Field Notes / SMB
9 in 10 Filipino SMBs carry at least one of these three security holes
Across our last 50 engagements with Filipino SMBs, three gaps showed up in more than 90 percent of the businesses we tested. Here is each one, what it costs an attacker, and the fix you can finish inside a working week.
01 Lock down your Facebook Page
he Filipino business runs on Facebook. The shop keeps a Page, the boss handles the inbox, and along the way the Page collects admins the way a beach collects plastic. Nobody sets out to leave a door open. It just never gets closed.
Across our 50 engagements, the median business carried 7 active admins on its Facebook Page. The worst case was a logistics firm in Quezon City with 23 admins, eleven of whom had left over the previous three years. Nobody had revoked their access. Their permissions outlived their company laptop, and one of the eleven had since joined a direct competitor.
A Page admin can post as you, rename the Page, transfer it to another Business Manager, or pull your entire customer message history. We have watched all four happen. The usual path starts with an ex-employee whose personal Facebook account gets phished or reused into a breach. The attacker signs in, sees the old admin rights still active, and either ransoms the Page back or sells it. Stolen valid access, not a fresh exploit, is the single largest action in confirmed breaches worldwide Verizon DBIR 2024 .
Here is what you get back in 15 minutes. Open Meta Business Suite, go to Settings, then People and Assets, then People. Remove every account that should not be there. Turn on two-factor authentication for the admins who remain. That is the whole fix. The reason it stays broken is ownership. Marketing assumes IT handles it. IT assumes marketing handles it. Nobody does.
02 Give every finance login a name
The bookkeeper has a login. The owner borrows it. The part-time CPA on Saturdays uses it. The virtual assistant doing data entry has it too. One QuickBooks Online, Xero or Dynamics account, four humans behind a single identity. This is the structural gap we find more reliably than any other. In 47 of our last 50 engagements there was at least one shared financial credential, and in 31 of them several finance systems shared the same one.
The fix is cheap and it buys you a clean audit trail. Every accounting platform sold today supports per-user logins for an extra USD 5 to USD 15 per user each month. Weigh that against a single fraudulent transfer and the maths finishes itself. Give each person a named login, then turn on multi-factor authentication. QuickBooks Online and Xero both support authenticator apps. The bookkeeper will say it slows them by ten seconds at sign-in. Ten seconds is a rounding error next to the weeks it takes to recover from accounting fraud.
03 Close the door you opened in 2020
In 2020 many Filipino SMBs needed remote work overnight. The IT provider opened a port on the firewall, exposed Remote Desktop straight to the internet, and that was the setup. Five years on, that port is still open in roughly half the businesses we audit. It is the one hole that gives an attacker your actual server rather than an account.
Shodan, the search engine for internet-exposed devices, indexes more than 11,000 RDP services in the Philippines on any given day Shodan . Some are home users. Many are SMBs whose provider opened the port and moved on. An attacker pairs one of those addresses with a leaked credential list, then runs a credential-stuffing tool that cycles millions of pairs until a login succeeds. Once inside, they have a desktop on your server, and moving across the rest of the network from there is trivial.
Two fixes, both proven. Either close the exposed RDP and route remote access through a VPN with multi-factor authentication, or replace it with a zero-trust tool such as Tailscale or Cloudflare Access. Both have free tiers that cover small business use. The migration takes one Saturday for a firm with a server or two. A quieter win comes with it: your firewall logs become readable again, because the flood of failed logins against the open port stops drowning out everything useful.
04 Give the three holes an owner
What blocks the fix is almost never technology. The Page sprawl persists because nobody is responsible for it. The shared login persists because the workflow was built for one person and three more grew into it. The exposed RDP persists because the original provider left and the new one is wary of breaking a setup that appears to work. You do not have a technology gap. You have an ownership gap, and closing it is cheaper than any tool.
You do not need a CISO. You need someone whose job includes reviewing the access list every quarter and checking which ports are open. Often that is an external party on a light monthly retainer, or a competent local MSP who can read a firewall log and audit a Microsoft 365 tenant. The presence of someone who looks regularly is what changes the trajectory. Total budget to close all three sits under PHP 100,000, and most of it is time, not spend.
If you do one thing this week, open Meta Business Suite and count the Page admins you cannot personally confirm are current staff. That number is your immediate risk, and you can close it before lunch. It also predicts the rest. We have never met an SMB with clean Page governance and broken finance logins. The businesses that carry one usually carry all three.
- Remove every stale Facebook Page admin in Meta Business Suite and turn on two-factor for the rest (15 minutes).
- Give each finance user a named login in QuickBooks or Xero and enable authenticator-app MFA (one onboarding day).
- Close exposed RDP behind a VPN with MFA, or move to Tailscale or Cloudflare Access (one Saturday).
- Assign one owner to review the access list and open ports every quarter (external retainer or local MSP).
References
Sources
- Verizon. 2024 Data Breach Investigations Report (DBIR). Verizon Business, 2024. verizon.com
- Mandiant. M-Trends 2025 Report. Mandiant (Google Cloud), 2025. mandiant.com
- Shodan. The Search Engine for Internet-Connected Devices. Shodan, 2026. shodan.io
- National Privacy Commission. Data Breach Notifications. NPC Philippines, 2026. privacy.gov.ph
- IBM Security. Cost of a Data Breach Report 2024. IBM Corporation, 2024. ibm.com