In 2026, corporate data security is no longer an issue to be put off until “there’s time.” In Italy, the first half of 2025 saw 2,755 cyber incidents—the highest number ever recorded—representing a 36% increase compared to the end of 2024; furthermore, approximately one-fifth of all attacks recorded since 2020 occurred in just the first six months of 2025, according to the Clusit report cited in 2025 (source). For many SMEs, this changes the perspective: it’s not just about having antivirus software and backups, but about being able to detect faint signals, anomalies, and out-of-profile access attempts before the damage becomes operational.
The good news is that the foundation already exists in many companies. In 2022, 74.4% of Italian companies with at least 10 employees used at least three ICT security measures, a level in line with the EU average (74.0%) (ISTAT). The problem is that widespread adoption does not equate to comprehensive protection. If controls remain siloed, data slips through the cracks among local files, the cloud, email, personal devices, and forgotten permissions. This is where a more practical approach comes into play—one focused on the data lifecycle and continuous monitoring, not just prevention.
The most important figure to keep in mind is this: 2,755 cyber incidents in Italy in the first half of 2025—the highest level on record—representing a 36% increase compared to the end of 2024. For an SME, the message is not to panic. The point is to treat cyber risk as a standard part of operations, on par with business continuity or email availability.

Many Italian companies already have basic security measures in place, but they often implement them in a haphazard manner. A firewall does not protect a poorly secured shared file, a backup does not safeguard an account with excessive permissions, and antivirus software does not correct a configuration error in the cloud. The result is a defense that seems comprehensive on paper but leaves very real entry points wide open.
Security often fails not because of a lack of tools, but because of a lack of coordination among tools, people, and processes.
SMEs are particularly vulnerable when work is spread across the office, home, external consultants, and personal devices. In these situations, an attack doesn’t have to be sophisticated to succeed. All it takes is a poorly managed access credential, a session left open, or a file accidentally left shared in a cloud folder.
The idea of protecting only the network perimeter no longer holds up. Data moves, is duplicated, and is reused across multiple systems. That is why corporate data security must be viewed as the ability to reduce the attack surface and to immediately recognize when something deviates from the normal pattern.
A useful reference—even for those evaluating architectural and compliance options—is the analysis titled “NIS2: Opportunity or Obstacle?” The practical lesson is that compliance alone is not enough, because data must be protected on an ongoing basis, not just documented.

A significant portion of incidents stems from a basic error, not from a sophisticated attack. Data isn’t all stored in the same place, and it isn’t protected in the same way. A file stored on a server, an invoice sent via email, and a report opened in an ERP system require different security measures because they differ in terms of their attack surface, access methods, and the possibility of being copied. Distinguishing between data at rest, data in transit, and data in use remains the most useful starting point for avoiding generic security measures that appear robust but offer little actual protection.
Archived data is data that is stored on local servers, in cloud repositories, or in backups. What matters here are encryption, access controls, and—when necessary—techniques such as de-identification and tokenization (Digital Agenda). The right question isn’t just “Do we have the files saved?”, but “Who can open, copy, or move them without us noticing?”
For an SME, this translates into very concrete actions, and often the real trade-off is between operational simplicity and strict control:
If an archive also contains old versions, exports, or forgotten attachments, the risk increases without anyone noticing. In this case, managing dark data is just as important as protecting the current file.
Data in transit is data that travels between users, applications, and locations. This is where secure protocols such as SFTP, HTTPS, SSH, and TLS (Digital Agenda) are needed. If a company sends price lists, customer records, or HR documents, security cannot stop at the receiving server. It must also cover the transmission itself, because that is precisely where interception, configuration errors, and improper forwarding are most likely to occur.
The data in use is the data open within applications, browsers, and management systems. In this context, the principle of least privilege is crucial, because it restricts access to authorized users only and reduces the impact of a compromised account (Digital Agenda). If a sales representative sees more data than necessary, the risk is not theoretical—it is operational—because every additional piece of visible data becomes a potential target for copying, exporting, or sharing.
Rule of thumb: If you don't know what state a piece of data is in, you don't really know how to protect it.
A good initial assessment involves mapping out three things: where the data is located, who accesses it, and which systems move it. From there, gaps immediately become apparent—often more in permissions and data flows than in the software itself. For an SME, the practical takeaway is simple: less exposure for data that remains static, fewer unnecessary steps for data in transit, and fewer privileges for data used on a daily basis.
Dark data refers to forgotten, duplicated, or unused data that accumulates without any clear operational value. Many guides discuss backups and encryption but overlook this point, because the risk surface often grows even before protection is implemented. Old exports, attachments, local copies, and project archives end up scattered across multiple locations, and no one knows exactly where they are or who is using them. TechRadar Italia points out that this data may also include intellectual property and sensitive confidential information, and that managing it requires understanding the data’s origin, handling, and use.
The most common mistake is to hoard everything “just to be safe.” In practice, the more data you keep, the more potential access points, opportunities for error, and governance costs increase. Corporate data security often improves when you reduce what is no longer needed, rather than simply adding more controls.
For an SME, the point isn't just to get organized. It's about deciding which data truly deserves to remain online, which should be moved to the archive, and which must be removed from active systems before it becomes a risk of exposure or a compliance issue.
The EDPB's guidance for small businesses emphasizes data minimization, pseudonymization or anonymization, periodic review of authorizations, and encryption (EDPB). What companies often fail to do is translate these principles into a data lifecycle management process for infrequently used or forgotten data, with clear rules on retention, archiving, and deletion.
A simple criterion works better than an abstract rule. If data is not needed for an active process, a legal obligation, or a specific operational recovery, it should be removed or archived in a controlled manner. If, on the other hand, it is truly necessary for the business, it should be kept active with clear ownership and periodic review.
In the projects I manage, this practical approach avoids endless discussions about files “that might come in handy.” When a folder remains open simply out of habit, the risk is very real. Every additional copy increases the number of people who can view, export, or forward it, and every unmanaged archive makes it harder to track where sensitive data has ended up.
You can use this sequence:
There are two benefits here. You reduce the risk of exposure and make it easier to protect what really matters. SMEs that take this step often discover that part of the problem wasn’t a lack of protection, but the amount of data left circulating for no particular reason.
An effective defense doesn’t come from scattered tools, but from controls that work together. In the SMEs I work with, the most useful measures remain those that focus on automatic session termination, up-to-date firewalls and antivirus software, secure backups, unique identifiers, revocation of outdated permissions, and periodic access audits. The principle is simple. Each measure taken on its own helps, but the real breakthrough comes when one measure covers the blind spot of another.

