Cybersecurity for small businesses: basics you can apply today

Screen showing the word Security with a hand-shaped cursor

Unique passwords, two-step verification, tested backups and more: basic cybersecurity measures a small business can put in place today.

You don’t need a security department to close the most obvious doors. These measures are simple, and you can apply them one at a time without being a specialist. Start by protecting what you would hate to lose most.

A different password for every account

Reusing one password is the most common shortcut and the most dangerous: if it leaks from one site, it opens all the others. Use a password manager. It creates long, unique passwords, stores them for you, and you only have to remember one master password. And don’t share passwords by message or on sticky notes stuck to the monitor.

Two-step verification

On top of the password, add a second check: a code generated by an app on your phone or a confirmation on a trusted device. If you can choose, prefer that over text messages. Turn it on first for email, because that is where every other account gets reset, then for banking, cloud storage and the business’s social media.

Keep everything updated

Updates fix security flaws that are already known. Turn on automatic updates on computers and phones, and don’t forget what you can’t see: the router, the cameras and the programs you use every day. If a device no longer gets updates, plan to replace it.

Backups you can actually restore

Follow the 3-2-1 rule. In plain words: keep three copies of your data (the original and two backups), on two different types of storage, such as an external drive and the cloud. Keep one of them away from where you work. Then comes the most important part: test them. Every so often, restore a file to confirm the backup works. And don’t leave the external drive plugged in all the time: if a virus encrypts your files, it can encrypt the backup too.

A separate WiFi network for guests

Visitors, customers and devices like TVs or cameras shouldn’t share a network with your computers and your point-of-sale system. Many routers let you create a guest network with its own password. Also change the router’s factory admin password and use WPA2 or WPA3 encryption.

Everyday accounts without administrator rights

If everyone works on administrator accounts, any malicious program someone opens has permission to install itself and change whatever it wants. Use standard accounts for daily work, and keep one administrator account, with its own password, only for installing or configuring things. Remove the accounts of people who no longer work with you.

Be wary of anything that pushes you to act fast: urgent payments, a supplier’s new bank details, files you didn’t expect or “account locked” notices. Before you click, check who really sent it and where the link goes. If in doubt, go to the site yourself by typing the address, or confirm by phone using a number you already have.

A simple plan in case something happens

Write it down today, even if it is half a page:

  1. Disconnect the affected computer from the network, by unplugging the cable or turning off its WiFi.
  2. Tell the person in charge and your IT support.
  3. Change the affected passwords from another computer you know is clean.
  4. Restore from a backup. Before paying any ransom, talk to a specialist.
  5. Write down what happened and what was done, so it doesn’t happen again.

Also keep a list of contacts handy: your IT support, your bank and your email provider.

How we can help

At iTech Los Cabos we plan, install and optimize WiFi and wired networks, and we provide technical support. If you want help putting these measures in place at your business, take a look at our networks and WiFi and IT support services.

Share on WhatsApp

Need help with your technology?

Tell us what you need and we will reply by WhatsApp, phone or email.