Cybersecurity

The Five Security Things That Actually Matter for Small Businesses

Most cybersecurity advice is written for companies with a security team. These are the five things I'd put in place first at a small business, in order, with the question to ask your IT provider about each one.

October is Cybersecurity Awareness Month, so you will see a lot of security advice over the next few weeks. Most of it is written for organizations with a security team, and it is read by owners who already have a full-time job.

So here is the short list. These are the five things I'd do first, in order, with the question to ask your IT provider about each one and the answer that should make you look harder. If all five are really in place, you've closed off most of what actually happens to businesses your size.

Multi-factor authentication on email and remote access

This is first because a stolen password is still one of the most common ways small business incidents start. Multi-factor authentication (a code or a phone prompt on top of the password) means a stolen password alone doesn't get anyone in.

Turn it on for email first. After that, add it to your administrator accounts and to anything that reaches your systems from outside the office. Everything else can follow later.

People push back on this one because they remember it being irritating. Current setups prompt far less often than the version that annoyed everyone a few years ago, and most of the daily friction comes down to how it is configured. We wrote about how to set it up without a daily fight, because that's what decides whether your staff keep using it.

Ask your provider which accounts don't have it yet, and why. Look harder if you get a general reassurance instead of a list. In my experience there's always a list, and the exceptions are where the risk is.

Backups you have actually restored from

I put this second because it's what turns a disaster into a bad week. By backups I mean ones that someone has recently restored from on purpose, and that person should be able to tell you how long it took.

The usual failure is a backup that ran every night for two years while missing the one thing you needed. The other is a backup that takes eleven days to restore, which for most businesses is about the same as having none. We covered why the backup you have is often not the backup you think you have in more detail.

Ask when you last restored something from backup, and how long it took. Look harder if nobody can name a date. "They run every night and we get alerts" tells you about the backup. It tells you nothing about a restore.

Supported software and current updates

I put this third because it is entirely preventable, and it shows up on every cyber insurance questionnaire I've seen.

There are two parts. First, everything you run should still get security updates from the company that makes it. That's a specific problem for anyone still running Windows 10, which stopped getting free security updates on October 14, 2025. Second, the updates that are available should actually be installed, on a patching schedule someone owns, for your applications as well as the operating system.

Ask what you're running that no longer gets security updates, and what the plan is for it. Look harder if the answer is that everything is fine. In a business that's been around a few years there's nearly always something, and a provider who has looked will know what it is.

Accounts and administrator rights

This is fourth, and it is the one small businesses skip most often because it feels like paperwork. Here's what I'd check:

  • Everyone has their own account instead of sharing one.
  • Everyday accounts don't have administrator rights, which limits what a mistake or an intrusion can do.
  • Accounts for people who have left are disabled in your main system.
  • Those same accounts are also disabled in the applications outside your main system, which is the half that usually gets missed.

Ask to see the list of active accounts next to the list of people who left this year. Look harder if the two lists overlap. This is the easiest check in this post for a non-technical owner, because you know who works here.

A written rule about changing payment details

This is fifth, and it is the only item that isn't technical at all.

The fraud that costs small businesses the most is a convincing email asking for a payment or a change of bank details, sent to someone who has no reason to be suspicious, and it needs no malware at all. No security product stops a legitimate employee from making a legitimate payment to the wrong account.

What stops it is one rule everyone knows. Payment details never change because of an email, and any request to change them gets confirmed by phone, on a number you already had. It costs nothing, and the person who actually processes payments needs to know it as well as the owner.

This is still the gap I see most often in otherwise well-run businesses. Ask what your rule is when a supplier emails about new bank details. Look harder if nobody has one, or if the rule lives only in your head.

What didn't make the list

Plenty of reasonable measures didn't, and one is worth naming: security awareness training. It helps, and I'm not against it.

I put it sixth because a trained employee with no second factor on their email can still give away their password to one convincing message. It is also the item most often bought instead of the five above, when it should be bought in addition to them.

How to use the five questions

Take them to whoever handles your technology and ask them in one conversation. It should take about twenty minutes. You are not auditing anyone, and you do not need to understand the technical detail behind the answers.

I would listen for one thing: whether the answers are specific. Dates, lists, names, and documents mean someone is looking at your environment. General reassurance means someone is answering from memory.

If you'd like the answers written down, that's what an assessment produces, and you keep it whatever you decide next. Or book a free 15-minute call and we'll go through the five questions with you.

  • Fast Track 50 Emerging Business Nominee, 2025
  • Top 3 Computer Support, Lake County, 2025
  • CyberCert SMB1001 Bronze
  • MSPAlliance member
  • Lenovo Partner
  • Microsoft Partner
  • Dell Partner
  • More than 20 years of experience
  • Managed services since 2010
  • Based in Northeast Ohio
  • Offices in Lake and Summit counties
  • Owner operated and independent
  • CMMC and HIPAA experience