July 19, 2026 · by David Gilbert · 3 min read · Cyber Security
Cyber security advice for small businesses often comes in two unhelpful flavours: vague reassurance that doesn't tell you anything to actually do, or dense technical jargon clearly written for someone with an IT department behind them. Neither helps the small business owner sitting across from me who just wants to know what to actually do this week. So here's the real checklist, in the order I genuinely think matters most.
1. A Password Manager and Unique Passwords
I've written about this in detail elsewhere, but it tops every list I give clients because it closes off the single most common way small businesses get compromised: a reused password leaking from some unrelated breach and unlocking something that actually matters.
2. Multi-Factor Authentication on Email and Banking
If someone gets your password anyway, MFA is usually what stands between "minor inconvenience" and "actual disaster." It takes minutes to set up on most platforms and is, without close competition, the best security-improvement-to-effort ratio available to any small business right now.
3. Proper, Tested Backups
Not a backup that exists somewhere in theory — a backup you've actually tested by restoring a file from it recently. I've seen businesses discover, mid-crisis, that their "backup" had been silently failing for months. Ransomware and hardware failure both become survivable inconveniences instead of business-ending events when backups are genuinely solid.
4. A Real Policy on Verifying Unusual Requests
Anything involving money, passwords, or access changes gets verified through a second channel before it's actioned — no exceptions, regardless of how urgent or how convincing the request sounds, regardless of who it appears to be from. This single habit defeats the overwhelming majority of business email compromise and impersonation scams I see, including the increasingly convincing AI-driven ones.
5. Keep Software Updated
Boring, I know. But a meaningful share of real-world breaches exploit known vulnerabilities that had a patch available for months before the attack. Turning on automatic updates where you reasonably can is a one-time decision that quietly protects you on an ongoing basis.
6. Basic Staff Awareness, If You Have a Team
Not a dense annual training video nobody retains a word of. A short, occasional, realistic conversation about what a phishing email or a suspicious phone call actually looks like in practice, using genuine recent examples rather than generic warnings. Five minutes of real conversation beats an hour of generic slides.
7. Know Who to Call Before You Need Them
Decide, before any incident happens, who you'd actually contact if something went wrong — and make sure more than one person in the business actually knows. The worst time to be searching for help is mid-incident, panicking, with the one person who knows the systems unreachable.
What's Deliberately Not on This List
Expensive enterprise-grade security software most small businesses don't need, complex policies nobody will actually follow, and anything that requires a dedicated IT staff member to maintain properly. This list is built around real small business constraints — limited time, limited budget, no internal IT department — not a corporate security framework copy-pasted down to a smaller scale.
The Honest Summary
None of this guarantees you'll never have an incident. Nothing does. What it does is close off the overwhelming majority of how small businesses actually get compromised, which in my experience is almost never some highly sophisticated, unstoppable attack — it's one of these seven boring, fixable things, left unaddressed for too long.