Technology · medium risk
Small-business cyber security basics
Prioritise multi-factor authentication, updates, backups, access control and recovery before buying complex tools.
Start with the failures that stop the business
For a small business, the biggest gains often come from protecting email, keeping devices updated, controlling access and knowing how to recover.
Do this now
- Turn on multi-factor authentication for email, banking, cloud storage, website administration and accounting.
- Use supported devices and automatic security updates.
- Use a password manager and unique passwords rather than a shared spreadsheet or repeated password.
- Back up essential data separately and test that a file can be restored.
- Give each person their own account and only the access they need.
- Write a one-page response card: who to contact, how to secure accounts, how to warn customers and where clean backups are kept.
- Check supplier access and remove accounts promptly when someone leaves.
What good looks like
One lost phone or compromised password does not give access to the whole business. Important systems have more than one trusted recovery route, and the owner can restore essential data without depending on the affected account.
Common mistakes
- Securing banking but leaving the email account weak.
- Sharing one administrator login across the team.
- Assuming cloud storage is automatically a tested backup.
- Buying a security product without assigning updates, alerts and recovery.
When to get help
Use a reputable cyber professional if you handle sensitive or regulated data, rely heavily on connected systems, have suffered an incident or cannot verify your backups and access controls.
Keep in your roadmap
Record the owner of each critical account, MFA status, last access review, backup test date and incident contact.
