A Cyber Security Checklist for Small and Growing Businesses
You do not need a security department to be hard to attack. Ten practical steps, most of them free, that protect a small or growing business from the attacks that actually happen.

Small businesses often assume they are too small to be a target. Attackers disagree. Most attacks are not aimed at a particular company; they are aimed at whoever is easiest, and a business with no security basics is easy. The good news is that the basics are affordable, and most of them are free.
Here are ten steps, roughly in order of impact.
1. Turn on multi-factor authentication
Start with email, then banking, accounting, cloud storage and social media. A second sign-in step stops most attacks that rely on stolen passwords. If you do only one thing on this list, do this.
2. Use strong, unique passwords
A different password for every account, ideally long passphrases stored in a password manager. Reused passwords turn one leak into many breaches.
3. Protect how you pay and get paid
Never change supplier bank details on the strength of an email. Confirm by phone on a known number, and require two people to approve new payees and large transfers. Payment fraud is one of the most expensive attacks a small business can suffer.
4. Keep everything updated
Turn on automatic updates for computers, phones, browsers and business software. Replace devices that no longer receive security updates.
5. Back up, and test it
Keep regular backups of important data, with at least one copy that is offline or cannot be changed from your main systems. Try restoring a file now and then to prove it works.
6. Give people only the access they need
Not everyone needs to be an administrator or see every folder. Remove access promptly when someone leaves or changes role.
7. Train your team, briefly and often
Your people are your front door. Short, regular lessons on phishing, payment fraud and passwords, plus realistic practice, do more than a single long session.
8. Make reporting easy
Everyone should know exactly who to tell when something looks wrong or they think they clicked something, and that they will not be blamed for reporting.
9. Secure your devices
Screen locks, encrypted disks and the ability to locate or wipe a lost laptop or phone. Keep work and personal use separate where you can.
10. Write down what to do if something goes wrong
One page is enough: who to call for IT help, your bank's fraud line, how to reach your staff if email is down, and where your backups are. Keep a printed copy.
Start this week: steps 1, 3 and 4 cost nothing and can be done in an afternoon. They close the doors attackers use most often.
Know where you stand
A checklist tells you what to do; it does not tell you how your people would actually respond to a convincing attack. CyberWatch AI gives growing businesses a simple way to find out: realistic phishing simulations, short training, a one-step way for staff to report suspicious messages, and one security score that shows whether things are improving. You can also request a free assessment to see where you stand today.


