Think Build Implement Repeat
SaaS & Product

The Six Security Measures That Prevent Most Small Business Breaches

Last updated:

You are not being targeted by anyone sophisticated

Small businesses are rarely the subject of a deliberate campaign. What happens is opportunistic: a credential reused from another breach, a phishing email, an unpatched system found by an automated scan, or an invoice fraud attempt.

That is good news, because ordinary controls stop ordinary attacks. You do not need an enterprise security programme; you need six things done properly.

1. Multi-factor authentication, everywhere

The highest-return control available and usually free. Email first, then anything financial, then everything else. A stolen password stops being sufficient.

If you do nothing else this quarter, enforce multi-factor authentication on email. Email compromise is the entry point for most of the invoice fraud and impersonation that hits small businesses.

2. A password manager

Shared credentials in a spreadsheet, or the same password across services, is how one breach becomes several. A business password manager with shared vaults costs a few pounds per user and removes the problem.

It also solves offboarding partially: rotate the shared credentials when someone leaves rather than trying to remember which they knew.

3. Updates on a schedule

Operating systems, browsers, phones, servers, website software. Automate what can be automated and schedule the rest monthly. Unpatched software is how automated attacks succeed.

This includes the website: an unmaintained content management system is the most common route into a small business's web presence.

4. Backups you have restored

  • Everything critical covered, including cloud services people assume are backed up
  • One copy somewhere separate from the primary system
  • Retention long enough to survive a problem found weeks later
  • An actual restore performed at least annually

Ransomware turns from a catastrophe into an expensive inconvenience if backups work. Untested backups routinely turn out not to.

5. Offboarding that actually removes access

List every system someone had access to and remove it the day they leave. Automate it if you can; use a written checklist if you cannot.

Check today: pick someone who left six months ago and see whether every account is closed. In most businesses without an automated process, at least one is not.

6. A payment verification rule

Any change to supplier bank details, and any unusual payment request, is verified by phone to a known number — never a number in the email requesting it.

This single rule prevents the most common financially damaging attack on small businesses, and it costs nothing but a policy and the discipline to follow it.

Frequently asked questions

Do we need cyber insurance?

It is increasingly common and increasingly conditional — insurers now ask about the controls above, and cover can depend on having them. Worth reading the requirements before an incident rather than after.

What about Cyber Essentials?

It is a reasonable framework covering broadly these areas, and certification is sometimes required to win contracts. Even if you do not certify, the checklist is a good structure.

How much should we spend on security?

Most of the six above cost little beyond attention. Spend on tooling only after they are all genuinely in place, because expensive tools on top of missing basics is a common and ineffective pattern.

Who should own this in a small business?

Someone named, with time allocated. Security that belongs to everyone belongs to nobody, which is how quarterly checks stop happening.

Keep reading

Not sure whether the basics are covered?

Run the six checks. If any answer is uncertain, that is where to start — and we are happy to help you work through them.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

SaaS DevelopmentCustom Software Development