Cybersecurity

Cybersecurity basics every growing business should cover

Security programs often become shopping lists. A growing business usually gets more value from doing the basics consistently than from buying a long list of tools that nobody owns.

Know what you are protecting

Keep a basic record of systems, devices, cloud services, important data, administrators, and external providers. It does not need to be perfect. It needs to be good enough to answer: what would hurt the business if it stopped or leaked?

Protect accounts first

Use multi-factor authentication for email, remote access, finance, cloud administration, and any system holding sensitive information. Remove shared accounts where practical. Give administrators a separate account for privileged work, and review access when people change roles or leave.

Keep software and devices current

Decide who owns updates, how quickly important security patches should be installed, and how exceptions are tracked. Unsupported systems need a replacement plan or additional controls because fixes may no longer be available.

Make backups harder to destroy

Backups should cover the information and systems needed to resume work. Keep at least one protected copy that an attacker using a normal administrator account cannot erase. Test restoration. A successful backup job is not the same as a successful recovery.

Secure email and endpoints

Email remains a common route into businesses. Use modern spam and phishing protection, block risky attachment types where appropriate, and make it easy for staff to report suspicious messages. Managed endpoint protection should be installed, monitored, and reviewed rather than simply licensed.

Plan for the first hour of an incident

Write down who should be contacted, who can make decisions, how staff will communicate if normal systems are unavailable, and where insurer, legal, technical, and law-enforcement details are kept.

Keep the incident contact list somewhere that does not depend on the systems it is meant to help recover.

Review suppliers

Ask important technology suppliers how they protect access, notify customers of incidents, back up data, and support recovery. Record where your information is stored and how it can be exported if the relationship ends.

Give staff a simple route to ask

Security awareness works best when staff know how to pause and check. Avoid training that only tries to catch people out. Explain the few warning signs that matter and respond constructively when someone reports a mistake quickly.

What to do next

Choose three gaps that could cause the most harm, give each one an owner and date, and review progress monthly. A short list that gets finished is better than a large policy nobody uses.