Cybersecurity Basics for Small Businesses: 7 Steps to Start With

7 low-cost cybersecurity steps that stop the most common attacks on small businesses, based on UK NCSC and US CISA guidance.

By

·

Most attacks on small businesses rely on stolen passwords, fake emails and software that was never updated. A few basic controls block a large share of them, and most cost little or nothing.

These 7 steps follow the advice in the UK National Cyber Security Centre’s Small Business Guide and the US CISA guidance on multi-factor authentication.

The 7 steps at a glance

StepEffortCost
Turn on multi-factor authenticationLowUsually free
Use a password managerLowFree to low
Keep software and devices updatedLowFree
Back up important dataMediumLow
Train staff to spot phishingMediumFree to low
Limit admin accessLowFree
Have a simple incident planLowFree

1. Turn on multi-factor authentication

Multi-factor authentication (MFA) asks for a second proof of identity, such as a code from an app, when someone logs in. CISA says users who enable MFA are significantly less likely to get hacked. Start with email, banking and admin accounts.

2. Use a password manager

A password manager creates and stores a strong, unique password for every account. It stops one leaked password from opening all your other accounts. Our guide to password managers and MFA explains how to roll both out.

3. Keep software and devices updated

Updates fix security holes that attackers already know about. Turn on automatic updates for operating systems, browsers, apps, and your website plugins and themes.

4. Back up important data

Keep regular backups of important files and your website, with at least one copy stored separately from your main systems. Test that you can restore from a backup. A backup you can’t restore doesn’t help after a ransomware attack.

5. Train staff to spot phishing

Phishing emails trick people into clicking links, opening files or sharing passwords. Short, regular training works better than a single yearly session. Share our guide on how to spot a phishing email with your team.

6. Limit admin access

Give admin rights only to people who need them, and use separate admin accounts for admin work. Remove access as soon as someone leaves.

7. Plan what to do if something goes wrong

Write down who to call, which passwords to change and how to restore from backup. In the UK, you can report cyber crime to Action Fraud.

Start with step 1 this week. It gives the biggest protection for the least effort. More guides are in the Cybersecurity section.

Kandy Christopher Avatar

Questions? Contact us or chat on WhatsApp.

Keep reading