There's no company too small to be targeted. Statistically speaking, at some point in the life of your business, it's virtually guaranteed that you'll be hit. Here are some basic, sensible low cost things you can do to protect yourself.
1) Have a virus scanning software system installed and keep it updated
This is one of the "holy trinity" of fundamentals. If you can't even be bothered to take this step, especially given that you can even get some level of virus protection for free, then you are putting yourself in the line of fire.
2) Have your firewall turned on
Another thing you can do for free, and if you're not doing it, you certainly should be. Yes, you can spend money to buy better and more robust solutions, and you may want to, but the bottom line is that, as with virus protection above, you can get at least some level of protection for no money. If you're not, you may as well be hanging a large, neon sign just outside your shop inviting criminals in and telling them where all the valuables are.
3) Have a Malware detection program running
Part of what makes a good anti-virus program a good anti-virus program is the fact that it only focuses on doing one thing. Since it only focuses on doing one thing, it tends to do that one thing very well. Unfortunately, that means that your anti-virus program probably isn't great at stopping other kinds of threats like Malware. You need more software for that. This is really the last of the "holy trinity" of simple steps you can take to give yourself some basic level of protection, and like the others, you can find solutions on the market that are free. There's simply no reason not to do this.
4) Make sure all chip-equipped, networked components are protected
Would you triple lock your front door and leave your back door standing wide open? How much sense does that make from a security standpoint? If you answered something close to "Not Much," you win the prize, and it's the same thing with any "smart appliances" you might have in your office.
Did you know that last year, a group of Russian hackers "slaved" a big group of smart appliances, including a rogue refrigerator, and used them to launch a DOS (Denial of Service) attack against a network? It happened. It could happen to you. If you have smart appliances that are connected to your network, then you need to be certain that your various network protections apply to them (and they won't automatically).
5) Develop a sensible password policy
Step one is developing the policy. Step two is making sure your employees know what it is, and step three is making sure they know why it's important. If you want to be dramatic, hire a system security analyst to come in after hours and install a program that makes it appear that the whole company has been hacked. Your people file in, log on, and are greeted with messages telling them that they won't get paid because the company's accounts have been frozen. All their vacation time has been wiped out, etc. Make it as grim and dire as you want. Then, before everybody freaks out too badly, reveal the truth, but let them know that the scenario you just mocked up for them could easily happen. When you point out how it can hurt their wallets, that usually drives the point home.
Network security has come a long ways since the early days of personal computers, but in order to gain any advantage of that strength, you do have to actually do the work You do actually have to take steps. There's no reason not to.

