Cybersecurity
The Six Security Basics That Prevent Most Small Business Breaches
Small businesses aren't breached by sophisticated attacks. They're breached by reused passwords and missing two-factor. Here's the short list that closes most of the gap.
Small businesses don't get breached by sophisticated attacks. Nobody is writing custom malware for a six-person firm.
They get breached because a password was reused, two-factor wasn't switched on, or a former contractor still had access eight months later. The defences are correspondingly unglamorous, and the six below close most of the realistic gap.
1. Two-factor on email, first
If you do one thing, do this.
Email is the reset path to everything else. Whoever controls your email can reset your banking, your accounting software, your domain, your CRM. It's the master key, and it's usually protected by a password alone.
Turn on two-factor for every business email account today. Then, in order: banking, accounting software, domain registrar, payment processor, anything holding client data.
Prefer an authenticator app or a hardware key over SMS. SMS codes can be intercepted through SIM-swap attacks, which are a real and not-especially-advanced technique. SMS is still vastly better than nothing — use it where it's the only option.
2. A password manager, for everyone
The vulnerability isn't weak passwords so much as reused ones.
When a service you signed up to years ago gets breached, those credentials get tried everywhere else. If the same password protects your accounting software, that's how the compromise happens — no sophistication required.
A password manager fixes this by making unique passwords practical:
- Everyone gets one, including you
- Unique password for every service
- Shared credentials go in a shared vault, not in a spreadsheet or a chat message
- The manager itself gets two-factor and a strong master password
Never share credentials over email or chat. They persist in the thread indefinitely, and that thread outlives the working relationship.
3. Update everything, automatically
Attackers overwhelmingly exploit known, already-patched vulnerabilities. The window between a patch being published and it being exploited is short, and the exploitation continues for years afterward because so many systems never update.
Turn on automatic updates for operating systems, browsers, phones, and any software you host yourself. Set a monthly reminder to check anything that can't update automatically.
The unglamorous version of this: if a device is too old to receive security updates, it is a liability. That includes phones, and it's a real cost worth budgeting for rather than deferring.
4. Back up, and test the restore
Ransomware is the realistic worst case for a small business, and backups are the answer — provided they work.
The rule that matters: three copies, two different media, one off-site and disconnected.
The disconnected part is the bit people miss. Ransomware encrypts anything it can reach, including a connected backup drive and, in some cases, synced cloud storage. A backup that's permanently attached is a backup that gets encrypted alongside everything else.
Then test a restore. An untested backup is an assumption. Restore something real, once a quarter — the number of businesses that discover their backups were failing silently at the moment they need them is not small.
5. Remove access when people leave
This is a process failure rather than a technical one, which is why it's skipped so consistently.
Contractors, former employees, an agency you stopped working with two years ago — all frequently retain access to email, shared drives, tools and systems long after the relationship ends.
The fix is a leaver checklist, run the same day:
- [ ] Email account disabled or forwarded then disabled
- [ ] Removed from every shared tool
- [ ] Shared passwords they knew, rotated
- [ ] Devices returned or wiped
- [ ] Access to shared drives revoked
- [ ] Any API keys or integrations they created, reviewed
Keep an access list so this is possible at all. If you can't answer "what does this person have access to", you can't remove it — and that's the underlying problem.
6. Know how to recognise a payment scam
The attack that actually costs small businesses money isn't technical. It's someone emailing your bookkeeper, pretending to be you or a supplier, asking for a payment or a change of bank details.
Two rules prevent almost all of it:
Any change to bank details gets verified by phone, on a number you already had — never a number in the email requesting the change.
Any unexpected payment request gets verified, however urgent it claims to be. Urgency is the technique; it exists to prevent the check.
Say this out loud to whoever handles payments, and say explicitly that verifying is never treated as an insult or a delay, including when the request appears to come from you. That last part matters — the attack works partly because people don't want to question the boss.
What you probably don't need yet
To be clear about proportionality:
- A dedicated security tool suite, before the basics above are done
- Penetration testing, unless you build software or a client requires it
- A formal security certification, unless a client contract demands one
- Cyber insurance, before basic controls — insurers increasingly ask, and gaps can affect a claim
Doing the six above beats buying anything, and costs almost nothing.
Where this gets specific
Sector and jurisdiction change the requirements. If you handle health data, payment card data, or personal data at any scale, there are specific obligations that vary by where you operate — and those are a conversation with someone who advises on compliance in your jurisdiction rather than a checklist item.
This article is the general floor, not a compliance programme.
The mistakes
- No two-factor on email. It's the reset path to everything.
- Reused passwords. The actual mechanism behind most account takeovers.
- Deferred updates. Known vulnerabilities are the ones exploited.
- Connected backups. Encrypted along with everything else.
- Never testing a restore. An assumption, not a backup.
- No leaver process. Access that outlives the relationship.
- No payment verification rule. The attack that actually takes the money.
What to do next
Turn on two-factor for every business email account today — it takes ten minutes and it's the highest-value thing on this list by a wide margin.
Then write the bank-details rule and tell whoever handles payments. Those two changes address the two most common ways small businesses actually lose money to this.
The Newsletter
WealthLink Weekly
Business. Money. Marketing. Real Estate. Technology. One email.
One email a week. Unsubscribe anytime.