The most important IT security basics for a small business are: turn on multi-factor authentication for email and key accounts, keep devices and software updated, use a password manager, back up data with at least one copy offsite, protect every device with security software, limit who has admin access, and train staff to spot phishing.
Most cyber attacks on small businesses aren't sophisticated. They're automated, and they succeed because of weak passwords, missing updates or a convincing email. These seven essentials, drawn from more than 12 years of working in IT, close the most common gaps.
1. Turn on multi-factor authentication (MFA)
MFA means a stolen password alone isn't enough to get into an account. Turn it on for email first (Microsoft 365 or Google Workspace), then banking, accounting software and anything with customer data. In Microsoft 365, the simplest starting point is enabling security defaults, which require MFA for every user.
2. Keep everything updated
Updates fix security holes that attackers actively exploit. Turn on automatic updates for Windows, macOS, browsers and Microsoft 365 apps, and don't forget routers, printers and phones. Devices that no longer get updates, such as unsupported Windows 10 PCs, should be upgraded or replaced.
3. Use a password manager
A password manager creates and remembers a unique, strong password for every account, so one leaked password doesn't unlock everything. A business password manager also lets you share logins safely and remove access when someone leaves.
4. Back up your data: the 3-2-1 rule
Keep 3 copies of important data, on 2 different types of storage, with 1 copy offsite or in the cloud. Just as important: test that you can actually restore from your backups. Ransomware often targets connected backups, so keep at least one copy separate.
5. Protect every device
Every laptop and PC needs up-to-date security software (Microsoft Defender is built into Windows), disk encryption such as BitLocker, and a lock screen. For more than a handful of devices, central device management lets you enforce these settings and wipe a lost laptop remotely.
6. Limit admin access
Staff should use standard accounts day to day, with admin rights kept for the few people who really need them. This stops most malware from installing itself. Remove accounts promptly when people leave.
7. Train your team to spot phishing
Most attacks start with an email. Teach staff to check sender addresses, to be suspicious of urgent requests to pay invoices or change bank details, and to confirm unusual requests by phone. Suspicious emails can be forwarded to the National Cyber Security Centre at report@phishing.gov.uk.
Worth considering: Cyber Essentials
Cyber Essentials is a UK government-backed certification that covers these basics. It shows customers you take security seriously, and it's required for some government contracts. Working through the seven steps above puts you most of the way there.
Need a Hand With This?
Bring it to us for a free diagnostic. You get a fixed quote before any work starts, repairs from £65, no fix — no fee, and a 6-month warranty.