5 min read
A small-business security baseline you can set up this week
You do not need an enterprise budget to stop the most common attacks. These basics, spread over five working days, close the doors attackers try first.
LoneLupus TeamLoneLupus Technologies
On this page7 sections
Small businesses often assume they are too small to interest attackers. In reality, much cybercrime is automated and opportunistic. Attackers try stolen passwords, send phishing emails in bulk and scan for unpatched systems, and they do not check your turnover first. The good news is that a short list of basics blunts the most common of these attempts, and none of them needs specialist tools.
Here is a baseline you can put in place over one working week. Take one theme per day.
Day 1: lock down your accounts
Many break-ins begin with a password, so start there.
- Use a password manager. It creates and stores a long, unique password for every account, so one leaked password cannot open the rest.
- Turn on multi-factor authentication (MFA). Begin with email, banking, accounting, cloud storage, your domain registrar and social media. An authenticator app, a passkey or a hardware key is stronger than SMS codes, but SMS is far better than nothing.
- Protect email above all. Whoever controls your inbox can reset the passwords to almost everything else.
- Stop sharing logins. Give each person their own account, so you can see who did what and remove access cleanly.
Day 2: update and protect your devices
- Turn on automatic updates for operating systems, browsers and apps on every laptop and phone. Updates fix the holes that automated attacks look for.
- Replace software and devices that no longer receive security updates.
- Switch on full-disk encryption: BitLocker or Device Encryption on Windows, FileVault on Mac. Modern phones encrypt their storage once a passcode is set.
- Require a screen lock with a short timeout on every device.
- Keep built-in protection, such as Microsoft Defender, switched on.
- Use standard user accounts for daily work and keep administrator rights for the moments they are needed.
Day 3: back up, then prove you can restore
Backups are your safety net against ransomware, theft, hardware failure and honest mistakes. The classic guide is the 3-2-1 rule: keep three copies of important data, on two different types of storage, with one copy off-site or in the cloud.
Remember that file-sync tools are not backups by themselves. If a file is encrypted or deleted on one device, the change can sync everywhere. Choose a backup that keeps previous versions, and keep at least one copy that an infected computer cannot reach.
Day 4: secure email, Wi-Fi and payments
Email and your domain
Ask whoever manages your domain to set up SPF, DKIM and DMARC. These DNS records help receiving mail servers confirm that a message claiming to come from your domain really did, which makes it harder for criminals to impersonate you. Start DMARC in monitoring mode, check the reports, then move the policy to quarantine or reject. Only an enforcing policy stops spoofed messages being delivered.
The office network
- Change the router's default admin password and update its firmware.
- Use WPA2 or WPA3 with a strong Wi-Fi password.
- Put visitors and smart devices on a separate guest network.
- Turn off remote administration unless you truly need it.
A payment rule that costs nothing
Invoice fraud works by impersonating a supplier or a manager and asking for an urgent payment or a change of bank details. Make it a firm rule that any such request is confirmed by calling a number you already have on file, never the one in the message. Tell your team they will never be in trouble for slowing down to check.
Day 5: tidy up access and write the plan
- List who has access to what, and remove anything that is no longer needed. People should have the access their role requires and no more.
- Create a leaver checklist: disable accounts, recover devices, change any shared credentials and transfer ownership of files.
- Review which third-party apps are connected to your email and cloud accounts, and remove the ones you do not recognise.
- Write a one-page incident plan: who to call, how to disconnect an affected device, where the backups are and who talks to customers. Print a copy, because you may not be able to open it on a locked computer.
Make it a habit
Security is not a one-week project, but after this week the ongoing work is light. Hold a short conversation with your team about spotting phishing: unexpected urgency, mismatched sender addresses, links that lead somewhere odd and requests to bypass a normal process. Encourage people to report a suspicious message or a mistaken click straight away. Early reports limit damage. Blame makes people hide things.
Then set a quarterly reminder to review accounts, test a restore and check that updates are still switched on.
When to bring in help
This baseline will not make you invulnerable, and nothing will. What it does is remove the easy openings, so that an opportunistic attacker moves on. If you handle sensitive customer data, work in a regulated industry, run your own servers or simply lack the time, it is worth having a specialist assess your setup and monitor it for you.
Either way, start with the basics above. They are what any good security partner would ask about first. Guard the perimeter well and the rest of your work gets calmer.