Explainer
Cyber Basics for Small Businesses
A cyber security starter kit for small businesses
You run a business. You don't have a dedicated IT team, you don't have a massive security budget, and you definitely don't have time to become a cyber security expert. That's fine. This guide covers the things that actually matter — the stuff that prevents the vast majority of attacks small businesses face.
Think of it as locking your doors and windows. You don't need a moat. You just need to not be the easiest target on the street.
## What this guide covers
- The real threats small businesses face (not the Hollywood version) - The essential security basics that make the biggest difference - How to build simple habits without slowing your team down - What to do if something goes wrong
---
## Why Small Businesses Get Targeted
There's a misconception that hackers only go after big companies. The reality is the opposite — small businesses are targeted precisely because they usually have weaker defences and fewer resources to detect or respond to attacks.
Common attacks on small businesses include phishing emails sent to staff, ransomware that locks your files until you pay, compromised business email used to redirect payments, and stolen customer data. None of these require a sophisticated attacker. Most are automated or opportunistic. They don't care what your business does — they care that your door was unlocked.
---
## The Essentials (Do These First)
### 1. Use strong, unique passwords — and a password manager
The single biggest vulnerability in most small businesses is passwords. People reuse them, share them, and make them easy to guess.
Get your team on a password manager. It generates and stores unique passwords for every account, and your team only needs to remember one master password. Most have business plans that are affordable and let you manage access centrally.
The rule is simple: every account gets a unique password. No exceptions.
### 2. Turn on two-factor authentication everywhere
2FA means that even if someone steals a password, they still can't get in without a second verification step. Turn it on for email, banking, cloud storage, social media, and any business-critical platform.
Start with your email accounts — those are the keys to everything else.
> **Need a walkthrough?** See our guide: *Set Up 2FA in 5 Minutes (And Why You Should)*
### 3. Keep software updated
When you see "Update available," don't ignore it. Software updates often include security patches — fixes for vulnerabilities that hackers actively exploit. This applies to operating systems, browsers, apps, plugins, and any software your business uses.
Turn on automatic updates wherever possible so you don't have to think about it.
### 4. Back up your data regularly
If ransomware encrypts your files tomorrow, do you have a backup? If your laptop dies, can you recover your client list?
Back up your important business data regularly — ideally using the 3-2-1 rule: 3 copies, on 2 different types of storage, with 1 stored offsite or in the cloud. Automated cloud backup services make this easy and relatively cheap.
Test your backups occasionally. A backup you can't restore from is not a backup.
### 5. Control who has access to what
Not everyone in your business needs access to everything. Limit access based on what people actually need to do their jobs. If someone leaves the company, revoke their access immediately — this includes email, cloud storage, shared accounts, and any business tools.
Shared logins are a common shortcut in small businesses, but they're a security problem. When something goes wrong, you can't tell who did what. Give everyone their own account where possible.
---
## Train Your Team (Keep It Simple)
You don't need formal security training. But your team needs to know a few things:
**How to spot phishing.** Most cyberattacks start with an email. Your team should know to pause before clicking links, to verify unexpected requests (especially anything involving money or passwords), and to report anything suspicious without fear of being blamed.
> **Share our guide with your team: *How Phishing Scams Actually Work***
**What to do if they make a mistake.** If someone clicks a bad link or gives away a password, the worst thing they can do is hide it out of embarrassment. Make it clear that reporting a mistake immediately is expected and appreciated — not punished. The faster you know, the faster you can respond.
**The basics of device security.** Lock your screen when you walk away. Don't plug in unknown USB drives. Be careful on public WiFi. These are small habits that add up.
---
## Protect Your Customer Data
If you store customer information — names, email addresses, payment details, anything personal — you have a responsibility to protect it. In many countries, you also have a legal obligation.
Keep only the data you actually need. The less you store, the less there is to steal.
Make sure any platform or service you use to store customer data has proper security measures — encryption, access controls, and a good track record.
If you take payments, use a reputable payment processor rather than handling card details yourself. Let the experts handle the high-risk stuff.
---
## Have a Basic Incident Plan
You don't need a 50-page document. You need answers to four questions written down somewhere your team can find them:
**Who do we contact first?** (Your IT person or provider, your bank if financial data is involved, your insurance company if you have cyber coverage.)
**How do we contain the damage?** (Disconnect affected devices, change compromised passwords, revoke access.)
**Who needs to be told?** (Customers if their data was affected, your country's data protection authority if legally required, your team.)
**Where do we report it?**
> **Find your country's reporting options on our [Resources page].**
Write this down before something happens. During a crisis is the worst time to figure out your plan.
---
## What You Don't Need (Yet)
Small businesses often get sold expensive security products they don't need. Before you buy anything, make sure you've covered the basics above. They're free or low-cost and handle the majority of risk.
You don't need enterprise-grade firewalls. You don't need a security operations centre. You don't need to hire a full-time cyber security person.
You need strong passwords, 2FA, updated software, backups, and a team that can spot a phishing email. Start there. Everything else can come later as your business grows.
---
## The Bottom Line
Cyber security for small businesses isn't about being unhackable — nothing is. It's about not being the low-hanging fruit. The basics covered in this guide will protect you from the vast majority of attacks that hit small businesses every day.
Do the simple things consistently, and you're already ahead of most.
> **Running a small business and dealt with a cyber incident?** Share your story on our [Stories page] — your experience might help another business owner.
---
*This guide is part of the StillOnline.org prevention series. Written in plain language for busy people who have a business to run.*
Need help reporting or recovering?
Find where to report cyber crime in your country and where to get support.
Get help