The Six Security Measures That Prevent Most Small Business Breaches
Last updated:
You are not being targeted by anyone sophisticated
Small businesses are rarely the subject of a deliberate campaign. What happens is opportunistic: a credential reused from another breach, a phishing email, an unpatched system found by an automated scan, or an invoice fraud attempt.
That is good news, because ordinary controls stop ordinary attacks. You do not need an enterprise security programme; you need six things done properly.
1. Multi-factor authentication, everywhere
The highest-return control available and usually free. Email first, then anything financial, then everything else. A stolen password stops being sufficient.
If you do nothing else this quarter, enforce multi-factor authentication on email. Email compromise is the entry point for most of the invoice fraud and impersonation that hits small businesses.
2. A password manager
Shared credentials in a spreadsheet, or the same password across services, is how one breach becomes several. A business password manager with shared vaults costs a few pounds per user and removes the problem.
It also solves offboarding partially: rotate the shared credentials when someone leaves rather than trying to remember which they knew.
3. Updates on a schedule
Operating systems, browsers, phones, servers, website software. Automate what can be automated and schedule the rest monthly. Unpatched software is how automated attacks succeed.
This includes the website: an unmaintained content management system is the most common route into a small business's web presence.
4. Backups you have restored
- Everything critical covered, including cloud services people assume are backed up
- One copy somewhere separate from the primary system
- Retention long enough to survive a problem found weeks later
- An actual restore performed at least annually
Ransomware turns from a catastrophe into an expensive inconvenience if backups work. Untested backups routinely turn out not to.
5. Offboarding that actually removes access
List every system someone had access to and remove it the day they leave. Automate it if you can; use a written checklist if you cannot.
Check today: pick someone who left six months ago and see whether every account is closed. In most businesses without an automated process, at least one is not.
6. A payment verification rule
Any change to supplier bank details, and any unusual payment request, is verified by phone to a known number — never a number in the email requesting it.
This single rule prevents the most common financially damaging attack on small businesses, and it costs nothing but a policy and the discipline to follow it.
Frequently asked questions
Do we need cyber insurance?
What about Cyber Essentials?
How much should we spend on security?
Who should own this in a small business?
Not sure whether the basics are covered?
Run the six checks. If any answer is uncertain, that is where to start — and we are happy to help you work through them.
Related services
What we build for problems like this one