Many small businesses assume attackers are only interested in large corporations. In reality, smaller organisations are often targeted precisely because their defences are weaker. The good news: a handful of basics stops most common attacks.
Use strong passwords and multi-factor authentication
Turn on multi-factor authentication (MFA) for email, banking and cloud accounts. It blocks the vast majority of account takeover attempts – even if a password is stolen.
Keep systems updated
Enable automatic updates for operating systems, browsers and business software. Many successful attacks exploit vulnerabilities that already had a fix available.
Protect every device
Install reputable antivirus or endpoint protection on all computers, and make sure it is actually running and updating.
Back up – and test your backups
Ransomware is far less damaging when you can restore your data. Keep regular backups, including one copy off-site or offline, and test restoring them.
Train your people
Most incidents start with a convincing email. Short, regular awareness training helps staff spot phishing and report it before damage is done.