The " defense in depth " approach works when each layer compensates for the limitations of the previous one. Encryption protects the content even if a file leaves the expected perimeter; backups allow for a quick recovery without interrupting operations; DLP reduces unauthorized data leaks; MFA makes it harder to misuse credentials; access management limits privileges; andsystem hardening reduces the attack surface. If any one of these layers is missing, the defense remains more vulnerable than it appears.
The practical aspect lies in integration, not in the list. The documentation cited in the source emphasizes that the protection of sensitive data must be extended from the Microsoft 365 environment to SaaS services, the cloud, and on-premises repositories through classification and data loss prevention (DNCSRL). For an SMB, this is a practical consideration, because today, data used for work does not reside in a single system and often moves between applications that were not designed to communicate securely with one another.
Zero Trust enterprise security helps address this very issue. Every access attempt must be verified in the proper context—taking into account identity, device, location, and risk level—so that access isn't granted simply because someone is already on the network.
In a hybrid work environment, the problem isn’t just remote access, but the number of devices involved. The EDPB’s guide for SMEs suggests policies on remote work, protection of personal devices, VPNs, automatic session lockout, and the removal of obsolete access credentials. For many companies, the issue is cultural rather than technical. They apply rules designed for office computers to a distributed environment, and then are surprised when the controls fail.
A personal laptop should not be treated as an implicit extension of the corporate network. It should be managed as an entry point, with clear policies regarding encryption, updates, access, and profile separation.
For those trying to decide where to start, the priority isn’t to accumulate tools. A well-executed backup remains useful, but it doesn’t make up for chaotic permissions or credentials left active for too long. Corporate data security is truly robust when controls communicate with one another and when the security perimeter also includes forgotten data—the data that often falls off the radar and creates the hardest-to-detect risks.
Artificial intelligence changes the way you look at data, because it shifts the focus from fixed rules to behavior. In an SME, this is invaluable, since anomalous patterns often go unnoticed amid the normal activity of users, suppliers, and consultants. ELECTE, an AI-powered data analytics platform for SMEs, specializes in automated analysis and anomaly detection—an approach that fits well within a continuous monitoring framework.

Traditional security often relies on thresholds, signatures, and known rules. This works well in many situations, but it struggles when behavior changes in subtle ways. An AI system, on the other hand, can detect unusual logins, abnormal times, activity volumes that deviate from the norm, or combinations of events that, taken individually, seem harmless.
The practical value isn't in replacing the IT team, but in helping them anticipate issues. When data comes from different sources—such as CRM, ERP, the cloud, and access logs—manual monitoring can easily become reactive. AI makes it easier to transition to continuous monitoring of signals.
For an SME, useful applications are very down-to-earth:
A similar analysis also ties in well with the topic of managing data spikes and dips, because the same logic that helps identify a business anomaly can help identify a security anomaly. The key is to have a platform that doesn’t just store data, but actively monitors it.
With continuous monitoring, corporate data security is no longer a reaction to incidents. It becomes the ability to detect small anomalies before they turn into access issues or data loss.
An effective plan for SMEs must be sequential, not ideal. Companies that manage to make real improvements start with a few high-impact measures and then consolidate the rest. The priority is to get things in order before adding new tools, because security works best when roles, data, and access permissions are already clearly defined.

Over the course of a week, focus your efforts on what reduces immediate exposure.
Over the next month, work on structure and control.
Within three months, it aims to make security reproducible.
The most useful routine isn't the perfect one—it's the one that someone can actually stick to every week.
If you want a simple metric, measure the number of unjustified access attempts that were blocked, the success rate of account recoveries, and how quickly an anomaly is brought to the attention of the appropriate personnel. These are far more useful indicators than a checklist filled out just once.
Corporate data security works best when it doesn’t disrupt work, but rather supports it. In a sales office, for example, the team can share quotes and price lists in classified environments, with access revoked once a collaboration ends. In administration, sensitive documents remain accessible only to those who actually need to handle them, while in operations, production and logistics data are monitored without the need for constant manual checks.
It’s the internal culture that makes the difference. If employees perceive safety as an obstacle, they’ll circumvent the rules. If, on the other hand, they see it as a way to avoid bottlenecks, mistakes, and wasted time, they’ll embrace it more readily. This requires simple language, concrete examples, and shared responsibility—not just procedures filed away.
The goal is not to make everything visible to IT, but to make everything manageable. The companies that achieve the best results treat data as an operational asset, with controls that protect it without slowing down the sales cycle, billing, or customer support.
ELECTE helps SMEs transform raw data into actionable insights through automated analysis and anomaly detection, which are also useful for continuous security monitoring. If you want to gain more control over your information flows and see how an AI-powered approach can support governance and anomaly detection, visit ELECTE and explore how to integrate it into your processes.