Most attacks on small businesses are not sophisticated. They rely on weak passwords, unpatched software and one person clicking one bad link. The good news is that a handful of basic, affordable steps block the overwhelming majority of them.
Almost every attack that reaches a small business is automated and indiscriminate. It is looking for an open door, not for you.
The short version
Here is the checklist we walk clients through. You can action most of it yourself, and it costs far less than a single incident would.
The essentials
- Turn on multi-factor authentication (MFA) everywhere you can, especially email, banking and admin accounts. It is the single most effective thing you can do.
- Use a password manager so every account has a long, unique password nobody has to remember.
- Keep software updated. Turn on automatic updates for devices, apps and browsers. Most breaches exploit known holes that a patch already fixed.
- Back up your data automatically, keep a copy offline or in a separate account, and test that you can actually restore it.
- Lock down email. Enable spam and phishing filters, and be wary of any message creating urgency about payments or passwords.
The next layer
- Limit access. People should only have access to what they need. Remove logins the day someone leaves.
- Protect every device with reputable security software and a firewall, including phones and laptops used for work.
- Secure your Wi-Fi with a strong password and a separate network for guests.
- Train your team. A five-minute chat about phishing does more than most tools. People are your first line of defence.
- Have a simple plan for what to do if something goes wrong, who to call, how to isolate the problem and how to recover.
How to know if you're covered
If you can confidently tick every box above, you are ahead of most businesses your size. If a few are shaky, those are your priorities. A short security review will tell you exactly where the gaps are and what to fix first, usually in a single afternoon.
Not sure how you'd score?
We'll run a plain-English security review and show you the gaps.
Book a review →