Skip to content
Business Resource HubPractical guides for small businesses

Business Technology · guide

Cybersecurity for Businesses Without an IT Department

Seven measures that stop the attacks small businesses actually experience, in the order worth doing them.

By Business Resource Hub EditorialPublished Updated 10 min read

Small businesses are rarely targeted individually. They are caught by automated attacks and by invoice fraud, which means the defences that matter are unglamorous and cheap. Nearly all of the following can be done in a week without specialist help.

In priority order

  1. Turn on multi-factor authentication for email first, then banking, then accounting and your domain registrar. Email is the master key — whoever controls it can reset everything else.
  2. Use a password manager for the whole team so that reused passwords stop being the weak link.
  3. Set up automatic backups with one copy off-site, then restore a file to prove the backup works. An untested backup is a hope.
  4. Enable automatic operating system and browser updates on every device, including phones.
  5. Agree a payment verification rule: any change to bank details is confirmed by phone to a known number, no exceptions, no matter how urgent the email sounds.
  6. Remove admin rights from day-to-day user accounts and keep a separate administrator login.
  7. Keep a written list of accounts, who has access and what happens if a key person is unavailable.

The fraud that actually costs money

Business email compromise — a convincing message asking you to pay a changed account number — costs small firms more than dramatic ransomware. The phone-verification rule above is the single highest-return control in this list, and it is free.

Backups: the 3-2-1 rule, simplified

CopiesWhereChecked
Working copyThe device or cloud service you use dailyContinuously
Second copyAutomated cloud backup with version historyMonthly restore test
Third copyOff-site or offline drive, rotatedQuarterly

What you do not need to buy yet

  • Enterprise security suites sold on fear rather than a stated threat.
  • Penetration testing before you have MFA and backups in place.
  • A dedicated firewall appliance for a five-person office using cloud services.

Write the one-page incident plan

Decide now, on paper: who is called first, which accounts get locked, where the backups live, how customers are told, and your insurer's claims number. In an incident you will not be thinking clearly, and the plan is what replaces clear thinking. Review it once a year alongside your insurance renewal.

None of this makes you invulnerable. It does move you out of the group that automated attacks succeed against, which is the realistic goal.

Topics

  • security
  • backups
  • risk

This guide is general information, not accounting, legal or financial advice. Figures are illustrative and were last reviewed on 18 August 2026. Spotted something out of date? Tell us and we will correct it.