Home › Self-Check Guides › Cyber security basics for very small businesses
GUIDE · SMALL BUSINESS

Cyber security basics for very small businesses

What to do first when you have no IT department, a limited budget, and a business that cannot afford a week of downtime.

Last reviewed 12/09/2026 · Written and maintained by the cyberhygiene.tools team

In this guide

  • What actually happens to small businesses
  • Do these five things first
  • Then these
  • Training that works
  • Have a plan before you need one
  • A realistic order of work

What actually happens to small businesses

Small businesses are not usually targeted by name. They are caught by automated attacks that scan for whatever is reachable and weak, and by fraud that works equally well on a company of five or five thousand. That means the defences worth having are unglamorous and mostly free.

Three things cause the large majority of real losses:

Notice that none of these is a sophisticated technical attack. They are all, at root, someone getting a password or someone believing an email.

Do these five things first

1. Two-factor authentication on every business account

Email first, then accounting, banking, cloud storage, and your domain registrar. This is free, takes an afternoon across a small team, and prevents the single most common cause of loss. If you do nothing else on this page, do this.

Use an authenticator app or passkeys rather than text messages where the option exists. Keep the backup codes somewhere the business can reach if a staff member loses a phone or leaves.

2. A payment verification rule, written down

Any change to bank details on any invoice must be confirmed by phoning a number you already had on file — never a number in the email, and never by replying to it. Any payment over a threshold you set needs a second person to approve.

This single rule prevents most invoice fraud. It costs nothing, and it works precisely because it does not depend on anyone spotting a convincing fake. Write it down, tell every person who can make a payment, and make clear that following it is never something they will be criticised for, even when it turns out to be a real supplier.

3. Backups that are actually tested

Keep three copies of anything you cannot lose, on two different kinds of storage, with one of them offline or in a form that cannot be altered. Ransomware specifically seeks out connected backups, so a drive permanently plugged into the same machine is not a backup.

Then test a restore. A backup nobody has ever restored from is a hope, not a plan. Do it once now and once a year afterwards, and note how long it actually takes — that number is your real recovery time.

4. Updates on automatic

Operating systems, browsers, phones, and anything exposed to the internet — routers, firewalls, remote access, and any website software you run. Most successful intrusions use flaws that were fixed months earlier. Turn on automatic updates and stop thinking about it.

5. A password manager for the team

Business plans are inexpensive and solve several problems at once: no shared passwords in spreadsheets or chat, unique credentials everywhere, and — importantly — the ability to revoke access instantly when someone leaves. That last point alone justifies it.

Then these

Training that works

Annual compliance slideshows achieve very little. What works is short, specific and repeated. Fifteen minutes every couple of months on one real thing — a phishing email that actually reached your team, a supplier fraud attempt, a new scam in your industry — sticks far better than an hour once a year.

The most important cultural point is this: staff must never be punished for reporting a mistake. The expensive scenario is not someone clicking a link. It is someone clicking a link and saying nothing for three days because they are afraid. Make reporting fast, blameless, and visibly appreciated.

Have a plan before you need one

Write one page and keep a printed copy, because the digital one may be encrypted when you need it. It should answer:

  1. Who is called first, with mobile numbers.
  2. Which systems must come back first for the business to function.
  3. Who talks to customers, and roughly what they say.
  4. Your bank's fraud line, your insurer, and your IT support.
  5. Where the backups are and who knows how to restore them.
  6. Who reports to the regulator or the national cyber agency, and by when.

Half an hour producing this page is worth more than any product you could buy, because the failure mode in a real incident is confusion rather than a lack of tools.

A realistic order of work

Week one: two-factor authentication everywhere, and the written payment verification rule. Week two: backups configured and a restore tested. Week three: updates set to automatic, password manager rolled out. Week four: the one-page incident plan, and the offboarding checklist.

That is a month of modest effort with no meaningful spend, and it removes most of the realistic risk to a business of this size. Anything beyond it is refinement.


Frequently asked questions

What is the highest-value security step for a small business?

Two-factor authentication on every business account, starting with email. It is free, it takes an afternoon, and it prevents the most common cause of real losses.

How do we stop invoice fraud?

Write down a rule that every change of bank details is verified by phoning a number you already had on file, never one from the email, and require a second approver above a set amount. Make clear that following the rule is never criticised.

What counts as a proper backup?

Three copies, two kinds of storage, one offline or otherwise unalterable — and a restore you have actually tested. A drive permanently connected to the same machine will be encrypted along with everything else.

Do we need cyber insurance?

It can help with the cost of recovery and legal obligations, and most insurers now expect basic controls like two-factor authentication and tested backups before they will pay. Read what the policy requires of you before relying on it.

How should we train staff without wasting their time?

Short and frequent beats long and annual. Fifteen minutes every couple of months on one real example that reached your team, plus a clear rule that reporting a mistake never leads to blame.