Skip to content
Mounteyes
All guides

Cybersecurity tips for small businesses

10 min readUpdated: Small Business

A small business does not get attacked less, it gets attacked with less effort. Almost every incident traces back to one of five gaps, and none of the fixes needs a security team.

The short version

  • Shared logins are the most common root cause. Give everyone their own account.
  • Verify every change of bank details by phone, on a number you already had.
  • Backups only count if you have restored from one and it worked.
  • Remove access the day someone leaves, not at the end of the month.

Accounts and access come first

One shared login for the company email, the social accounts or the billing portal is the single most common cause of a small-business incident. It cannot be audited, it never gets changed when someone leaves, and it usually has no second factor because that would inconvenience everyone.

Give every person their own account with their own 2FA. Grant the least access that lets them do the job, and use the platform's own delegation features — Instagram and Facebook business tools, Google Workspace roles — instead of handing out a password.

Keep a short written list of every service the business depends on, who owns it, and who has access. When someone leaves, that list is the difference between removing access in ten minutes and discovering an active login a year later.

Invoice and payment fraud

This is where small businesses lose the most money. An email that appears to come from a supplier, or from the owner, asks for a payment or announces new bank details. The wording is normal, the timing is plausible, and often a real email thread has been read first.

One rule stops nearly all of it: any change of bank details, and any unusual payment request, is verified by voice on a number you already had on file — never a number in the email. Say it out loud as a policy so that a junior employee is expected to check rather than feeling awkward about it.

Add a second approver for payments over a threshold you choose, and be suspicious of urgency and secrecy together. "Do this now and do not discuss it" is not how legitimate business works.

Backups you have actually tested

Ransomware and a failed hard drive have the same cure. Keep at least one backup off the machine and one copy that cannot be edited or deleted by a compromised account, and check that a restore genuinely works — an untested backup is a hope, not a plan. Include what people forget: the website and its database, accounting data, customer records, and anything living only in one person's laptop or WhatsApp.

Devices and updates

Turn on automatic updates for operating systems, browsers and phones, and enable full-disk encryption on every laptop — it is a setting, not a project, and it means a stolen laptop is a hardware loss rather than a data breach. Require a screen lock. Keep business data off personal devices where you can, and if you cannot, make sure you can revoke access to it remotely.

Your website and customer data

Keep the platform and plugins updated, since almost every website compromise is a known vulnerability that was left unpatched. Use unique admin credentials with 2FA, and remove old admin accounts. Collect the minimum customer data you need — data you never stored cannot leak — and if you take payments, use a hosted checkout so card details never touch your systems. Our website security checklist and headers checker cover the technical basics.

A one-page incident plan

Write down, before anything happens: who to call, which accounts to lock first, where the backups are, how to reach customers if email is down, and who speaks for the business. A plan written during an incident is written badly.

If money has moved, report it at cybercrime.gov.in or on 1930 immediately and involve your bank. Preserve evidence rather than wiping machines. Then tell affected customers plainly and early — the reputational damage comes from the concealment far more than from the incident.

Staff awareness, done usefully

A once-a-year lecture changes nothing. What works is a short, specific set of rules everyone knows — verify bank changes by phone, never install remote-access software for a caller, report a mistake immediately without blame — and a culture where telling someone about a clicked link takes seconds rather than courage. Incidents get expensive during the hours people spend hoping it was nothing.

Nothing on this site will ever ask for your password, OTP or recovery codes.

Related guides

Want this handled for you?

Our engineers do this work for businesses every day, on monitoring platforms built to catch it earlier. Describe your situation and we will tell you what would actually help.

Talk to Our Security Team