Cyber security for a small business: where to start

By OpsinelPublished 5 min read

Short answer: Start a small business’s cyber security with the measures that cost least and stop the most common attacks: two-factor authentication, separate passwords, updates, backups, a rule for checking payments and training employees to spot phishing. Most of these steps need neither a security specialist nor a large budget.

Small businesses often assume they are too small to interest scammers. But most attacks do not pick their victims by size: the same fake invoice or password-stealing page is sent to thousands of companies at once. A small business is simply less likely to have someone who stops it.

Below are eight steps in order, starting with the ones that cost least and protect against the most common threats.

1. Turn on two-factor authentication

Start with email (Microsoft 365 or Google Workspace), the bank, the accounting software and the account that manages your domain. Even if a password is stolen, nobody can sign in with it without the second step. It is free and takes a few minutes per account. More: Two-factor authentication (2FA).

2. Agree how you handle passwords

A separate password for every account, not one for all of them. The easiest way is a password manager: it also lets you share team accounts safely instead of sending passwords in chat messages or keeping them in a spreadsheet. More: How to create a strong password.

3. Keep devices and software up to date

Turn on automatic updates for the operating system, the browser and applications on every work computer and phone. Many attacks exploit holes that have already been fixed, on devices that were never updated.

4. Back up and test the backups

Your most important files and the accounts need a copy that a computer infected with ransomware cannot change or delete. Once a quarter, try restoring at least one file: a backup nobody has restored from may not work. More: Ransomware: how to protect your business.

5. Introduce a rule for checking payments

For small businesses the costliest incidents are often not viruses but fake invoices and “CEO” requests for an urgent transfer. One rule stops most of them: always confirm changed supplier bank details and unusual payments by calling a number you already know, not the one in the email. More: CEO fraud and invoice fraud.

6. Protect your company’s email domain

SPF, DKIM and DMARC records on your domain help mail systems recognise emails that scammers send in your company’s name. They are set up once, usually by your IT provider or whoever manages your domain. You can see where your domain stands with the free SPF, DKIM and DMARC checker; how the records work is explained in Email spoofing: how scammers send email in your name.

7. Teach employees to spot phishing

Technical measures do not stop everything. An email that gets past the filters only stops when an employee recognises it. The most effective approach combines short training with safe phishing simulations: employees receive a realistic email and, if they click, learn straight away what they should have noticed.

How to organise this is covered in How to train employees to spot scams. How to check whether your team spots phishing is explained in Phishing test for employees.

8. Agree what to do if something happens

Write one page: whom an employee tells after clicking a suspicious link, who changes passwords, whom to call at the bank and for IT. Most importantly, people must not be afraid to report: the sooner a mistake is known, the smaller the damage. More: What to do if an employee clicked a phishing link.

What it costs

Two-factor authentication, updates, the payment rule and the response plan cost only time. The paid items are usually a password manager, backup storage and employee training. For example, Opsinel phishing simulations and training cost €30 per month for 10 employees, prices exclude VAT. You can work out the price for your team in the price calculator.

If you only get one thing done this week, turn on two-factor authentication for email. Email is where other accounts’ passwords are reset, and from a taken-over mailbox scammers send fake invoices to your customers in your name.

Try it yourself

Can scammers send email in your name?

A free SPF, DKIM and DMARC check of your domain. The domains you enter are not stored.

Could you spot a phishing email?

10 realistic emails and an explanation after each answer. About 5 minutes, no sign-up.

Take the phishing quiz

Frequently asked questions

Are small businesses really a target?

Yes. Most phishing emails are sent in bulk, without looking for a particular victim. A small business often has no IT person to notice a suspicious sign-in or email, so a mistake comes to light later.

Do we need to hire an IT security specialist?

Not for the first steps. A company can introduce two-factor authentication, a password manager, updates and the payment rule itself. For the email domain records and the backup system, the IT provider who already looks after your computers is usually enough.

How long does it take to get started?

The first five steps can be done within a few weeks without starting a separate project. Employee training and phishing simulations are ongoing: a first campaign to see where you stand, then one a month or a quarter.

Where should employee training start?

With one phishing simulation to see where you stand, and a short lesson for those who clicked. How to read the result is described in Phishing test for employees.

Sources and further reading

Public guidance from security agencies and standards bodies.

From theory to practice

A phishing simulation lets your employees practise: they get a realistic email and, if they click, a short lesson straight away. Create an account and see sample data straight away.