Small businesses assume they are not worth attacking. That misreads how most attacks work. Attackers are not selecting targets by value, they are selecting by ease, at scale, automatically. A small business with no multi-factor authentication is easier than a large one with a security team, and the payment fraud works just as well.
The good news is that most real incidents are prevented by a short list of unglamorous measures.
The eight things that matter
1. Multi-factor authentication, everywhere it is offered.
This is the single highest-value control available. It defeats the overwhelming majority of credential attacks, because a stolen password on its own stops being useful.
Priority order: email first, then banking, then accounting, then everything else. Email first because whoever controls your email can reset the password on everything else.
Use an authenticator app rather than SMS where you have the choice. SMS is better than nothing and worse than an app.
2. A password manager.
The reason people reuse passwords is that remembering forty is impossible. A password manager makes unique passwords the easy option rather than the disciplined one.
The specific risk it addresses: credential stuffing. A breach at some service you forgot you used gives attackers an email and password pair, which they then try everywhere. Reused passwords turn one irrelevant breach into a compromise of your bank.
3. Updates, on automatic.
Operating systems, browsers, phones, and anything internet-facing. Most successful attacks use vulnerabilities that were patched months earlier. Turn on automatic updates and stop thinking about it.
4. Backups you have actually tested.
Three copies, two different media, one off-site is the traditional rule and it still holds. The critical addition: at least one copy that cannot be modified from your network, because ransomware encrypts connected backups along with everything else.
Then test a restore. An untested backup is a hope, and a meaningful proportion fail when first attempted for real.
5. A payment verification rule.
This prevents the fraud that actually hits small businesses hardest.
The pattern: an email arrives, apparently from a supplier or a director, asking for a payment or a change of bank details. It is convincing, often correctly referencing a real invoice, sometimes sent from a genuinely compromised account.
The rule: any change of bank details, and any unusual payment request, is verified by phone on a number you already had. Not a number in the email. Never approved on email alone, regardless of who it appears to come from.
Write it down, tell everyone who can move money, and make it a rule that is never embarrassing to apply.
6. Separate administrator accounts.
Do not use an account with administrative rights for daily work. If that account is compromised while browsing email, the attacker inherits the rights.
7. Remove access when people leave.
Have a list of every system and who has access. On departure, revoke everything the same day, including shared accounts, and change any shared credentials the person knew.
8. Know what you would do.
Half a page. Who to call, where the backups are, how to isolate a machine, who needs to be told. Under GDPR, a personal data breach with risk to individuals must be reported to the supervisory authority within 72 hours, which is not long enough to work out the process from scratch.
Phishing, briefly
Most incidents start with an email. Awareness helps, but the reliable defence is process rather than vigilance, because eventually someone tired will click.
Tell staff, once, in plain terms: no legitimate organisation asks for a password by email; urgency is the most common manipulation tactic; check the sender's actual address, not the display name; when in doubt, go to the site directly rather than clicking the link. And most importantly, that reporting a suspected click brings no blame. The delay caused by embarrassment is worse than the click.
Your suppliers are part of your security
Any vendor holding your data extends your attack surface.
When evaluating one, ask what security measures they document, whether they encrypt data in transit and at rest, how access is controlled, and what their breach procedure is. Serious vendors publish this. Mirage Cloud, for instance, sets out its technical and organisational measures in an annex to its data processing agreement covering encryption, access control, data segregation, logging, backups and incident procedures.
Be alert to overclaiming here. "End-to-end encryption" specifically means the provider cannot read the content, and a great many products claim it while describing TLS plus encryption at rest, which is standard practice and something different. If the marketing page and the security annex disagree, believe the annex.
Where to start
If you do nothing else this month: turn on multi-factor authentication for email and banking, and write down the payment verification rule.
Those two take an hour and prevent most of what actually happens to small businesses.
Comments
Log in or sign up to join the conversation.