Security is not a product installed once. It is a set of habits: who can sign in, what they can do, how copies are stored and how the team reacts when something looks unusual. For small businesses, a few foundational controls can materially reduce exposure.
Protect accounts and access
Every person should have an individual account and only the permissions needed for their role. Use unique passwords, a password manager and multifactor authentication wherever available. CISA includes MFA, updates and phishing awareness among its core small-business practices.
- Do not share an administrator account.
- Remove access immediately when a person leaves.
- Review privileged users periodically.
- Never approve an MFA request you did not initiate.
Update systems and reduce the attack surface
Keep the operating system, modules and devices updated. Remove unused plugins, files and accounts. A smaller environment has fewer unnecessary points to monitor and maintain.
Create backups that can actually be restored
A backup is not complete until a restore has been tested. Keep copies separate from the primary system, restrict access and record the date of the latest recovery test. NIST publishes quick-start guidance for small-business cybersecurity risk management.
- Define what must be copied and how often.
- Keep at least one copy outside the primary environment.
- Test a restore periodically.
- Keep incident contacts and steps available outside the system.
Respond quickly to unusual signs
Repeated failed logins, unknown accounts, new files or unusual slowness deserve investigation. Change credentials from a trusted device, preserve evidence and obtain professional support when the incident exceeds internal capability.
Authoritative resources
Next step
Begin with individual accounts, MFA, updates and tested backups. This is general guidance; specific controls should match the risks, data and obligations of your business.