← All insights

Cybersecurity

Cybersecurity basics every small business should have

Small businesses often assume they are too small to be a target. The opposite is true. Attackers favour small companies precisely because they expect the basics to be missing. The good news is that most incidents are stopped by a handful of fundamentals, none of which require a security team. Here are seven to have in place.

1. Turn on multi-factor authentication everywhere

A stolen password is only useful if it is the only lock on the door. Multi-factor authentication adds a second step, a code or a tap on your phone, so a leaked password alone is not enough to get in. Enable it on email, banking, and every business tool that offers it. This single step blocks the large majority of account takeovers.

2. Use a password manager

People reuse passwords because remembering unique ones is impossible. A password manager removes the trade-off: it generates and stores a strong, different password for every account, and your team only has to remember one. Reused passwords are how a breach at one service becomes a breach at yours.

Most break-ins are not clever hacks. They are a reused password and a login page.

3. Keep everything updated

Those update prompts you keep postponing usually contain security fixes for holes attackers already know about. Turn on automatic updates for operating systems, browsers, and apps. An unpatched device is a known, open door.

4. Protect the devices themselves

Every laptop is a way into your business. Each one needs active protection: malware scanning, real-time monitoring, and a clear view of its security state. This is exactly why we built Bolt, our free desktop security app, to scan for threats, watch key folders in real time, and give each machine a simple 0 to 100 security score, at no cost.

5. Back up, and test the backup

Ransomware is survivable if you have clean backups you can actually restore from. Back up your important data automatically, keep a copy somewhere separate, and, crucially, test a restore now and then. A backup you have never restored is a hope, not a plan.

6. Train people to spot the trap

The most common way in is not technical, it is a convincing email that gets someone to click, pay, or hand over a password. A short, honest conversation about what phishing looks like, urgency, a spoofed sender, an unexpected invoice, does more than most software. Your team is the firewall that thinks.

7. Give the least access that works

Not everyone needs to be an administrator, and old accounts for people who have left are a gift to an attacker. Give each person the access their job needs and no more, and remove accounts promptly when someone leaves. Small habit, large reduction in risk.

The short version

Multi-factor authentication, a password manager, automatic updates, protected devices, tested backups, aware people, and least-privilege access. None of it is exotic, and together it stops the overwhelming majority of what actually happens to small businesses.

Want a hand putting these in place? See how we help with cybersecurity, get Bolt free, or book a free consult.

Start with the basics, for free.

Protect every machine with Bolt, our free security app, then talk to us about the rest.

Get Bolt free