Skip to content

Technology & AI for Business

Most small businesses are not hacked by experts. They are caught by an ordinary mistake.

A reused password, a convincing message from “the supplier”, an old laptop with no backup. None of this needs an IT department to fix. A practitioner walks owners through the basics in plain language: what to do this week, what to ask your staff to do, and what to do in the first hour if something goes wrong.

A shop owner and practitioner check a digital draft against real order details.
Explore this page6 sections

Security is mostly habits, not products.

Small businesses now run on email, a messaging app, online banking, accounting software and a cloud folder or two. Each one is a door, and most are protected by a password someone chose years ago and shared with a colleague. An attacker, or a fraudster, does not need to be clever to use that.

The good news is that the basics are cheap and well understood. Unique passwords, two-step verification, updated devices, tested backups and a habit of checking before paying or clicking close most easy routes in. This session is about doing those properly and keeping them going, not about buying a bigger tool. No practice makes a business immune, and we will not pretend otherwise.

What the session covers

37 topics across 7 areas. Seven parts, in the order an owner can act on them.

What You Are ProtectingYou cannot protect what you have not listed.5
  • The accounts that matter: email, banking, accounting, social media, the domain and website
  • Where customer and staff information is kept
  • The devices: phones, laptops, shared computers
  • What would hurt most if it were lost, locked or leaked
  • Who currently has access to each

Business email is often the key to everything else, because password resets go there.

Passwords That Hold UpLong, unique and not in anyone's head.5
  • Why reusing a password is the biggest everyday risk
  • Longer passphrases instead of clever short ones
  • What a password manager does, and whether one suits your team
  • Shared logins: when unavoidable, and how to handle them
  • Never sending a password over chat or email
Two-Step VerificationA second lock on the important accounts.5

Guidance from agencies such as CISA in the United States ranks codes sent by text or email as the weakest form of second step and security keys and authenticator apps as stronger. Any second step is still far better than none.

  • Turning it on for email, banking, accounting and social media first
  • Authenticator apps and security keys versus codes sent by message
  • Why a code should never be read out to a caller
  • Keeping recovery options and backup codes safe
  • What to do when a phone is lost or changed
Phishing and Payment FraudWhere most small-business losses begin.6
  • Urgent or frightening language, and requests for money or details
  • Look-alike email addresses and shortened links
  • A message that “the owner” wants gift cards or an urgent transfer
  • A supplier “changing their bank account” by email or message
  • Fake payment links, fake KYC messages and fake courier notices
  • The rule: confirm by a second channel you already trust, before paying

Fluent spelling no longer proves a message is genuine. Check the request, not the grammar.

Updates, Devices and Wi-FiBoring, and effective.5
  • Updating phones, laptops, browsers and routers
  • Screen locks and device encryption
  • Changing default router and CCTV passwords
  • Public Wi-Fi and shared computers
  • Retiring old devices without leaving data on them
Backups That Actually RestoreA backup you have never tested is a hope.5
  • What needs backing up, and how often
  • A common rule of thumb: more than one copy, on different media, one kept away from the office
  • Why a copy that is always connected can be lost along with the original
  • Doing a trial restore and noting how long it took
  • Who is responsible, and when it is checked
People, Access and When Things Go WrongMost incidents involve a person, not a machine.6
  • Giving each person only the access the job needs
  • A short checklist for removing access when someone leaves
  • Telling staff what to do the moment they click something wrong
  • First hour: disconnect, change passwords, call the bank, keep evidence
  • Reporting: cybercrime.gov.in and the 1930 helpline for financial fraud
  • CERT-In: its April 2022 directions require certain organisations to report listed incident types within six hours, so check whether and how they apply to you

Reporting duties and contact details change. Check the current position on cert-in.org.in rather than relying on this page.

What participants leave with

  • A one-page list of their accounts, devices and who has access
  • A this-week action list, in priority order
  • A short staff briefing they can read out at the next team meeting
  • A tested-backup checklist and a leaver checklist
  • A one-page “if something goes wrong” sheet with the reporting channels filled in

What this session is not

  • A product demonstration or a recommendation of any security tool
  • A security audit of any participant's business
  • A guarantee that following these steps makes a business safe
  • A substitute for specialist help after a serious incident

How the session runs

A practitioner who handles security in a business explains each habit with plain examples, many of them hypothetical and clearly labelled as such. Participants then work through their own list of accounts and devices on paper or on their phones, turning on the first protections during the session where they are able. The session uses no real passwords or customer data, and nobody is asked to show their accounts to the room.

What your students leave with

  • A short, honest list of what actually needs protecting in their business
  • Strong, separate logins and two-step verification on the accounts that matter most
  • The signs of a phishing message or a payment-fraud request, and a rule for checking
  • A backup arrangement that has been tested, not just switched on
  • A clean way to give staff access and to take it away when they leave
  • A one-page “if something goes wrong” plan with the right people to call

Scheduled sessions

Nothing scheduled yet

Sessions are arranged with a college once a date is agreed. Ask us and we will find the right person for it.

A student rather than a college? See what is coming up, or ask your placement team to host this.

Fix the few things attackers rely on, and know who to call before you need to.

Tell us who your students are and what stage they are at. Sessions are free for participants.