Foundations (do these first)
๐ Passwords and Access
Enforce unique passwords. Use a business password manager. Remove access immediately when staff leave.
๐ก Multi-factor Authentication
Require MFA on all business email, cloud storage, and accounting tools โ no exceptions.
๐ Update Software Regularly
Enable auto-updates on all devices. Outdated software is the #1 entry point for attackers.
Data and continuity
๐พ Back up regularly
Follow the 3-2-1 rule: 3 copies, 2 media types, 1 off-site or cloud. Test restoring capability quarterly. If using a cloud service, ensure it is a reputable provider โ avoid free services with unclear privacy terms.
๐ค Limit who can access what
Staff should only see the data their role requires โ not everything on the system. Apply least-privilege access โ give each person only the minimum access required for their current responsibilities.
๐ Encrypt sensitive data
Enable encryption on devices, storage, and customer transactions. Essential for e-commerce โ financial and personal data must be unreadable if accessed by hackers.
๐ถ Separate your networks
Run a separate Wi-Fi network for customers and guests. Never share the same network used for business systems with them โ a compromised guest device could otherwise expose your entire business network.
Human risk
โ๏ธ Phishing โ the #1 way attackers get in
What it is
A deceptive email, text, or call that tricks someone into clicking a link, entering credentials, or transferring money โ by pretending to be a trusted source like a bank, vendor, or colleague.
How it happens
An employee gets an urgent email from a "supplier" asking to confirm payment details. They click the link, enter their login โ and attackers now have access. It takes seconds and no technical skill to fall for.
Stay safe
Never click links in unexpected emails โ go directly to the website instead. Verify unusual requests by phone. Train staff regularly and run practice drills to build awareness before a real attack hits.
๐ Have an incident response plan
Know who to call if your system is breached. Write down steps: isolate the device, notify your IT contact, preserve logs. Do not wait until it happens.
๐งโ๐ป Run phishing drills
Send simulated phishing emails to staff, review who clicked. Free tools like Google's Phishing Quiz make this easy to set up and run regularly.
โ If you think your system has been breached:
Disconnect the affected device from the internet immediately. Do not turn it off. Contact your IT provider or a cybersecurity firm. Notify affected customers if their data may be at risk.
Monthly checklist
โ Confirm backups completed successfully
โ Check for pending software and firmware updates
โ Caution staff never to share passwords by email or chat
โ Check login activity for any unusual or unexpected sign-ins
โ Confirm that a backup can recover the system to a working state
โ Check that sensitive customer or business data is stored securely
โ Collect reports from staff on any suspicious emails or login attempts
โ Check who has access to business accounts, remove unnecessary access
68%
of breaches involve a human element โ phishing, stolen credentials, or error
Verizon Data Breach Investigations Report (DBIR) 2025
88%
of SMB breaches involve ransomware โ vs. 39% at large enterprises
Verizon Data Breach Investigations Report (DBIR) 2025
$120k+
minimum realistic cost of a data breach for a small business โ enough to threaten survival
Verizon DBIR 2024 ยท IBM Cost of a Data Breach Report 2024