Business Technology · guide
Cybersecurity for Businesses Without an IT Department
Seven measures that stop the attacks small businesses actually experience, in the order worth doing them.
Small businesses are rarely targeted individually. They are caught by automated attacks and by invoice fraud, which means the defences that matter are unglamorous and cheap. Nearly all of the following can be done in a week without specialist help.
In priority order
- Turn on multi-factor authentication for email first, then banking, then accounting and your domain registrar. Email is the master key — whoever controls it can reset everything else.
- Use a password manager for the whole team so that reused passwords stop being the weak link.
- Set up automatic backups with one copy off-site, then restore a file to prove the backup works. An untested backup is a hope.
- Enable automatic operating system and browser updates on every device, including phones.
- Agree a payment verification rule: any change to bank details is confirmed by phone to a known number, no exceptions, no matter how urgent the email sounds.
- Remove admin rights from day-to-day user accounts and keep a separate administrator login.
- Keep a written list of accounts, who has access and what happens if a key person is unavailable.
The fraud that actually costs money
Business email compromise — a convincing message asking you to pay a changed account number — costs small firms more than dramatic ransomware. The phone-verification rule above is the single highest-return control in this list, and it is free.
Backups: the 3-2-1 rule, simplified
| Copies | Where | Checked |
|---|---|---|
| Working copy | The device or cloud service you use daily | Continuously |
| Second copy | Automated cloud backup with version history | Monthly restore test |
| Third copy | Off-site or offline drive, rotated | Quarterly |
What you do not need to buy yet
- Enterprise security suites sold on fear rather than a stated threat.
- Penetration testing before you have MFA and backups in place.
- A dedicated firewall appliance for a five-person office using cloud services.
Write the one-page incident plan
Decide now, on paper: who is called first, which accounts get locked, where the backups live, how customers are told, and your insurer's claims number. In an incident you will not be thinking clearly, and the plan is what replaces clear thinking. Review it once a year alongside your insurance renewal.
None of this makes you invulnerable. It does move you out of the group that automated attacks succeed against, which is the realistic goal.
Read next
Automation That Is Worth Setting Up, and Automation That Isn't
How to find the tasks worth automating, and a simple hours-saved test before you build anything.
8 min read
Card Payment Fees: Reading the Real Cost
How to compare Stripe, Square, SumUp and a traditional merchant account on the numbers that reach your bank.
9 min read