Starting a small business means building something worth protecting. That could be customer trust, online sales, invoices, appointments, employee information, or the tools that keep your doors open. Cybersecurity is not just for large companies. A successful phishing email, stolen password, failed hard drive, or ransomware infection can stop a small business cold.
The goal is not to buy every security product on the market. It is to make sure one mistake or one bad day does not become a business-ending event.
Here are the security fundamentals I would put in place early.
1. Make backups your first recovery plan
Backups are what let you recover when prevention fails. They protect against ransomware, accidental deletion, failed hardware, and mistakes during an update. A cloud sync folder alone is not a complete backup: if a file is encrypted, deleted, or corrupted, that change can sync everywhere.
Use the 3-2-1 rule:
- Keep three copies of important data.
- Store them on two different types of storage.
- Keep one copy offsite and off the normal network.
For a small business, that often means production data, a local backup, and a protected cloud or physically disconnected copy. The off-network copy matters. If ransomware can reach it using the same network and the same administrator credentials, it may encrypt the backup too.
An easy local backup option: a NAS
A network-attached storage (NAS) device can be a practical way to keep a local backup and restore files quickly after accidental deletion or a computer failure. This NAS is one option to consider (paid link).
Do not treat a NAS connected to the same network as your only backup or as your off-network copy. If malware reaches the network and can use the same credentials, it may be able to damage files on the NAS too. Use it as one layer: protect its administrator account with MFA where available, use a separate backup account, enable snapshots or immutable backups if supported, and replicate critical data to a separate offsite destination.
Disclosure: As an Amazon Associate I earn from qualifying purchases.
What to back up:
- Accounting and payroll data
- Customer files and documents
- Shared drives and line-of-business applications
- Website files and database
- Microsoft 365 or Google Workspace data
- Network-device and firewall configurations
- Password-manager emergency access and recovery information
Backups only count if you can restore them. At least quarterly, restore a few files and test a full recovery of one important system or service. Record how long it took, who performed it, and what was missing. That tells you whether your recovery plan is real.
A useful question to ask: “If every computer was encrypted this morning, what would we restore first, and where would we get the clean copy?”
2. Require multi-factor authentication, especially for the accounts that matter most
Multi-factor authentication (MFA) is one of the highest-value security controls a small business can deploy. A stolen password should not be enough to access email, banking, cloud storage, payroll, or an administrator account.
Start with these accounts:
- Email and Microsoft 365 / Google Workspace
- Domain registrar and DNS provider
- Banking, payroll, and payment processors
- Accounting and point-of-sale systems
- Password manager
- Remote-access and VPN accounts
- Website-hosting and social-media accounts
- Every administrator account
But MFA needs to be implemented correctly. Avoid making SMS text messages the only option where stronger methods are available. Prefer an authenticator app, hardware security key, passkey, or other phishing-resistant method. Protect the backup codes too: store them in a secure password manager or another controlled location, not in an unprotected email inbox or desk drawer.
For administrator accounts, do not let a daily-use account be the only account with powerful access. Use a separate admin account, require strong MFA, and keep at least two trusted people with documented recovery access so a single lost phone does not lock the business out.
3. Use a password manager and stop sharing passwords
Shared passwords turn normal employee turnover into a security problem. A password manager gives each person their own access, allows strong unique passwords, and lets you remove access immediately when someone leaves.
Every important account should have a different password. Reusing a password means a breach at an unrelated website can become a breach of your business email or banking account.
Set a simple rule: no passwords in email, text messages, spreadsheets, sticky notes, or shared browser profiles.
4. Protect email because it is usually the front door
Phishing is still one of the easiest ways to steal credentials, deliver malware, or redirect payments. AI has made it easier for criminals to produce convincing messages, but the basic warning signs have not disappeared: urgency, unexpected login links, invoice changes, gift-card requests, and requests to bypass normal approval steps.
Train employees to pause before signing in, opening an attachment, or changing payment information. For money movement or bank-detail changes, require a second verification through a known phone number or another independent method. Do not call a number included in the suspicious email.
If you use a custom business domain, configure SPF, DKIM, and DMARC. These records help receiving mail systems verify that messages claiming to be from your domain are legitimate and reduce impersonation of your business.
Use the IT Knowledge Bases tools when a message looks suspicious:
- Phishing URL Scanner — inspect a suspicious destination before anyone logs in or downloads something.
- Safe Link Decoder — see the underlying destination inside a Microsoft Safe Links URL in your browser.
- DNS Lookup and RDAP Lookup — investigate unfamiliar domains and registration details.
These tools support investigation. They do not replace verification, email security, or a decision to avoid entering credentials on an unexpected page.
