Cybersecurity for small businesses: 10 simple measures
Most small-business breaches happen not because of genius hackers but because of weak passwords and missing backups. Here are 10 measures you can put in place within a week.
Many small-business owners think: "Who would want my small company?" In practice, attackers target everyone — automatically. A hacked mailbox, files locked by ransomware or a hijacked Instagram account hit a small company harder than a large one.
The good news: most attacks are stopped by simple measures.
1. Unique, strong passwords
One password for everything is the main cause of breaches. If the password to one service leaks, attackers will try it everywhere. Use a password manager (Bitwarden, 1Password, KeePass) — it creates and stores strong passwords for you.
2. Two-factor authentication
Turn it on wherever possible: email, bank, social networks, the website admin panel, hosting. Even if a password is stolen, nobody can log in without the code from the app on your phone. An authenticator app is more reliable than SMS.
3. Backups using the 3-2-1 rule
Three copies of important data, on two different media, with one copy outside the office or server (in the cloud). Once a quarter, check that you can actually restore everything from a copy.
4. Updates
Update Windows, phones, browsers, your website's CMS and plugins. Most website breaches happen through outdated plugins with known vulnerabilities.
5. Care with emails and links
Phishing means emails that look like messages from a bank, the tax office or a partner. Rules for employees:
- don't open unexpected attachments;
- check the sender's address;
- don't enter passwords via links in emails — go to the website manually;
- confirm any request to "transfer money urgently" with a phone call.
6. Minimum access
Each employee gets access only to what they need for work. When someone leaves, disable their accounts and change shared passwords the same day.
7. Corporate email on your own domain
Addresses like name@yourcompany.tj look more trustworthy to customers and are better protected than employees' personal mailboxes. Set up SPF, DKIM and DMARC — records that stop fraudsters from sending emails in your name.
8. Website protection
- an HTTPS certificate;
- a strong password and two-factor protection for the admin panel;
- regular website backups;
- CMS and plugin updates.
9. Office Wi-Fi
A separate guest network for visitors, a strong password for the work network and a changed default router password.
10. An incident plan
Write down in advance: whom to call if your email or website is hacked; where the backups are kept; who can revoke access. In a stressful situation, such a list saves hours.
Where to start this week
- Turn on two-factor authentication for your email and bank.
- Back up important files to the cloud.
- Install a password manager and change your most important passwords.
Who can help
In the "Cybersecurity and security audits" category on GHOST.TJ, you can order a security audit of your website and office, backup setup and staff training.