Small Business Cybersecurity: What to Actually Fix First
Why small businesses are a target, not an afterthought
There’s a common assumption that cybercriminals only go after large companies with valuable data and deep pockets. In reality, small businesses are often preferred targets. Attackers know that a five-person accounting firm or a local retail shop is far less likely to have dedicated IT staff, tested backups, or a written response plan. Weaker defenses mean faster, easier payouts, whether through stolen customer data, ransomware, or a hijacked email account used to defraud a client.
The good news is that meaningful security doesn’t require an enterprise budget or a full-time security hire. Most of what actually stops attacks is a handful of specific habits and settings, done consistently. Below is a practical rundown, organized in the order it usually pays off to tackle it.
Start with account security
Almost every serious breach at a small business traces back to a compromised account, not a sophisticated technical exploit. Fixing this first gives you the most protection for the least effort.
Turn on multi-factor authentication everywhere it’s offered
Email, banking, payroll, cloud storage, and any software that touches customer data should all require a second step to log in, not just a password. Use an authenticator app rather than SMS text codes where possible, since text messages can be intercepted more easily.
Get rid of shared logins
If your team logs into a shared email inbox, a shared social media account, or a shared admin panel using one password everyone knows, that’s a single point of failure. When someone leaves the company, changing that password becomes a scramble, and in the meantime former employees or anyone who ever saw it retains access. Give each person their own login wherever the software allows it, and use a password manager to make individual accounts practical.
Adopt a password manager
The reason people reuse passwords is that remembering dozens of unique ones is genuinely hard. A password manager solves this by generating and storing strong, unique passwords for every account. This one habit closes off one of the most common ways accounts get compromised: credential stuffing, where attackers try passwords stolen from one breached site on other services.
Lock down the devices your team actually uses
Laptops, phones, and tablets are where data lives day to day, and they’re frequently the weakest link because they leave the office.
Require screen locks and encryption
Every device that touches business data should lock automatically after a short period of inactivity and require a PIN, password, or biometric to unlock. Modern laptops and phones almost all support full-disk encryption, and it’s usually a free setting, not an add-on. Turn it on. If a laptop is stolen, encryption is the difference between a lost asset and a data breach.
Keep software updated
Operating system and application updates frequently patch security flaws that are actively being exploited. Set devices to update automatically where possible. If your team uses personal devices for work, at minimum confirm those devices are current before they’re allowed to access company accounts.
Have a plan for lost or stolen devices
Know, in advance, how you would remotely lock or wipe a company phone or laptop if it went missing. Most business email and file-storage platforms include this capability, but it’s only useful if you’ve already set it up and know how to trigger it under stress.
Treat email as your biggest attack surface
Email remains the most common way attackers get a foothold, whether through phishing links, fake invoices, or messages that impersonate a vendor or executive.
Enable spam and phishing filtering
Most business email platforms include filtering tools that are turned off or set too loosely by default. Review these settings and tighten them, particularly for external senders and attachments.
Set up domain authentication
Technical settings called SPF, DKIM, and DMARC make it much harder for someone to send email that appears to come from your domain. If you don’t know whether these are configured, ask whoever manages your email hosting or domain registrar. This is a one-time setup that pays off indefinitely.
Train your team to slow down
Most phishing succeeds because someone is moving fast and doesn’t stop to check a sender address or hover over a link. A simple habit helps: before acting on any email that requests a payment, a password, or a change to account details, verify it through a second channel, like a phone call to a known number, especially if the request feels urgent.
Back up your data like you expect to need it
Backups are the difference between a bad day and a business-ending event when ransomware or hardware failure hits.
Follow the basic rule of three
Keep at least three copies of important data, on two different types of storage, with one copy stored somewhere physically separate (including cloud storage). If your only backup is a hard drive sitting next to the computer it’s backing up, a fire, theft, or ransomware infection can take out both at once.
Actually test your restores
A backup you’ve never tried to restore from is a guess, not a safety net. Periodically pick a file or folder and confirm you can actually get it back from your backup system. This takes a few minutes and catches problems long before you need the backup for real.
Watch out for backups that sync everything, including infections
Some cloud backup tools sync in real time, which means if a file gets encrypted by ransomware, the infected version can overwrite your clean backup. Look for a backup solution that keeps version history, so you can roll back to a point before the damage happened.
Write down what happens if something goes wrong
Most small businesses have no incident plan at all, which means the first time anyone thinks about what to do during a breach is during the breach itself, which is the worst possible time to make decisions.
Keep it short and specific
An incident plan doesn’t need to be a formal document. A single page listing who to call, what accounts to lock down first, and where backups are stored is enough to save critical time.
Know who you’d call
Identify in advance an IT contact, a lawyer familiar with data breach obligations in your area, and your cyber insurance provider if you have one. Trying to find these contacts while systems are down wastes time you don’t have.
Practice it once
Even a short conversation with your team about what everyone would do if email got compromised tomorrow surfaces gaps you won’t otherwise notice, like nobody knowing where the backup drive actually is.
Where to start this week
If all of this feels like a lot, pick one item and do it today: turn on multi-factor authentication for your email account. It takes about ten minutes and closes off the single most common way small businesses get breached. Then work through the rest in order, account security first, then devices, then email, then backups, then the incident plan. None of it requires a big budget. It requires doing the basics consistently, which is exactly what most attackers are counting on you not to do.
For the complete, structured playbook on this topic, see Small Business Security Checklist in our library. New here? Start with our free guide.