CrestPointCPAS
All InsightsRisk & Technology

Cybersecurity Basics Every Small Business Should Have in Place

Small businesses are frequent targets precisely because their defenses tend to be weaker. A handful of foundational controls address most of the common attack paths.

5 min read

Small and mid-sized businesses are attractive targets for cybercriminals for a simple reason: they often hold valuable data — customer records, banking information, employee data — while having far less security infrastructure than a large enterprise. Sophisticated defenses aren't usually what's missing; a handful of foundational controls address most of the common ways businesses actually get compromised.

Multi-factor authentication, everywhere it's available

A password alone is one of the weakest security controls in common use, since passwords are reused, phished, and leaked in breaches unrelated to the business itself. Multi-factor authentication — requiring a second factor, like a code from an app or a physical key, in addition to a password — closes off the large majority of account takeover attempts even when a password has been compromised. It should be enabled on email, banking and financial platforms, and accounting software, and treated as a requirement rather than an optional convenience.

Patching and update discipline

Many breaches don't exploit a novel vulnerability — they exploit a known one that a patch already existed for, on a system that hadn't been updated. A basic, enforced process for keeping operating systems, software, and firmware current closes off a significant share of opportunistic attacks, which tend to target known, unpatched vulnerabilities rather than developing something new.

Employee awareness, focused on phishing and payment fraud

Business email compromise — where an attacker impersonates an executive, vendor, or client to redirect a payment or extract sensitive information — remains one of the more financially damaging categories of fraud a small business can encounter, and it succeeds through social engineering rather than a technical exploit. Training that teaches employees to verify payment or banking detail changes through a second channel — a phone call to a known number, not a reply to the email in question — addresses this risk more directly than most technical controls can.

A real backup strategy

Backups are only useful if they're tested, and if at least one copy is stored somewhere an attacker who has already compromised the network can't reach. A commonly cited standard is the "3-2-1" approach: at least three copies of critical data, on two different types of storage media, with at least one copy stored offsite or offline. Ransomware specifically targets connected backups, so a backup that's always online and always accessible from the compromised network offers less protection than the name suggests.

A basic incident response plan

Knowing who to call, what to shut down, and how to communicate with customers and employees in the first hours of a suspected breach makes a measurable difference in how much damage is contained. This doesn't need to be an elaborate document — a short, specific plan that's actually been reviewed by the people who would execute it is far more useful than a comprehensive one that sits unread. Many businesses also find that cyber insurance, reviewed with a clear understanding of what it actually covers and excludes, is a reasonable complement to these controls rather than a substitute for them.

This article is provided for general informational purposes only and does not constitute tax, legal, accounting, or financial advice. Rules, limits, and thresholds referenced here change over time; confirm current figures and how they apply to your specific situation with a CrestPoint CPAs advisor.

Let's talk about where your business is headed.

Tell us about your business and we'll connect you with the right team — no pressure, just a conversation.