What Actually Keeps a Small Business Secure

What Actually Keeps a Small Business Secure

Ask five IT providers what “cybersecurity” means and you’ll get five different marketing pitches. Most of them aren’t wrong, exactly, they’re just long lists of tools and acronyms that don’t tell you which ones actually matter for a business your size. This is the shorter version: what genuinely keeps a small or medium business secure, in roughly the order it’s worth doing it in.

Multi-Factor Authentication, With One Caveat

If you do nothing else on this list, do this one. MFA is the single biggest lever available, it stops the overwhelming majority of account takeovers even when a password has already been stolen or guessed.

The caveat is that MFA itself has become a target. “MFA fatigue” attacks work by bombarding a user with approval requests until, out of irritation or habit, they tap approve without really looking. It’s not a flaw in MFA, it’s a flaw in how people respond to friction. The fix isn’t abandoning MFA, it’s using number-matching or app-based approval rather than a simple accept-or-deny push, and making sure your team knows that a flood of unexpected login requests is itself the warning sign, not something to just clear and move on from.

Backups That Are Actually Backups

Every business we talk to already has backups. Fewer have actually tested whether those backups would get them back up and running. A backup job that’s run successfully every night for two years, and a backup you can genuinely recover from, are not automatically the same thing. Corruption, misconfiguration, and silent failures tend to go unnoticed for exactly as long as nobody’s tried a real restore.

The practical version: back up what actually matters, keep at least one copy somewhere genuinely separate from your main systems, so a single incident can’t take out both, and test a real restore on a schedule, not just when something’s already gone wrong. If the last time anyone checked was “when we first set it up,” that’s worth fixing before anything else on this list.

Email Authentication, Because It’s Cheap and It Works

Configuring SPF, DKIM, and DMARC properly does two things: it stops your own emails from getting flagged as spam, and it makes it much harder for someone to send a convincing fake email that looks like it’s come from your business. It’s one of the lower-effort items here relative to what it actually protects against. We’ve written a full guide to why your emails land in junk, including how to check your own setup.

What Happens If Something Gets Through Anyway

No list of precautions gets you to zero risk, so it’s worth having a rough idea of what the first hour after something goes wrong actually looks like: isolate the affected device from the network rather than switching it off outright, you may lose evidence you need later, work out what’s actually been affected before making changes, and contact your IT provider immediately rather than trying to quietly fix it yourself first. A recent survey of Welsh SMEs found that 66% have already experienced a cybersecurity incident, yet 41% have no formal incident response strategy (source). Having even a basic plan, who to call, what to isolate, what not to do, puts you ahead of most.

Cyber Insurance Isn’t a Substitute, and Insurers Know It

Cyber insurance is worth having, but it’s increasingly conditional. Insurers are asking harder questions before they’ll pay out: was MFA actually enabled, were backups actually tested, was there a real incident response process in place. A policy bought without the underlying security behind it is a policy that may not pay when you actually need it to. The practical items above are largely the same ones insurers are starting to require as standard.

Certification as Proof, Not Just Protection

Cyber Essentials certification forces you through most of the items on this list in a structured way, and it gives you something concrete to show clients, insurers, and public sector procurement teams who ask. We’ve written about what actually trips businesses up during certification, most of it turns out to be about tidying up existing gaps rather than adding anything genuinely new.

Where to Start

If none of this is in place yet, start with MFA and a real backup test. Both are quick to check, and both close the gaps most likely to actually hurt you. Everything else on this list is worth doing, but those two are worth doing this week.

If you’d like us to look at where your business actually stands against this list, get in touch, or read more about our cyber security services.