Skip to content
← All guides

Prevention

Cyber basics for small businesses

The small number of controls that prevent most losses for a business without a security team, and the one that matters most.

2 min read

Small businesses get targeted precisely because they hold real money and rarely have anyone whose job is security. The good news is that a very short list of controls prevents most of what actually happens.

Invoice fraud is the expensive one

The pattern is consistent. Someone gets into a mailbox, often a supplier's rather than yours, and watches quietly. They wait for a real invoice to be discussed, then send a message from that genuine mailbox saying the bank details have changed. Everything about it is authentic, because it is authentic. Only the account number is wrong.

It is not caught by looking harder at the email. It is caught by picking up the phone.

The short list

  1. Two-factor authentication on every business account

    Email first, then banking, then anything holding customer data. This is the highest value hour you will spend.

  2. Call-back verification for payment changes

    Written down, applied to everyone including the owner, with no exception for urgency. Urgency is the tell.

  3. Separate accounts for each person, and remove leavers the same day

    Shared logins make it impossible to tell who did what, and dormant accounts belonging to former staff are a standard way in.

  4. Backups that are not reachable from your network

    Ransomware operators look for backups first and encrypt them too. A backup on a connected drive is not a backup.

  5. Keep devices and software updated

    Unglamorous, and it closes the holes that automated attacks rely on.

We are too small to be a target. Is that not true?

No, and it is the most costly assumption in this area. Most attacks are automated and indiscriminate, and they find you because you exist rather than because anyone chose you. Small businesses are also attractive precisely because the controls are usually weaker while the bank balance is still real.

Do we need cyber insurance?

It is worth pricing, particularly if you hold customer data or move significant payments. Read what is actually covered, since social engineering and invoice fraud are commonly excluded or capped separately, and those are the most likely claims you will ever make. Ask that question specifically before buying.

Need to report this?

Where to report cyber crime in your country, and where to find support.

Get help

This happened to them too

First-hand accounts from people who went through the same thing.

Related guides