Small business cyber security, ranked by what actually stops attacks: MFA, updates, backups, email and payment fraud checks, and a one-page incident plan. No security team required.
Cybersecurity for a small business comes down to a short list: multi-factor authentication on every important account, automatic updates, tested backups, a password manager, and a habit of verifying any request to move money. Those five steps block most of the attacks small companies actually face, and none of them need a security team.
The attacks that hit small businesses are rarely sophisticated. They are phishing emails, reused passwords, fake supplier invoices and unpatched software. So the protections below are ranked by how much risk they remove per hour of effort, not by how technical they sound.
| # | Protection | Stops | Effort |
|---|---|---|---|
| 1 | Multi-factor authentication | Account takeover from stolen passwords | 1 afternoon |
| 2 | Payment verification rule | Fake invoices, CEO fraud | 1 meeting |
| 3 | Automatic updates | Attacks on known software flaws | 1 hour |
| 4 | Backups you have restored | Ransomware, deletion, hardware loss | Half a day |
| 5 | Password manager | Reused and weak passwords | 1 week to roll out |
| 6 | Email protection | Spoofing of your domain, phishing | 1 to 2 hours |
| 7 | Device protection | Malware, lost laptops | 1 day |
| 8 | Least-privilege access | One compromised account opening everything | Ongoing |
| 9 | Staff awareness | Phishing clicks | 30 minutes a quarter |
| 10 | Incident plan | Chaos when something goes wrong | 1 hour |
If you do one thing this week, do this. Turn on MFA for, in this order:
Prefer an authenticator app (Microsoft Authenticator, Google Authenticator, or the one in your password manager) or a hardware key such as a YubiKey. Text-message codes are better than nothing but can be intercepted through SIM swapping. In Google Workspace and Microsoft 365, admins can enforce MFA for everyone so nobody opts out.
Business email compromise, where a criminal poses as a supplier or the owner and asks for a payment or a change of bank details, is one of the costliest crimes reported to the FBI's IC3 each year. No software fully stops it. A rule does:
Write it down and tell your bookkeeper and your bank.
Most successful attacks use flaws that already have a fix. Turn on automatic updates for Windows, macOS, phones, browsers and plugins. Replace anything no longer supported, such as an old router or an operating system past its end-of-life date. If you run WordPress, keep core, themes and plugins updated and remove plugins you do not use.
The 3-2-1 rule is a good standard: three copies of important data, on two kinds of storage, with one off-site. For most small businesses that looks like:
Note that Google Workspace and Microsoft 365 do not act as full backups on their own; deleted items are only kept for a limited time. Once a quarter, restore a real file and time how long it takes. An untested backup is a guess.
Reused passwords turn one breached website into access to your email. A business password manager such as 1Password, Bitwarden or Dashlane gives each person unique passwords, lets you share logins without sending them in chat, and lets you remove access instantly when someone leaves. Check current pricing; business plans are typically charged per user.
Two jobs here:
Give people access to what they need and no more. Separate admin accounts from everyday ones. Remove former staff and contractors the day they leave. Review who has access to banking, payroll and your website host twice a year.
Skip the hour-long annual video. Instead:
Write this before you need it:
Print it. If your systems are locked, a document on the shared drive will not help.
Once these are in place, ask your insurer or IT provider what they would add for your industry. Businesses handling card payments should also read the PCI DSS requirements that apply to them, and healthcare or legal practices will have sector rules on top.
Your website and domain matter too. Use HTTPS everywhere, lock down your registrar with MFA and registrar lock, keep the site's software updated, and do not store card numbers yourself; let your payment processor handle them. Hosted platforms remove much of the patching work. We.Inc, for example, hosts the sites it builds with SSL included, so there are no server or plugin updates for you to manage. For the ongoing tasks that remain, see our website maintenance cost guide.
For official, free guidance, CISA's small business resources, the NIST Cybersecurity Framework's small business quick-start guides and the UK NCSC's Small Business Guide are all worth reading.
Turn on multi-factor authentication for email, banking, your password manager and any admin accounts. Stolen passwords are behind a large share of break-ins, and MFA stops most of them. Use an authenticator app or security key rather than text messages where you can.
There is no fixed figure. Many of the most effective protections are free or already included in tools you pay for, such as MFA, automatic updates and built-in antivirus. The main costs are usually a password manager, a backup service and, as you grow, managed IT help. Check current pricing for each.
Yes, mostly through automated and opportunistic attacks: phishing emails, password guessing, and fake invoices. Attackers do not need to know who you are, they just need one weak account. Government agencies such as CISA in the US and the NCSC in the UK publish small business guidance for exactly this reason.
It can cover costs like incident response, data recovery and legal notification. Insurers now commonly ask whether you use MFA, backups and endpoint protection before quoting, so putting the basics in place first also helps you get cover.
Disconnect affected devices from the network, change passwords for affected accounts from a clean device, call your bank immediately if money moved, and contact your IT provider or insurer. Report fraud to the relevant authority, such as the FBI's IC3 in the US or Action Fraud in the UK.
How we research, test and update this page: our editorial policy. We.Inc is our own product.
We.Inc is an AI-powered website builder you can resell under your own brand. Launch a branded client dashboard, bill on Stripe Connect, and deliver AI-generated websites in minutes. White-label plans start at $99 a month for 25 client sites, with a 7-day free trial and no per-site fees.