Working securely: the three habits that make the most difference
Cybersecurity sounds like something for large companies with their own IT department. In practice it is smaller businesses that are most exposed, simply because less time and knowledge goes into it.
To many small businesses, cybersecurity sounds like something for large companies with their own IT department. In practice it is precisely the smaller ones that are most exposed, simply because less time, budget and knowledge goes into it. Below is what we encounter, and what in our experience makes the most difference.
What we see going wrong at small businesses
One password for nearly everything. The same password for the mailbox, the accounting software and all kinds of online accounts. As soon as that one password leaks somewhere, for instance through a breach at a third party, the door is open to every other application.
No two-step verification. Often available in the software already in use, but never switched on because it feels like an awkward extra step. That one step is usually the difference between an attempt that fails and an account that is genuinely taken over.
Too little suspicion about email. A message that looks urgent and official, supposedly from the bank, a supplier or even the owner, is trusted too readily, especially when someone is busy. Phishing deliberately exploits that.
Updates left waiting. Security updates get postponed because a restart is inconvenient right now. Those are often exactly the updates that close vulnerabilities already being actively exploited.
Backups that exist but have never been tested. It is assumed the backup system works, without ever checking that something can actually be restored. Only when it is needed does it sometimes emerge that it had been failing for months without anyone noticing.
Too much access for too many people. Everyone an administrator on their own device, or everyone with access to every shared folder, even where the role does not require it. The more people who can reach sensitive data, the greater the risk from a human error or a compromised account.
The three habits that pay off most
Two-step verification, everywhere it is available. By some distance the most effective and cheapest measure there is. Even when a password leaks, an account stays protected as long as that second step is active. We recommend it as standard as the first concrete step.
Stopping to think before you click, and teaching that to the whole team. Not a technical measure but a reflex: when in doubt about an email, link or attachment, check through another channel that it really is the right sender. This habit costs nothing and stops a large share of incidents before they start.
Genuinely testing, regularly, that your backup works. Not just checking that the backup runs, but actually restoring a file or a full environment, to be sure it works when it matters. A backup that has never been tested is often no more than a false sense of security.
A real example
At a business with around ten staff, someone in the accounts department received an email that at first glance looked like an ordinary invoice from a known supplier: the same layout, the same writing style as other messages from that supplier. The sender address looked almost identical, bar one small detail nobody noticed.
The employee opened the attachment, which installed malicious software in the background. That same day someone attempted to log in to her mailbox from an unusual location. That attempt failed, because two-step verification was active on that account.
Without that extra layer, the intruder would probably have gained access to the entire mailbox, including earlier invoices and client details: material perfectly suited to building even more convincing phishing attempts against others.
The device did have to be thoroughly checked and cleaned, and a day was lost to investigation and recovery. Annoying, but contained. Without two-step verification this could have looked very different, with possible access to the whole mail environment and the risk of forged invoices carrying altered account numbers. We have seen that last scenario happen at other companies, with financial damage as a result.
This incident shows in one go why those three habits matter: the phishing email itself was hard to avoid, a critical eye could have stopped it before it went wrong, and two-step verification stopped it anyway once it already had.
Want to know how secure your current setup really is? Get in touch for a no-obligation review. A few targeted changes are often enough to reduce the risk substantially.