5. Keep systems, browsers, plugins, and network equipment updated
Attackers routinely exploit known weaknesses in old software. Turn on automatic updates where sensible and establish a regular patching routine for:
- Windows and macOS devices
- Browsers and browser extensions
- Microsoft 365 desktop applications
- Firewalls, routers, switches, and Wi-Fi access points
- Website platforms, themes, and plugins
- Point-of-sale, accounting, and remote-support tools
Prioritize internet-facing systems and actively exploited vulnerabilities. Before updating a critical system, confirm that you have a usable backup and know how to roll back or get support if the update causes trouble.
6. Separate business systems from guest and personal devices
Your business Wi-Fi should not be the same network used by guests, smart TVs, personal phones, cameras, or random Internet-of-Things devices. A separate guest Wi-Fi network is an easy first step. More mature setups separate office computers, servers, cameras, and payment devices into their own network segments.
Change default passwords on network equipment, disable remote management from the internet unless it is truly needed, and keep a current list of the devices connected to the network. If you cannot identify a device, investigate it.
7. Secure every device that touches business data
Laptops and phones are portable copies of business information. Require screen locks, full-disk encryption, supported operating systems, and a way to remotely remove company data from a lost device when possible.
Use reputable endpoint protection on business computers. More importantly, make sure alerts are reviewed and someone is responsible for acting on them. Security software that nobody watches becomes an expensive checkbox.
8. Give people only the access they need
Most employees do not need local administrator rights, access to every shared folder, or permission to change financial information. Limit access based on the job. This reduces the damage from a compromised account and makes it easier to manage offboarding.
When an employee, contractor, or vendor leaves, immediately remove their access to email, shared folders, VPN, business apps, password vaults, and physical systems. Do not wait for the next billing cycle or hope they no longer know the password.
Also review who has access at least a couple of times each year. Small businesses frequently discover old accounts, former vendors, and unnecessary admin rights only after an incident.
9. Have a short, written incident plan
You do not need a 100-page policy. You need people to know what to do in the first hour.
Write down:
- Who has authority to take a system offline or disable an account.
- Who calls your IT provider, cyber-insurance carrier, bank, and legal counsel.
- Where the recovery instructions, administrator contacts, MFA recovery methods, and backup details are stored.
- How you will communicate if email and phones are unavailable.
- What should be preserved for investigation before systems are wiped or rebuilt.
Keep a printed copy or a protected offline copy. An incident plan stored only in the email system you cannot access is not much of a plan.
10. Protect payments and vendor changes with a second check
Business email compromise often targets invoices, payroll, and bank-account changes rather than trying to deploy malware. Establish a rule that any new payment destination, wire transfer, direct-deposit change, or urgent purchase needs independent verification.
This is one area where process beats technology. A two-minute phone call to a verified number can prevent a major loss.
11. Know your critical services and their recovery order
Make a one-page list of the systems that keep the business operating: email, point-of-sale, file storage, phones, accounting, website, scheduling, inventory, and payroll. For each one, list the owner, vendor support number, login location, MFA/recovery method, backup status, and the acceptable downtime.
That list will make a disaster much less chaotic. It also exposes weak spots before an attacker does.
Start here: the small-business security checklist
Do not try to complete every security project at once. Start with the items below, check them off, and build from there.
Do these first
- Turn on multi-factor authentication for your business email.
- Turn on MFA for your domain registrar, website hosting, banking, payroll, and payment accounts.
- Save backup codes in a password manager or a protected offline location.
- Use a password manager and change any shared or reused business passwords.
- Turn on automatic updates for business computers and phones.
- Confirm your important files are actually being backed up.
Make sure your backup can survive ransomware
- Identify the files and systems you could not afford to lose.
- Confirm there is a backup copy that is not continuously reachable from normal employee computers.
- Confirm the backup uses separate, protected administrator credentials.
- Restore one file from backup. Do not assume the backup works because it says “successful.”
- Write down where the backup is, who can access it, and who to call for help.
Set safer habits for everyone
- Tell employees and partners: never approve an unexpected MFA prompt.
- Require a phone call to a known number before changing bank details, payroll deposits, or payment instructions.
- Create a separate guest Wi-Fi network; do not give visitors the business network password.
- Remove access immediately when an employee or contractor leaves.
- Keep one printed or offline page with key account owners, support contacts, and recovery instructions.
Add these as the business grows
- Configure SPF, DKIM, and DMARC for your email domain.
- Use separate administrator accounts rather than doing daily work with admin rights.
- Keep an inventory of devices, software, subscriptions, and vendors with access.
- Review who has access to important accounts twice a year.
- Practice restoring a more important system or service at least once a year.
Final thought
Security is not about promising that nothing bad will happen. It is about making sure a bad link, lost laptop, ransomware infection, or account takeover does not take your business with it. Start with MFA and tested offline backups, then build the habits and controls around them. Those steps are far less expensive than trying to recover after the fact.
