract must distinguish between support availability, response time and the recovery target. A small team should not sell round-the-clock coverage without an organisation capable of providing it, either directly or through a partner.
Building a package the customer can compare
An offering that customers can buy starts with an explicit scope. A core package could combine email security, protection for sensitive accounts, backup of priority data and incident preparedness. Updates and endpoint protection remain necessary: the three commitments structure the offering without covering every aspect of security. More complex needs require an additional assessment.
- At the outset: inventory, configuration, resolution of critical issues and an initial recovery test.
- Every month: backup checks, alert monitoring and support during defined hours.
- Periodically: access reviews, an incident exercise and a brief report to the business owner.
- At additional cost: work outside the package, additional volumes or specialist investigations, at a stated rate.
Pricing can combine a flat fee per business with a variable component linked to users or devices. No model works everywhere. The key is to avoid surprise bills and make cost drivers visible: storage, ageing equipment, number of sites and specific applications. A sales discount does not fix a poorly defined scope.
Profitability depends on operations
For the provider, the danger lies in underestimating the support required. Resetting access, explaining an alert or fixing a failed backup takes time. An appealing subscription becomes unprofitable if every customer requires a different architecture. Standardising a limited technology stack and documenting procedures therefore protects margins as much as quality.
The risks associated with the provider itself must also be factored in. Its privileged access can become a target. Account separation, traceability of interventions and protection of its own tools are essential. The contractual relationship must specify responsibilities, subcontractors and arrangements for returning data. A reassuring service does not lock the customer in.
Selling proof, not fear
Regulatory and contractual pressures are strengthening demand. The EU’s NIS2 Directive, adopted in 2022, broadens the European cybersecurity framework, but not all SMEs automatically fall within its scope. Requirements may also come from clients or insurers. A good salesperson distinguishes between applicable obligations, contractual requests and recommendations, rather than invoking a universal compliance requirement.
The most convincing proof remains within reach: a successful recovery, protected sensitive accounts, unnecessary access removed and an exercise conducted with the business owner. These results must appear in a readable report. They do not prove invulnerability; they show that the service performs verifiable work.
What next? Looking ahead to September 2026, the best-positioned offerings may be those that deliver this simplicity at scale: few options, precise commitments and identifiable human support. This remains a commercial hypothesis, not an established outcome. To test it, the best approach is to interview a few businesses in the same trade and measure the real cost of the service. The final question comes down to one sentence: does the customer know what they are buying, and who will help them tomorrow morning?


