Skip to content
ChecklistEntrepreneurship6 min

Cybersecurity basics a small business can do this week

Seven practical steps for a business with no IT team: logins, two-step verification, phishing, updates, backups, staff access, and who to call if it goes wrong.

Share on WhatsApp
Two adults use a practical guide, checklist cards and a recorded workshop to support their learning

Conceptual image · created with AI

Most small businesses do not have an IT department, and many owners assume security is for bigger companies. In practice, the common routes in are ordinary ones: a password used in many places, a convincing message that asks for money, a laptop that was never backed up.

The steps below are the basics, in the order we would do them. None needs special software or a large budget. They will not make a business immune to attack, and nobody can honestly promise that, but they close the doors that are easiest to open.

What you should come away with

  • Protect business email first, because password resets for everything else usually go there
  • Turn on two-step verification for email, banking, accounting and social media
  • Check any request for money or details through a second channel you already trust
  • A backup you have never restored from is a hope, not a backup
  • Remove access the day someone leaves
  • Know in advance who you would call, including cybercrime.gov.in and 1930 for financial fraud

Start with a list. Take ten minutes and write down the accounts that would hurt most to lose: business email, online banking, payment apps, accounting software, the website and domain, social media pages, and any cloud folder that holds customer records. Next to each, note who can log in. You cannot protect what you have not listed, and the list often reveals a login that three people share or a former employee who still has access.

Step one is business email. Almost every other account can be reset through it, so whoever controls the inbox can often take over the rest. Give it a long, unique password that you use nowhere else. A passphrase of several unrelated words is easier to remember and harder to guess than a short, clever one. Reusing the same password across accounts is the single most common everyday weakness, because when one site is breached, attackers try the same details elsewhere.

Step two is two-step verification, sometimes called multi-factor authentication. It asks for a second proof, such as a code from an authenticator app, after the password. Switch it on for email, banking, accounting software and social media first. Guidance from CISA, the United States cybersecurity agency, ranks security keys and authenticator apps as stronger than codes sent by text or email, though it treats any second step as better than none. Whichever you use, never read a code out to someone who phones you. Keep recovery options and backup codes somewhere safe, and think through what happens if the phone is lost.

Step three is a habit rather than a setting: check before you pay or click. Most small-business losses begin with a message. CISA lists warning signs such as urgent or frightening language, requests for personal or financial details, shortened links and email addresses that are slightly wrong. Fluent spelling no longer proves a message is genuine. Typical hypothetical examples: a message that appears to come from the owner asking staff to buy vouchers urgently; a supplier who says their bank account has changed; a courier notice with a link; a request to share a one-time code. The rule is the same each time. Confirm by calling a number you already have, not one in the message, and agree inside the business that any change of bank details needs that second check, whoever asks.

Step four is updates and devices. Keep phones, laptops, browsers and routers updated, because updates often fix weaknesses that are already being exploited. Use a screen lock on every device that touches business accounts. Change default passwords on the Wi-Fi router and on any CCTV or smart devices, since factory passwords are widely known. When an old phone or laptop is retired, wipe it properly rather than handing it on with data inside.

Step five is backups. Decide what you cannot afford to lose, such as billing records, customer lists and photographs, and copy it regularly. A widely used rule of thumb is to keep more than one copy, on more than one kind of storage, with one copy kept away from the office. A copy that is always plugged in or synced can be damaged or encrypted along with the original, so keep at least one that is not permanently connected. Then do the step most people skip: restore a few files and note how long it took. A backup you have never tested may fail on the day you need it.

Step six is people. Give each person only the access their job needs, and use separate logins instead of a shared one so you can see who did what. Write a short leaver checklist: email, shared folders, accounting, social media, phone numbers, keys. Do it on the person's last day. Tell staff plainly what to do if they click something wrong: say so immediately, because a fast report costs far less than a hidden mistake, and do not make it a matter of blame.

Step seven is knowing what to do when something goes wrong. If money has been lost to online fraud, act quickly: call your bank, and report through the National Cyber Crime Reporting Portal at cybercrime.gov.in or the helpline 1930, which are for financial fraud. Speed matters, so keep those details where staff can find them. Change passwords from a clean device, keep screenshots and messages as evidence, and disconnect any affected computer.

Some businesses also have a duty to report certain incidents. CERT-In, India's national cyber agency, issued directions on 28 April 2022 under the Information Technology Act that require service providers, intermediaries, data centres, body corporates and government organisations to report listed types of incident within six hours of noticing them. The list includes phishing attacks, ransomware, unauthorised access to systems, data breaches and unauthorised access to social media accounts. Whether and how this applies to your business is a question to check against the current text on cert-in.org.in, or with a lawyer or adviser, because directions can be updated.

Finally, put it in the diary. Choose one hour this week for steps one and two, and another next week for the backup test. Review the list every few months. Security is mostly habit, and small habits that are kept up beat large plans that are not.

TopicsTechnologyEntrepreneurship

Come to the session it came from

Reading it is useful. Being in the room and asking your own question is better.