Squish/attentionSquish →

Seven Small Business IT Security Mistakes (and How to Fix Each One)

The small business IT security mistakes we see most often are ordinary, not exotic. Here are seven of them, why each one matters, and the fix for every single one.

By Squish··4 min read

The small business IT security mistakes that actually cause damage are almost never clever. Nobody gets taken down by a movie hacker. They get taken down by a password that was reused, a backup nobody checked, or an invoice that looked close enough to real.

Here are the seven we see most, and what to do about each.

1. Nobody has tested the backups

Having backups and having working backups are different things, and most businesses find out which one they have on the worst possible day.

Backups fail quietly. A job stops running, a drive fills up, a folder gets renamed, and the dashboard keeps showing green because nothing told it otherwise.

The fix: restore something on purpose. Pick a file, bring it back, confirm it opens. Do it once a quarter. If you cannot restore a test file in a calm moment, you will not restore your business in a panic.

2. The domain has no email protection

Three records — SPF, DKIM, and DMARC — prove that email claiming to come from your domain really did. Without them, anyone can send mail that appears to be from your business, and your legitimate email is likelier to land in spam.

This one is remarkably common, because nothing visibly breaks when it is missing. You just quietly have no defence against being impersonated.

The fix: check whether those three records exist. Our Tool Shed will tell you in seconds, free, without a signup. If they are missing, they need setting up properly rather than approximately.

3. One password, everywhere

The problem is not that people pick bad passwords. It is that they pick one decent password and use it in forty places. When any one of those forty gets breached, all forty are open.

The fix: a password manager, and multi-factor authentication on email and banking at minimum. Multi-factor is the single highest-value security change most businesses can make, and it is usually free.

4. Everyone is an administrator

It is easier to give everyone full access than to think about who needs what. Then someone clicks the wrong link, and whatever they can reach, the problem can reach too.

The fix: give people the access their job requires. Review it when someone changes role, and remove it the day they leave — not the following month.

5. The former employee still has access

Offboarding tends to cover the laptop and the building key, and miss the eleven online accounts.

The fix: keep a list of every service your business uses and who can get into it. Boring to make once, invaluable every time somebody leaves.

6. Nobody is watching for the invoice scam

The most expensive attack on a small business is rarely technical. Somebody emails your finance person, looks like a supplier or like you, and asks for a payment to a new account. It works because it is plausible and urgent, not because it is sophisticated.

The fix: a rule with no exceptions. Any change to payment details gets verified by phone, on a number you already had, before anything moves. Make it a policy so nobody has to make a judgement call under pressure.

7. It is all one person's job, informally

In most small businesses there is somebody who is good with computers and has absorbed the technology on top of their real work. Nothing is written down, nothing is monitored, and everything depends on them being available.

That is not a criticism of them. It is a single point of failure, and they usually know it better than anyone.

The fix: write down what exists — what you pay for, where it lives, who can access it. Whether you then hand it to a provider or not, the document is worth more than the decision.

The pattern

Look back over the list and notice what is missing from it: nothing here is exotic. Six of the seven are things somebody meant to get to. Security for a business your size is mostly a maintenance problem wearing a scary costume.

That is genuinely good news, because maintenance problems can be handled — either by putting a recurring reminder in a calendar, or by paying somebody to watch so you do not have to think about it.

Want to know where you stand right now? Our free Tool Shed will check your domain's email protection and security setup in a few seconds, no signup required. If you would rather have somebody look at the whole picture, ask Faber or talk to a human — we will tell you honestly what is worth fixing and what is fine.