Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. The Six Security Measures That Prevent Most Small Business Breaches
SaaS & Product

The Six Security Measures That Prevent Most Small Business Breaches

Six security basics that prevent most small business breaches: MFA, a password manager, scheduled updates, tested backups, offboarding and payment checks.

Updated 2 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Multi-factor authentication, a password manager, prompt updates, verified backups, offboarding that actually removes access, and a payment verification rule. Six measures, mostly cheap, covering the overwhelming majority of what actually happens to businesses your size.

You are not being targeted by anyone sophisticated

Small businesses are rarely the subject of a deliberate campaign. What happens is opportunistic: a credential reused from another breach, a phishing email, an unpatched system found by an automated scan, or an invoice fraud attempt.

That is good news, because ordinary controls stop ordinary attacks. You do not need an enterprise security programme; you need six things done properly.

1. Multi-factor authentication, everywhere

The highest-return control available and usually free. Email first, then anything financial, then everything else. A stolen password stops being sufficient.

If you do nothing else this quarter, enforce multi-factor authentication on email. Email compromise is the entry point for most of the invoice fraud and impersonation that hits small businesses.

2. A password manager

Shared credentials in a spreadsheet, or the same password across services, is how one breach becomes several. A business password manager with shared vaults costs a few pounds per user and removes the problem.

It also solves offboarding partially: rotate the shared credentials when someone leaves rather than trying to remember which they knew.

3. Updates on a schedule

Operating systems, browsers, phones, servers, website software. Automate what can be automated and schedule the rest monthly. Unpatched software is how automated attacks succeed.

This includes the website: an unmaintained content management system is the most common route into a small business's web presence.

4. Backups you have restored

  • Everything critical covered, including cloud services people assume are backed up
  • One copy somewhere separate from the primary system
  • Retention long enough to survive a problem found weeks later
  • An actual restore performed at least annually

Ransomware turns from a catastrophe into an expensive inconvenience if backups work. Untested backups routinely turn out not to.

5. Offboarding that actually removes access

List every system someone had access to and remove it the day they leave. Automate it if you can; use a written checklist if you cannot.

Check today: pick someone who left six months ago and see whether every account is closed. In most businesses without an automated process, at least one is not.

6. A payment verification rule

Any change to supplier bank details, and any unusual payment request, is verified by phone to a known number — never a number in the email requesting it.

This single rule prevents the most common financially damaging attack on small businesses, and it costs nothing but a policy and the discipline to follow it.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Do we need cyber insurance?

It is increasingly common and increasingly conditional — insurers now ask about the controls above, and cover can depend on having them. Worth reading the requirements before an incident rather than after.

What about Cyber Essentials?

It is a reasonable framework covering broadly these areas, and certification is sometimes required to win contracts. Even if you do not certify, the checklist is a good structure.

How much should we spend on security?

Most of the six above cost little beyond attention. Spend on tooling only after they are all genuinely in place, because expensive tools on top of missing basics is a common and ineffective pattern.

Who should own this in a small business?

Someone named, with time allocated. Security that belongs to everyone belongs to nobody, which is how quarterly checks stop happening.

Keep reading

More on SaaS & Product

Start here

Not sure whether the basics are covered?

Run the six checks. If any answer is uncertain, that is where to start — and we are happy to help you work through them.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →