It would be unusual for no one to monitor the machinery, warehouse, or entrance doors on a factory floor overnight. The company would probably have cameras, an alarm system, access cards, and a clear record of who had moved around the premises. If someone tried to get inside at two in the morning, someone would most likely respond. Paradoxically, in most companies, the standard virtual office — Microsoft 365, Google Workspace, corporate email, SharePoint, calendars and shared documents — remains unprotected. Yet this is precisely where purchase orders, invoices, business proposals, contracts and internal communications are created, making it a lucrative target for hackers.
Attackers no longer need to break into companies using a Hollywood-style cyberattack. Even now, thousands of stolen credentials granting access to the systems of Slovak organisations are literally floating around the darker corners of the internet. Can you be certain that none of them belongs to one of your employees?
With cybersecurity typically receiving less attention, small and medium-sized businesses are easy targets for hackers. In recent years, smaller companies have faced a growing number of ransomware attacks.An attack capable of bringing your business to its knees does not have to begin with anything dramatic. Even we have recently responded to incidents in which a piece of outdated software was all it took to breach a company.

A login from an unusual country, a new device being added, an email forwarding rule being created, consent being granted to a third-party application or someone quietly browsing documents on SharePoint or Google Drive. None of this is likely to be detected by conventional antivirus software. If your environment is not monitored by technologies capable of correlating and evaluating these events, you are essentially defenceless.
Just as a company needs to know who entered its warehouse or production facility, its digital operations need to know who is signing in to its email accounts, accessing its documents and whether anything in the environment deviates from normal user behaviour.
Are you sure attackers have nothing to gain from you?
This is a common refrain, especially in light industry and manufacturing. If you believe attackers have no way to harm you, imagine your day-to-day operations with your warehouse management, accounting, or communications systems “switched off”. Imagine suspicious messages being sent to clients from your corporate email account, or the authorities asking about that leak of customers’ personal data last month.
Hackers’ tactics and creativity often go far beyond what we can anticipate. One easy-to-imagine example is business email compromise. “We handled a serious incident in which an attacker took control of an accountant’s mailbox. The company then received an invoice from a supplier that looked exactly the same as usual. The only difference was the bank account, which was located somewhere abroad,” says Jozef Rusnák, describing one typical scenario.
The risk is especially acute for small and medium-sized businesses, which are increasingly appearing on hackers’ radar. They may not have large budgets, but they use the same cloud tools as major corporations — without having a team to monitor them.
“We had a case where a company had purchased a security tool but was only using a small fraction of its capabilities. Without expert oversight, a smaller business with no experienced IT security team has no chance of unlocking the full potential of the services available to it,” Rusnák explains.
Cloud Services Monitoring dramatically improves security
It provides expert oversight of what is happening in your virtual office. Conventional antivirus software will not help if someone in the environment sets up email forwarding outside the organisation. Some of these events may, after all, be legitimate. Only active monitoring can distinguish between different situations and evaluate them in context.
“The advantage of monitoring for smaller companies is that they can put all of our expertise and technology to work for them in a highly cost-effective way,” explains Jozef Rusnák

Monitoring cloud services such as Microsoft 365 or Google Workspace is particularly valuable for businesses that need visibility into their cloud environment but do not want to, or cannot, build their own SOC. It is also a highly cost-effective way to gain expert oversight of their environment.
Not every company needs cameras in every room. But every company should know whether someone is moving through its emails, documents and accounts in the middle of the night. If the machines on your factory floor are under surveillance, the systems where a successful incident could cause serious financial and reputational damage should not be left unattended either.
This activity is supported by the European Cybersecurity Competence Centre (ECCC) as part of the project under grant code 101145856, and by the Ministry of Investments, Regional Development and Informatization as part of the state programme of the Recovery and Resilience Plan of the Slovak Republic under project grant code 17I04-04-V02-00001.
