· 4 min read
Five security steps most small businesses are still missing
Almost every incident we are asked to help with starts in the same place: someone's password ended up somewhere it should not have, or a convincing email persuaded a member of staff to do something they would not normally do. Sophisticated attacks exist, but they are rarely what hits a ten-person office.
The first step is multi-factor authentication — a second sign-in step, usually a prompt on a phone. It is the single biggest difference between a stolen password being an inconvenience and being a serious incident. Turn it on for everyone, including the director who finds it annoying.
The second is knowing which devices are allowed to reach your data. If any laptop anywhere can sign in with the right password, you have no boundary. Device management lets you say: company-managed, up to date, encrypted, or no access.
The third is backups you have actually restored. A backup that has never been tested is a hope, not a plan. We restore a sample regularly so there are no surprises on the day it matters.
The fourth is leaver process. Accounts left open after someone moves on are a common and entirely avoidable weakness, particularly where staff turnover is high.
The fifth is telling your team what a suspicious message looks like — briefly, in plain English, more than once a year. People are not the weak link when they know what to expect.
None of this is expensive. Most of it uses licences you already pay for. If you would like to know which of the five you are missing, a free IT review will tell you.