Cybersecurity Essentials for Small Businesses

Software dashboard displayed on a screen
Photo via Pexels

Small businesses are attacked because they are accessible, not because they are interesting. Automated scanning finds exposed services and unpatched systems indiscriminately, and phishing campaigns are sent in volume without regard to company size.

The encouraging part is that a small number of well-established controls stop most of what actually happens. Sophisticated targeted attacks exist; they are not what closes most small businesses.

Multi-factor authentication is the single highest-value control

Credential theft is the most common initial access method in reported breaches. Multi-factor authentication makes stolen passwords substantially less useful, and Microsoft and others have published figures suggesting it blocks the overwhelming majority of automated account compromise attempts.

Enable it everywhere it is available, prioritising email, financial systems, remote access and administrative accounts. Email is the highest priority because it is the reset mechanism for everything else.

Prefer authenticator apps or hardware security keys over SMS, since SIM swapping defeats text-based codes. Hardware keys are the strongest option and are inexpensive for the accounts that matter most.

Backups you have actually tested

Ransomware remains a serious threat to small organisations, and the difference between an incident and a catastrophe is usually whether restorable backups exist.

The widely used guidance is three copies, on two different media, with one off-site. The modern addition is at least one copy immutable or offline, because ransomware operators specifically target connected backups.

The part organisations skip is testing restores. A backup that has never been restored is an assumption. Test quarterly, restore actual files, and document how long a full recovery takes — that figure is your real recovery time, and it is frequently longer than anyone assumed.

Patching and end-of-life software

Most successful exploitation uses known vulnerabilities with available patches. Enable automatic updates on operating systems, browsers and applications wherever practical.

Track anything running past its support date. Unsupported operating systems and applications receive no security fixes, and continuing to run them is a decision to accumulate unfixable vulnerabilities. This includes network equipment and any internet-facing device.

Email security and the wire fraud problem

Business email compromise causes very large financial losses, frequently exceeding ransomware in reported damages. The pattern is impersonation of an executive or supplier requesting a payment or a change of bank details.

The control is procedural rather than technical: verify any payment instruction or bank detail change through a second channel using contact details you already hold, not those in the email. Make this a written policy and give staff explicit permission to delay a payment for verification.

Technically, configure SPF, DKIM and DMARC for your domain to make it harder to spoof, and enable external sender warnings.

Access control and offboarding

Give people access to what they need and remove it when they change role. Administrative rights should be separate accounts used only when required.

Offboarding is a common gap. Departed employees retaining access to email, cloud storage or shared accounts is routine in small businesses. Maintain a list of systems and run through it on the day someone leaves.

Avoid shared logins entirely where possible; use a password manager with individual accounts so activity is attributable and access is revocable.

Training and incident planning

Security awareness training reduces phishing susceptibility, and simulated phishing with follow-up education has evidence behind it. The tone matters — a culture where people report mistakes quickly is worth more than one where they hide them.

Write a one-page incident plan: who to call, how to isolate a machine, where backups are, which regulators or customers must be notified and within what timeframe. Breach notification obligations apply regardless of company size and vary by state and sector.

Cyber insurance is increasingly relevant, and insurers now typically require MFA and backups as a condition of cover — which is itself a reasonable signal about which controls matter most.

Article Was Generated By AI.

This article is general information only and does not constitute professional advice. Circumstances vary, and you should consult a qualified professional before making decisions based on this content.