Cybersecurity for Small Business: The 10 Protections That Matter

Small business cyber security, ranked by what actually stops attacks: MFA, updates, backups, email and payment fraud checks, and a one-page incident plan. No security team required.

Cybersecurity for a small business comes down to a short list: multi-factor authentication on every important account, automatic updates, tested backups, a password manager, and a habit of verifying any request to move money. Those five steps block most of the attacks small companies actually face, and none of them need a security team.

The attacks that hit small businesses are rarely sophisticated. They are phishing emails, reused passwords, fake supplier invoices and unpatched software. So the protections below are ranked by how much risk they remove per hour of effort, not by how technical they sound.

The 10 protections, ranked

#ProtectionStopsEffort
1Multi-factor authenticationAccount takeover from stolen passwords1 afternoon
2Payment verification ruleFake invoices, CEO fraud1 meeting
3Automatic updatesAttacks on known software flaws1 hour
4Backups you have restoredRansomware, deletion, hardware lossHalf a day
5Password managerReused and weak passwords1 week to roll out
6Email protectionSpoofing of your domain, phishing1 to 2 hours
7Device protectionMalware, lost laptops1 day
8Least-privilege accessOne compromised account opening everythingOngoing
9Staff awarenessPhishing clicks30 minutes a quarter
10Incident planChaos when something goes wrong1 hour

1. Multi-factor authentication (MFA)

If you do one thing this week, do this. Turn on MFA for, in this order:

  1. Your email (Google Workspace or Microsoft 365). Email is the key to resetting every other password.
  2. Online banking and payment accounts (Stripe, PayPal, payroll).
  3. Your domain registrar and website host. Losing these means losing your site and email.
  4. Accounting, CRM and social media accounts.

Prefer an authenticator app (Microsoft Authenticator, Google Authenticator, or the one in your password manager) or a hardware key such as a YubiKey. Text-message codes are better than nothing but can be intercepted through SIM swapping. In Google Workspace and Microsoft 365, admins can enforce MFA for everyone so nobody opts out.

2. The payment verification rule

Business email compromise, where a criminal poses as a supplier or the owner and asks for a payment or a change of bank details, is one of the costliest crimes reported to the FBI's IC3 each year. No software fully stops it. A rule does:

Write it down and tell your bookkeeper and your bank.

3. Automatic updates

Most successful attacks use flaws that already have a fix. Turn on automatic updates for Windows, macOS, phones, browsers and plugins. Replace anything no longer supported, such as an old router or an operating system past its end-of-life date. If you run WordPress, keep core, themes and plugins updated and remove plugins you do not use.

4. Backups you have actually restored

The 3-2-1 rule is a good standard: three copies of important data, on two kinds of storage, with one off-site. For most small businesses that looks like:

Note that Google Workspace and Microsoft 365 do not act as full backups on their own; deleted items are only kept for a limited time. Once a quarter, restore a real file and time how long it takes. An untested backup is a guess.

5. A password manager

Reused passwords turn one breached website into access to your email. A business password manager such as 1Password, Bitwarden or Dashlane gives each person unique passwords, lets you share logins without sending them in chat, and lets you remove access instantly when someone leaves. Check current pricing; business plans are typically charged per user.

6. Email protection

Two jobs here:

7. Device protection

8. Least-privilege access

Give people access to what they need and no more. Separate admin accounts from everyday ones. Remove former staff and contractors the day they leave. Review who has access to banking, payroll and your website host twice a year.

9. Staff awareness

Skip the hour-long annual video. Instead:

10. A one-page incident plan

Write this before you need it:

Print it. If your systems are locked, a document on the shared drive will not help.

What to do this week, this month, this quarter

Once these are in place, ask your insurer or IT provider what they would add for your industry. Businesses handling card payments should also read the PCI DSS requirements that apply to them, and healthcare or legal practices will have sector rules on top.

Your website is part of your attack surface

Your website and domain matter too. Use HTTPS everywhere, lock down your registrar with MFA and registrar lock, keep the site's software updated, and do not store card numbers yourself; let your payment processor handle them. Hosted platforms remove much of the patching work. We.Inc, for example, hosts the sites it builds with SSL included, so there are no server or plugin updates for you to manage. For the ongoing tasks that remain, see our website maintenance cost guide.

For official, free guidance, CISA's small business resources, the NIST Cybersecurity Framework's small business quick-start guides and the UK NCSC's Small Business Guide are all worth reading.

Start free

Frequently asked questions

What is the most important cybersecurity step for a small business?

Turn on multi-factor authentication for email, banking, your password manager and any admin accounts. Stolen passwords are behind a large share of break-ins, and MFA stops most of them. Use an authenticator app or security key rather than text messages where you can.

How much should a small business spend on cybersecurity?

There is no fixed figure. Many of the most effective protections are free or already included in tools you pay for, such as MFA, automatic updates and built-in antivirus. The main costs are usually a password manager, a backup service and, as you grow, managed IT help. Check current pricing for each.

Do small businesses really get targeted?

Yes, mostly through automated and opportunistic attacks: phishing emails, password guessing, and fake invoices. Attackers do not need to know who you are, they just need one weak account. Government agencies such as CISA in the US and the NCSC in the UK publish small business guidance for exactly this reason.

Do I need cyber insurance?

It can cover costs like incident response, data recovery and legal notification. Insurers now commonly ask whether you use MFA, backups and endpoint protection before quoting, so putting the basics in place first also helps you get cover.

What should I do if I think we have been hacked?

Disconnect affected devices from the network, change passwords for affected accounts from a clean device, call your bank immediately if money moved, and contact your IT provider or insurer. Report fraud to the relevant authority, such as the FBI's IC3 in the US or Action Fraud in the UK.

More in Blog

Website builders for the businesses in this article

Related guides and tools

Start building

Related guides

How we research, test and update this page: our editorial policy. We.Inc is our own product.

We.Inc is an AI-powered website builder you can resell under your own brand. Launch a branded client dashboard, bill on Stripe Connect, and deliver AI-generated websites in minutes. White-label plans start at $99 a month for 25 client sites, with a 7-day free trial and no per-site fees.

Product

Who It's For

Features

Resources

Company

View Sitemap