Most attacks on small businesses rely on stolen passwords, fake emails and software that was never updated. A few basic controls block a large share of them, and most cost little or nothing.
These 7 steps follow the advice in the UK National Cyber Security Centre’s Small Business Guide and the US CISA guidance on multi-factor authentication.
The 7 steps at a glance
| Step | Effort | Cost |
|---|---|---|
| Turn on multi-factor authentication | Low | Usually free |
| Use a password manager | Low | Free to low |
| Keep software and devices updated | Low | Free |
| Back up important data | Medium | Low |
| Train staff to spot phishing | Medium | Free to low |
| Limit admin access | Low | Free |
| Have a simple incident plan | Low | Free |
1. Turn on multi-factor authentication
Multi-factor authentication (MFA) asks for a second proof of identity, such as a code from an app, when someone logs in. CISA says users who enable MFA are significantly less likely to get hacked. Start with email, banking and admin accounts.
2. Use a password manager
A password manager creates and stores a strong, unique password for every account. It stops one leaked password from opening all your other accounts. Our guide to password managers and MFA explains how to roll both out.
3. Keep software and devices updated
Updates fix security holes that attackers already know about. Turn on automatic updates for operating systems, browsers, apps, and your website plugins and themes.
4. Back up important data
Keep regular backups of important files and your website, with at least one copy stored separately from your main systems. Test that you can restore from a backup. A backup you can’t restore doesn’t help after a ransomware attack.
5. Train staff to spot phishing
Phishing emails trick people into clicking links, opening files or sharing passwords. Short, regular training works better than a single yearly session. Share our guide on how to spot a phishing email with your team.
6. Limit admin access
Give admin rights only to people who need them, and use separate admin accounts for admin work. Remove access as soon as someone leaves.
7. Plan what to do if something goes wrong
Write down who to call, which passwords to change and how to restore from backup. In the UK, you can report cyber crime to Action Fraud.
Start with step 1 this week. It gives the biggest protection for the least effort. More guides are in the Cybersecurity section.