There's a dangerous idea widespread among small businesses: "who's going to bother attacking me, I'm just a small shop?". The reality is the opposite. Cybercriminals rarely pick specific victims; they fire automated attacks at millions of addresses and keep whoever left the door open. And small businesses, usually less protected than big ones, are precisely that open door.
A ransomware attack that encrypts all your files, a CEO fraud where someone impersonates the boss to request an urgent transfer, or a single leaked password can halt your business for days or cost you thousands. The good news is that most of these blows are avoidable with basic measures. You don't need to be an expert or spend a fortune. Here are the five steps that make the difference.
Step 1: Strong passwords and a manager to remember them
The password is still the first line of defence, and also the most neglected. "123456", the company name, or the same key reused across twenty sites are an open invitation. The golden rule: one distinct, long password per service.
Nobody can memorise forty unique passwords, and you don't have to. A password manager (like Bitwarden or 1Password) generates them, stores them encrypted and fills them in for you. You only need to remember one master key. It's probably the biggest security improvement for the least effort you can make today.
Step 2: Turn on two-factor authentication everywhere
Even if your password is stolen, two-factor authentication (2FA) stops the attacker dead, because to get in they also need a code that only exists on your phone. Switch it on, no exceptions, for email, banking, your social accounts and any tool holding customer data.
A tip: wherever you can, use an authenticator app (like Google Authenticator or Authy) rather than SMS, which is more vulnerable. Email is the crown jewel, because every other password gets reset through it; protect it like the safe it actually is.
Step 3: Backups that actually work
The day ransomware encrypts your files, the difference between an anecdote and a catastrophe will be whether you have a backup. And not just any backup. Apply the 3-2-1 rule: three copies of your data, on two different types of media, with one of them off-site (in the cloud, for example).
The detail almost everyone forgets: a backup you've never tried to restore isn't a backup, it's a hope. Run a recovery test now and then. Discovering the backup was corrupt on the day you need it is one of the worst feelings there is.
Step 4: Update everything and distrust email
Most attacks come in through two doors: outdated software and booby-trapped emails. Updates aren't an annoyance that pops up at the worst moment; they usually patch security holes attackers are already exploiting. Keep automatic updates on for your operating system, browser and applications.
And then there's phishing, the king of techniques. An email that looks like it's from your bank, the postal service or a supplier asks you to click or to pay an invoice. When in doubt: don't click links in unexpected emails, check the sender, and if someone requests an urgent transfer "from the boss", pick up the phone to confirm it. Spain's INCIBE publishes alerts about the fraud campaigns circulating at any given time; they're worth a look.
Step 5: Train your team, the link that matters
You can have the best technology in the world, but if someone on your team clicks a malicious link, it all falls apart. Human error is said to be behind the vast majority of breaches, and it's true. That's why the most cost-effective step isn't buying an expensive antivirus, it's spending half an hour making sure your people can recognise a suspicious email and know what to do if they slip up.
Create simple, clear rules: no sharing passwords over WhatsApp, no transfer without double confirmation, and anyone who spots something odd says so without fear of a telling-off. A culture where reporting a mistake is normal catches problems while they're still small.
Start today, not when it's too late
None of these five steps requires being an IT specialist or a big budget. It requires deciding that your business's security matters before an incident proves it the hard way. If you do just these five, you're already ahead of most small businesses.
At Social Digital we help small businesses close these gaps without drama or jargon: we review your weak points, set up reliable backups, switch on the basic protections and train your team. If you'd like to know how exposed your business is right now, book a free security diagnostic with us and we'll tell you straight.

