Skip to content

Cybersecurity Basics for Small Businesses

Seven practical habits, from multi-factor authentication to 3-2-1 backups, that block most attacks on small businesses.

8 min readFoundationsLesson 3 of 15

You do not need an IT department to be a hard target. Most attacks on small businesses are not clever. They rely on a reused password, a missing update, or an employee clicking a convincing link.

Criminals look for easy wins. A few habits, set up once and kept up, move your business out of the easy pile.

Seven habits that stop most attacks

  1. 1

    Turn on multi-factor authentication (MFA)

    MFA asks for a second proof, like a code from an app, after your password. Start with email, banking, payroll, and your payment processor. An authenticator app or security key is stronger than a text message code.

  2. 2

    Use a password manager

    A password manager creates and stores a long, unique password for every account, so one leaked password cannot unlock everything. Business versions let you share logins with staff safely and remove access when someone leaves.

  3. 3

    Keep everything updated

    Updates patch the holes attackers use. Turn on automatic updates for computers, phones, browsers, routers, and your point-of-sale system. Replace devices that no longer get security updates.

  4. 4

    Back up with the 3-2-1 rule

    Keep three copies of important data, on two different types of storage, with one copy offsite or offline. An offline or locked copy is your best defense against ransomware. Test a restore a few times a year.

  5. 5

    Train for phishing

    Phishing emails and texts pretend to be someone you trust to steal logins or money. Teach everyone to pause on urgency, check the sender, and report anything odd. Make it safe to say "I clicked something."

  6. 6

    Lock down your Wi-Fi

    Change the router's default admin password, use WPA3 or WPA2 encryption, and put customers on a separate guest network so they never share a network with your registers or office computers.

  7. 7

    Protect payment card data

    Use a reputable processor and modern card terminals that encrypt card data. Never write down or store full card numbers, and never take card details by email. Your processor can explain your PCI compliance steps.

Start with your email

Your email account is the master key: it can reset almost every other password. If you only do one thing today, turn on MFA for email.

Myth or fact? Tap to flip

Owner story

Andre, owner of a three-location auto repair business in Columbus
Andre's front desk computer was hit with ransomware on a Monday morning. Every scheduling file was locked. Because his shop manager kept a nightly backup on an external drive that was unplugged after each run, they restored everything by noon and never considered paying the ransom. The next week Andre turned on MFA for every staff email account.

Illustrative composite, not a real customer.

Have a plan for a bad day

Write down who to call if something goes wrong: your bank, your IT help, your payment processor, and your insurer if you carry cyber coverage (see Business Insurance 101). Disconnecting an infected device from the network quickly can limit the damage. Keep this list on paper too, since your computer may be the thing that is down.

Cybersecurity and fraud prevention overlap. Many attacks end with a fake payment request, so pair these habits with the controls in Protecting Your Business From Fraud and Scams.

Quick check

Which backup setup best protects you from ransomware?

Words to know

MFA
Multi-factor authentication: a second proof of identity beyond your password.
Phishing
Fake messages that impersonate trusted senders to steal logins or money.
Ransomware
Malicious software that locks your files and demands payment to unlock them.
PCI DSS
Security standards for any business that accepts payment cards.

Finished reading?

Track your progress through Stage 6: Protect & Plan.