Cybersecurity for Small Businesses Without an IT Department
Why small businesses get hit the hardest
If you run a business with fewer than 50 employees and no dedicated IT staff, you are dealing with the same threats as a large corporation but with none of the defenses. Attackers know this. Automated scanning tools don’t care how big your company is; they care whether your systems are easy to break into. A small business with default passwords and no email filtering is a faster, cheaper target than a bank with a security team.
The good news is that most of what actually protects a small business is not expensive or technical. It’s a handful of habits and settings that take a few hours to set up and almost no time to maintain.
Email compromise: the most common way in
Business email compromise is when someone gains access to (or convincingly spoofs) an email account and uses it to redirect payments, request gift cards, or trick employees into wiring money. It’s the single most common way small businesses lose real money to cybercrime, and it rarely involves anything technically sophisticated.
What to do about it
- Turn on multi-factor authentication (MFA) for every email account, especially anyone who handles payments or invoices. This alone stops the vast majority of account takeovers.
- Set up a verbal verification rule for any request to change bank details or send money, even if the email looks like it’s from your CEO or a known vendor. A phone call to a known number takes two minutes and prevents five-figure losses.
- Enable your email provider’s built-in phishing and spoofing protections (both Google Workspace and Microsoft 365 have these; they’re usually off by default or set to “warn” instead of “block”).
- Train staff to hover over sender addresses, not just display names. “John Smith” can display correctly while the actual address is a random string at a lookalike domain.
Ransomware: assume it can happen, plan for it
Ransomware locks your files and demands payment to unlock them. Small businesses are attractive targets because they’re less likely to have backups and more likely to pay quickly to get back to work.
The core defense: real backups
A real backup means three things:
- Automatic. Not something a person has to remember to do.
- Offsite or disconnected. If the backup is on a drive plugged into the infected computer, ransomware can encrypt that too.
- Tested. At least twice a year, actually restore a file from the backup to confirm it works. An untested backup is a hope, not a plan.
Cloud backup services built for small businesses typically run somewhere in the range of $5 to $15 per device per month. That is far cheaper than a ransom payment, and unlike a ransom payment, it actually guarantees you get your data back.
Reduce your exposure
- Keep operating systems and software updated. Most ransomware exploits known vulnerabilities that already have patches available.
- Limit who has administrator access on company computers. Day-to-day work should happen from a standard user account, not an admin account.
- Disable macros in email attachments by default. This single setting blocks a large share of common ransomware delivery methods.
Password infrastructure that doesn’t rely on memory
“Use a strong password” is advice nobody can actually follow at scale. The real fix is infrastructure, not willpower.
What actually works
- A password manager for the whole team. Business plans for password managers usually cost a few dollars per user per month. Every account gets a long, random, unique password that nobody has to remember or type.
- MFA everywhere it’s offered, not just email. Banking, payroll, cloud storage, and any admin panel should have it turned on.
- A shared vault for business logins instead of a spreadsheet, sticky note, or one person’s memory. When someone leaves the company, you can revoke their access instantly instead of scrambling to change every password by hand.
A single reused password on a low-value account can be the thread that unravels everything if that account gets breached elsewhere and the same credentials work on your email or bank login.
Vendor security: your risk doesn’t stop at your door
Small businesses often connect their systems to dozens of vendors: payment processors, scheduling tools, marketing platforms, accountants, contractors with remote access. Each one is a potential entry point.
A basic vendor checklist
- Before signing up for a new tool, check whether it offers MFA and whether it’s on by default.
- Review which vendors have access to your systems every six months or so, and remove access for anyone or anything you no longer use.
- Ask vendors handling sensitive data (payments, customer records, health information) whether they carry cyber insurance and what their breach notification process looks like. A vendor that can’t answer this clearly is a risk signal.
- Never share admin credentials directly with a contractor. Create a separate account for them and remove it when the work is done.
Employee training that people actually retain
Long annual security trainings tend to be forgotten within a week. Short, frequent, low-pressure reminders work better.
A realistic training approach
- Spend fifteen minutes at onboarding covering the three or four things that matter most: MFA, phishing red flags, and who to tell if something looks wrong.
- Send a short reminder every quarter rather than one long session per year. Repetition beats duration.
- Make it normal, not shameful, to report a mistake. If someone clicks a bad link, the priority is finding out fast, not punishing them. Fear of blame is why security incidents get hidden until they’re worse.
- Use real, recent examples relevant to your industry rather than generic scare stories. Specific and current lands better than dramatic and abstract.
Incident response: what to do in the first hour
Even with good defenses, something will eventually go wrong. Having a simple plan written down before that happens changes the outcome dramatically.
A minimal incident response plan
- Disconnect, don’t panic. If a computer is showing signs of ransomware or compromise, disconnect it from the network (unplug ethernet, turn off Wi-Fi) rather than shutting it down, which can complicate recovery.
- Know who to call. Write down, in advance, who handles IT questions (even if that’s an outside contractor), who handles legal or compliance questions, and who handles customer communication. Trying to figure this out during an actual incident wastes critical time.
- Preserve evidence. Don’t wipe or reformat a compromised device before someone has looked at it, if you plan to investigate what happened.
- Communicate honestly. If customer data may have been affected, plan for direct, factual notification rather than delay. Delayed or vague communication tends to cause more damage to trust than the incident itself.
- Do a short post-incident review. Once things are stable, spend thirty minutes asking what allowed it to happen and what one or two changes would prevent it next time.
Where to start this week
If none of this is in place yet, don’t try to do it all at once. In order of impact for the time invested:
- Turn on MFA for email, banking, and any admin accounts.
- Set up automatic, tested backups.
- Roll out a password manager for the team.
- Write a one-page incident response plan with names and phone numbers.
None of this requires an IT department. It requires about a day of setup and a habit of checking in on it a few times a year. Small, consistent steps close most of the gap that makes small businesses an easy target.
For the complete, structured playbook on this topic, see Small Business Cybersecurity: Protecting Your Company Without an IT Team in our library. New here? Start with our free guide.