← All news

cybersecurity

Cybersecurity basics every small business should have in place

Most small-business security problems come from a few basics left undone. Here are five habits that prevent most of them — no enterprise budget required.

When small business owners hear "cybersecurity," it usually sounds expensive, complicated, and aimed at companies much bigger than theirs. So it slides down the list — behind payroll, behind client work, behind everything that feels more urgent this week.

Here's the thing: most of the security problems we see at small businesses aren't sophisticated attacks. They're the basics left undone. One reused password. An ex-employee who still has access to the shared drive. A backup nobody has ever actually tested.

The good news is that the fixes are mostly habits, not huge purchases. Here are the five that prevent the most problems.

1. Turn on MFA — and set it up so it's not annoying

Multi-factor authentication (that second step when you sign in, usually a code on your phone) is one of the highest-value security moves a small business can make. Start with email, because email is the front door to everything else — password resets for your other accounts go there.

Yes, it adds a step. The trick is making it a small one: use an authenticator app instead of texted codes where you can, and turn it on for the accounts that matter most first — email, banking, your file storage, and anything that holds client information. You don't have to boil the ocean on day one.

2. Use a password manager (and stop sharing passwords)

If your team is reusing passwords, keeping them in a spreadsheet, or texting them to each other — you're not alone. It only takes one of those passwords leaking somewhere else to open your business up.

A password manager fixes this quietly. Everyone gets their own login, passwords are generated and stored for them, and sharing (when it's genuinely needed) happens through the tool instead of over text. It also makes offboarding much simpler, which brings us to number five.

3. Put updates on a schedule

Many everyday security problems exploit old holes that already have fixes available. Those fixes only help if they're installed.

Pick a rhythm: computers update weekly, and anything that touches the internet (routers, firewalls, your website) gets checked monthly. Put it on a calendar, assign it to a person, and treat "we'll get to it" as the risk it actually is.

4. Have backups you've actually tested

A backup you've never restored is a hope, not a backup.

Whether it's ransomware, a dead laptop, or someone deleting the wrong folder, the question is never really "do you have a backup?" It's "how quickly can you be working again?" Once or twice a year, actually restore a file or two and time it. If your important data lives in cloud services like Google Workspace or Microsoft 365, remember that those tools aren't a full backup by themselves — deleted or overwritten files can still be lost for good.

5. Clean up access — especially when someone leaves

Over time, access piles up. Former employees, old vendors, that shared login everyone uses. Each one is a door you forgot to lock.

Make a short list of your key systems — email, files, accounting, client portals — and review who has access a couple of times a year. When someone leaves, removing access should be a same-day checklist item, not an afterthought three weeks later.

What this doesn't require

None of this needs an enterprise budget or a full-time IT person. It needs an afternoon of setup, a short checklist, and a rhythm. The businesses that get this right aren't the ones with the fanciest tools — they're the ones where the basics are simply done, on purpose, on a schedule.

A practical checklist

Use this as a light audit — not a scorecard:

  • MFA on email and other accounts that hold money or client data
  • Password manager in use; no shared spreadsheets or texted passwords
  • Updates on a calendar (devices weekly; internet-facing gear monthly)
  • Backups exist and a restore has been tested in the last year
  • Key systems listed; access reviewed a couple of times a year
  • Offboarding includes same-day access removal

If several items are open, start with MFA and access cleanup — they usually give the most calm for the least fuss.

Next step

If you'd rather have someone walk through it with you, that's exactly what we do. WrightClick helps small businesses get these fundamentals in place without the jargon or the fear tactics — a practical look at what you have, what matters most, and what to fix first.

Get in touch and we can start with a practical security review.