Blog/Security basics

A Cyber Security Checklist for Small and Growing Businesses

You do not need a security department to be hard to attack. Ten practical steps, most of them free, that protect a small or growing business from the attacks that actually happen.

CyberWatch AI27 September 2026 · 2 min read
A business owner working on a laptop at a café table

Small businesses often assume they are too small to be a target. Attackers disagree. Most attacks are not aimed at a particular company; they are aimed at whoever is easiest, and a business with no security basics is easy. The good news is that the basics are affordable, and most of them are free.

Here are ten steps, roughly in order of impact.

1. Turn on multi-factor authentication

Start with email, then banking, accounting, cloud storage and social media. A second sign-in step stops most attacks that rely on stolen passwords. If you do only one thing on this list, do this.

2. Use strong, unique passwords

A different password for every account, ideally long passphrases stored in a password manager. Reused passwords turn one leak into many breaches.

3. Protect how you pay and get paid

Never change supplier bank details on the strength of an email. Confirm by phone on a known number, and require two people to approve new payees and large transfers. Payment fraud is one of the most expensive attacks a small business can suffer.

4. Keep everything updated

Turn on automatic updates for computers, phones, browsers and business software. Replace devices that no longer receive security updates.

5. Back up, and test it

Keep regular backups of important data, with at least one copy that is offline or cannot be changed from your main systems. Try restoring a file now and then to prove it works.

6. Give people only the access they need

Not everyone needs to be an administrator or see every folder. Remove access promptly when someone leaves or changes role.

7. Train your team, briefly and often

Your people are your front door. Short, regular lessons on phishing, payment fraud and passwords, plus realistic practice, do more than a single long session.

8. Make reporting easy

Everyone should know exactly who to tell when something looks wrong or they think they clicked something, and that they will not be blamed for reporting.

9. Secure your devices

Screen locks, encrypted disks and the ability to locate or wipe a lost laptop or phone. Keep work and personal use separate where you can.

10. Write down what to do if something goes wrong

One page is enough: who to call for IT help, your bank's fraud line, how to reach your staff if email is down, and where your backups are. Keep a printed copy.

Start this week: steps 1, 3 and 4 cost nothing and can be done in an afternoon. They close the doors attackers use most often.

Know where you stand

A checklist tells you what to do; it does not tell you how your people would actually respond to a convincing attack. CyberWatch AI gives growing businesses a simple way to find out: realistic phishing simulations, short training, a one-step way for staff to report suspicious messages, and one security score that shows whether things are improving. You can also request a free assessment to see where you stand today.

Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.