IT

Small business cybersecurity: 10 cheap fixes that prevent big headaches

You do not need an IT department to stop the most common attacks. Ten cheap, practical security fixes any small business can knock out this month.

When people hear "cybersecurity," they picture a hoodie, a dark room and green code flying down a screen. For a small business, it is way less cinematic.

It is an email that looks like it came from your bank. A password you have used since 2014. A former employee who still has the login to your website. Boring stuff. Expensive stuff.

The good news: the fixes are boring too. And mostly cheap or free. Here are the ten I check first when a business asks me for IT help.

How big is the problem? People reported $16.6 billion in internet crime losses to the FBI in 2024, a 33 percent jump from 2023, according to the FBI's 2024 Internet Crime Report (opens in a new tab). The most reported type of complaint was phishing and spoofing: fake emails, texts and calls pretending to be someone you trust.

1. Turn on two step login everywhere

Two step login (also called MFA: a second proof it is you) means a stolen password alone is not enough to get in. After your password, you confirm with a code or an app on your phone.

Start with the accounts that would hurt most:

  1. Email. Whoever has your email can reset almost every other password you own.
  2. Banking and payroll.
  3. Your domain and website hosting.
  4. Google Business Profile, Google Ads and social media.

An authenticator app is stronger than text message codes, but text codes beat nothing by a mile.

2. Get a password manager

A password manager is an app that remembers strong, different passwords for every account so you do not have to. You remember one good passphrase. It handles the rest.

The rule is simple: no password used twice. When one site gets breached, attackers try that same email and password everywhere else. Unique passwords stop that cold.

3. Verify every money change by phone

This is one of the most expensive scams out there, and it is shockingly simple. Someone sends an email that looks like it is from a vendor, a client or even you. "We changed banks, please send this invoice to the new account." The money goes out. It does not come back.

The fix costs nothing: any change to payment details gets verified with a phone call to a number you already have on file. Not the number in the email. Make it a rule for everyone who touches money, including you.

4. Turn on automatic updates

Updates are not just new emoji. Most of them patch security holes that attackers already know about. Turn on automatic updates for:

  • Computers and phones.
  • Web browsers.
  • Your website, including WordPress plugins and themes. An abandoned plugin is an unlocked side door.

If a device is too old to get updates anymore, it is time to retire it.

5. Back up like you mean it

Ransomware (software that locks your files until you pay) and plain old spilled coffee have the same cure: a backup you can actually restore.

A simple rule people use: three copies, two different places, one off site. For most small businesses that means your working files, an automatic cloud backup, and a separate backup that ransomware cannot reach.

6. Shut the door when people leave

When someone leaves the business, their access should leave the same day. Email, shared drives, the website, social media, the booking system, the alarm code. Keep a simple list of every system and who has access. It makes this a ten minute job instead of a scavenger hunt.

7. Own your domain and your accounts

Your domain name (yourbusiness.com) is the foundation of your website and email. I am always surprised how often it is registered under a former web designer's personal account.

  • Domain registered in the business's name, with a business email you control.
  • Auto renew turned on, with a card that will not expire next month.
  • Two step login on the registrar account.
  • Same for hosting, Google, Meta and anything else that runs your marketing.

8. Split the Wi-Fi

Your customers do not need to be on the same network as your computers and card reader. Set up a separate guest network for visitors, change the router's default admin password, and keep the router updated too.

9. Teach the team three red flags

You do not need a training program. You need three habits:

  1. Urgency is a red flag. "Pay this in the next hour" is a scam's favorite sentence.
  2. Check the sender's actual address, not just the display name.
  3. When in doubt, call. Use a known number, never the one in the message.

Make it safe to ask. The person who says "this looks weird" should get a thank you, not an eye roll.

10. Write a one page "uh oh" plan

If something does go wrong, who do you call? Write it down now, while you are calm:

Where to go from here

Do numbers 1, 2 and 3 this week. They stop the most common, most expensive problems, and they cost almost nothing. Then work down the list one item a week. And if you would rather have someone check it all for you, IT support is one of the things I handle for clients: accounts, access, updates, backups and the website side of security.

- Danny

Danny, PRMR Marketing

Sources

  1. FBI IC3: 2024 Internet Crime Report (opens in a new tab)
  2. NIST SP 800-63B: Digital Identity Guidelines, Authentication (opens in a new tab)
  3. FTC: Cybersecurity for Small Business (opens in a new tab)
How we handle IT

Free marketing audit

Want us to look
at yours?

Our free audit reviews your website, search visibility, ads and tracking, with every issue ranked by how much it matters. You keep the findings either way.