Small businesses often assume they're too small to be attacked. It's the opposite: attackers love small businesses precisely because nobody's watching the doors. The good news — most successful attacks exploit missing basics, not genius hacking. These seven habits are free or nearly free, and none of them need an IT department.
1. Use a password manager
The single biggest upgrade available. A password manager (Bitwarden, 1Password, and others) remembers a different strong password for every account, so a leak at one service doesn't unlock all the others. You memorize one master password; it handles the rest.
2. Turn on two-factor login
Two-factor authentication (2FA) means logging in takes your password plus a code from your phone. Even if someone steals your password, they can't get in. Turn it on everywhere it's offered — especially email, banking, and anywhere customer data lives. It takes two minutes per account.
3. Treat your email account as the crown jewels
Whoever controls your email can reset the password of nearly every other account you own. Give it your strongest password and 2FA first. If you protect only one thing today, protect this.
4. Install updates — actually
Those update reminders you keep postponing? They're mostly security fixes for holes attackers already know about. Set your computer, phone, and website software to update automatically where possible.
5. Keep copies of what you can't afford to lose
Customer records, invoices, your website — anything whose loss would hurt should exist in more than one place, with at least one copy somewhere else (cloud storage counts). Our guide to the 3-2-1 backup rule explains a simple system.
6. Slow down on unexpected messages
Most breaches start with a convincing email, not clever code. Any message that creates urgency — "your account will be closed", "invoice overdue", "are you available? need a favor" — deserves a suspicious second look. Our guide to spotting phishing covers the telltale signs.
7. Give people only the access they need
Does the freelancer who edited your website two years ago still have the password? Every extra person with access is an extra door. Remove old accounts, and when someone leaves, change shared passwords the same day.