Most cybersecurity advice is written for organisations with a security team. It's not wrong, it's just addressed to someone else — and the effect on a six-person business is usually paralysis, or an expensive tool bought instead of the free controls that would have mattered.
The realistic picture is narrower and considerably more manageable. Small businesses are compromised through reused credentials, missing two-factor, access that outlived a relationship, and a plausible email about a changed bank account. Nothing on that list requires sophistication to execute, and nothing on it requires sophistication to defend.
The order to do this in
| Step | What it addresses | |---|---| | 1. The six basics | Most credential-based compromise | | 2. Payment verification | The attack that actually takes money | | 3. Access register | What you can't currently answer | | 4. Backups + restore test | The ransomware worst case | | 5. Incident plan | The first hour, decided in advance |
Do them in that order. Each one is cheap, and the first two cover the majority of realistic loss.
1. The six basics
Two-factor on email first — it's the reset path to your banking, accounting, domain and everything else. Then a password manager for everyone, because reuse rather than weakness is the actual mechanism behind account takeover. Then automatic updates, working backups, a leaver process, and a payment verification rule.
That's the whole floor, and it costs almost nothing.
→ The six security basics that prevent most breaches
2. The attack that takes the money
Worth separating from the rest, because it isn't technical and technical controls don't stop it.
Someone emails your bookkeeper — sometimes from a genuinely compromised supplier mailbox, so the address is real — saying bank details have changed. The invoice is real. The amount is right. The money goes somewhere else.
Two rules stop almost all of it: every bank detail change is verified by phone on a number you already had, and every unexpected payment request is verified however urgent it claims to be.
And one sentence makes those rules actually work: verifying is never an insult and never a delay problem, including when the request appears to come from me. Without that said out loud, the process exists on paper and someone approves the payment anyway.
→ How payment fraud actually reaches small businesses
3. Who has access to what
Ask most owners what a former contractor still has access to and the answer is approximate. That approximation is the vulnerability — you cannot remove access you can't enumerate.
Build the register (a spreadsheet is fine), give the least access that does the job, kill shared logins where individual accounts exist, and run the leaver checklist the same day rather than eventually.
Set the removal date at the moment you grant access, while you're thinking about it. It's the single highest-value habit here, because nobody ever remembers later.
→ Who has access to what (and why you probably don't know)
4. Backups that survive the thing you're backing up against
Three copies, two media, one off-site and disconnected — the disconnected part being what survives ransomware, since anything permanently attached gets encrypted alongside everything else.
And sync is not backup. Sync faithfully replicates deletions and encryption everywhere within seconds, which is the opposite of what you need.
Then the step that separates real backups from assumed ones: restore something real, every quarter. An untested backup is an assumption you're planning to verify during an emergency.
→ Backups that actually work when you need them
5. The first hour
Written before you need it, because it's the hour you'll think least clearly.
Contain first, investigate second — but don't destroy evidence while containing. For a fraudulent payment, call the bank before anything else; recovery odds fall by the hour. For ransomware, disconnect the backups immediately. For a compromised mailbox, check the forwarding rules, which is where persistence hides.
Fill in the phone numbers now. Print it. Store it somewhere that isn't the system it covers.
→ What to do in the first hour of a security incident
How to tell if it already happened
Worth doing once, because compromise is frequently quiet and discovered months later by accident. Half an hour covers the realistic signals.
Check every business mailbox for forwarding rules and filters you didn't create. This is the single most valuable check on the list. A rule quietly copying everything outward — or auto-deleting security alerts so you never see the login notifications — is the standard persistence mechanism, and it survives a password change.
Review active sessions and login history on email and anything financial. Most providers show recent sign-ins with location and device. You're looking for somewhere you've never been, or a device nobody recognises.
Check which devices are registered for two-factor, and whether the recovery email and phone number are still yours. Adding their own recovery method is how an attacker keeps access after you reset the password.
Look at outgoing payments for the last six months against suppliers you actually recognise. The fake-invoice version of payment fraud runs for months precisely because each amount is unremarkable.
Check your domain registrar and DNS records. Rarely looked at, and the most damaging thing to quietly lose control of.
Finding nothing takes half an hour. Finding something takes half an hour and saves considerably more.
What changes as you grow
The floor above is stable. A few things genuinely change, and it's worth knowing which trigger is which so you're not buying ahead of need or behind it.
Your first employee turns access management from a mental note into a process. That's the point at which the register, the joiner checklist and the leaver checklist stop being optional — not because the risk jumped, but because you no longer hold the whole picture in your head.
Holding client data changes your obligations rather than your controls. What applies depends on the data and where you operate, and it's the point to ask rather than assume.
Your first enterprise client frequently arrives with a security questionnaire, and occasionally a certification requirement. This is the most common reason small businesses formalise, and it's a reasonable one — but let the contract drive it rather than buying a certification speculatively.
Handling payments or card data directly brings specific requirements that don't apply otherwise. Using an established processor keeps most of that burden with them, which is usually the right trade at small scale.
Any of your own software touching customer data is where penetration testing starts being worth its cost, and not particularly before.
None of these change the basics. They add to them.
What you probably don't need yet
For proportionality, because most spending here happens in the wrong order:
- A security tool suite, before the six basics are done
- Penetration testing, unless you build software or a client requires it
- A certification, unless a contract demands one
- Cyber insurance, before basic controls — insurers increasingly ask, and gaps can affect a claim
The unglamorous list above beats anything you can buy, and costs almost nothing.
Where this stops being general
Sector and jurisdiction change the obligations considerably. If you handle health data, payment card data, or personal data at any scale, there are specific requirements — including breach notification deadlines that are short and start when you become aware.
That's a conversation with someone who advises on compliance where you operate, not a checklist item. This guide is the general floor, not a compliance programme.
The one thing
If you do nothing else this week: turn on two-factor for every business email account, and tell whoever handles payments the bank-details rule.
Ten minutes and one conversation, against the two most common ways small businesses actually lose money to this.
The Newsletter
WealthLink Weekly
Business. Money. Marketing. Real Estate. Technology. One email.
One email a week. Unsubscribe anytime.