Cybersecurity for small business — 10 essential measures
A common belief is: "We're a small company — hackers aren't interested in us." The reality is exactly the opposite. Small businesses are a preferred target precisely because they rarely have adequate protection.
The statistics speak for themselves: over 43% of cyberattacks target small businesses. The average cost after a successful attack exceeds $200,000 — enough to close most small companies.
The good news: most of this risk can be eliminated with relatively simple measures. Here are the 10 you should start with.
Measure 1: Strong passwords and a password manager
Weak passwords are behind over 80% of breaches. "123456" and "password1" protect nothing.
What to do:
- Use at least 12 characters, mixing upper/lowercase letters, numbers, and symbols
- Use a different password for every service
- Use a password manager (Bitwarden, 1Password) — free or cheap, and it saves a huge amount of trouble
Measure 2: Two-factor authentication (2FA) everywhere
Even if your password is stolen, 2FA blocks access. Turn it on for:
- Email (Google Workspace, Outlook)
- Financial systems and banking
- Cloud services (OneDrive, Google Drive, Dropbox)
- Social media and ad accounts
Apps like Google Authenticator or Authy make the process easy.
Measure 3: Regular data backups
In a ransomware attack, a backup is the only thing that saves you without having to pay the ransom.
- Back up daily to at least two types of media (local + cloud)
- Regularly test that the backup can actually be restored
- Keep at least one copy offline (without a permanent internet connection)
Measure 4: Update everything — regularly
Outdated software is full of vulnerabilities that hackers know about. Updates patch them.
- Enable automatic updates on Windows/macOS
- Regularly update all applications (browsers, Office, accounting software)
- Don't forget the firmware on routers, printers, and cameras
Measure 5: Antivirus and endpoint protection
Free antivirus software offers basic protection. For a business environment we recommend more serious solutions:
- Bitdefender Business, ESET Endpoint Security, Malwarebytes for Teams
- Centralized management — monitor all devices from one place
- Scan periodically, not just in real time
Measure 6: Employee training
The human factor is the weakest link. Over 90% of successful cyberattacks start with phishing — a fraudulent email that tricks an employee into clicking.
Train your team to recognize:
- Suspicious emails demanding urgent action
- Links leading to unfamiliar sites
- Unexpected attachments
- Fake invoices or payment requests
Measure 7: Network segmentation
Split your network into segments (VLANs). If one device is compromised, segmentation limits how far the threat can spread:
- Workstations on their own segment
- IoT devices (cameras, printers) on a separate one
- Guest Wi-Fi — with no access to internal resources
Measure 8: Access control for data
Not every employee needs to see everything. The principle of "least privilege" means: grant access only to what's necessary for the job.
- Define roles and permissions in Windows via Active Directory or local user accounts
- When an employee leaves — immediately disable the account
- Regularly review who has access to what
Measure 9: Secure email communication
Email is the primary attack vector. Protective measures:
- Enable SPF, DKIM, and DMARC for your domain (reduces the risk of spoofing)
- Use spam and anti-phishing filters
- If you use Microsoft 365 or Google Workspace — turn on advanced protection
- Don't open attachments from unknown senders
Measure 10: Have an incident response plan
Even with excellent protection, an incident can still happen. It's important to know what to do:
- Who needs to be notified immediately (IT, management)?
- How do you isolate the affected device?
- When and how do you notify customers (if their data is affected — GDPR requires it)?
- How do you restore from backup?
Have a written plan — even a one-page one.
Cybersecurity is not a one-time task
Security is a process, not a product. Threats change, systems get updated, employees come and go. Regular review is essential.
SNM Support offers cybersecurity consulting for small and medium businesses — assessing your current level, giving recommendations, and rolling out measures step by step. Get in touch with us for a free initial consultation.
Related articles
Blog