Five cyber security basics small businesses still get wrong
Most of the security problems we’re called out to fix aren’t sophisticated. They’re
ordinary gaps that nobody got around to closing. Here are the five we run into most,
and what to do about each.
1. Multi-factor authentication is on for some accounts, not all
Turning on MFA for your email and stopping there is common. The accounts that get
targeted next are the ones tied to money and identity: your accounting software, your
domain registrar, your payment processor, and the Microsoft or Google admin account
that can reset everyone else’s password. If an attacker gets the admin account, MFA on
the individual mailboxes doesn’t help much.
Make a list of every service that holds customer data or can move money, and check
each one individually. It’s a half-hour job.
2. Backups run, but nobody has ever restored one
A backup you haven’t tested is a guess. We’ve seen backups that had been “running”
for two years while silently skipping the folder that mattered, and cloud sync mistaken
for backup — which it isn’t, because sync faithfully copies the encryption when
ransomware hits.
Pick one real file, restore it somewhere harmless, and confirm it opens. Do that
twice a year and you’ll know where you stand.
3. Staff can’t tell a real login page from a fake one
Modern phishing pages are pixel-accurate copies. The reliable tell isn’t the design,
it’s the address bar — and the habit worth teaching is simple: never log in from a link
in an email. Navigate to the site yourself, or use a bookmark. If someone does enter
credentials on a suspect page, change that password immediately and check for new
mailbox forwarding rules, which is the first thing attackers set up.
4. Old devices are still on the network
The laptop of someone who left last year. The tablet in the back room running an
operating system that stopped getting updates. The old router still broadcasting a
guest network with a password on a sticky note. Each one is a way in that nobody is
watching.
Walk the office once a year and write down everything that connects to your network.
Anything you can’t account for gets removed or updated.
5. One password, reused everywhere
When a service you signed up for years ago gets breached, that password gets tried
against everything else. This is the single most common way small businesses get
compromised, and a password manager removes it entirely — staff only have to remember
one password, and every other login becomes unique.
Where to draw the line yourself
All five are things a business owner can genuinely handle in an afternoon, and we’d
rather you did than paid someone. What’s harder to do yourself is the ongoing part —
watching for unusual logins, keeping patching current across every machine, and
responding when something does happen at 11pm on a Friday.
If you’d rather that ran continuously than got checked once, Secure Nerds handles managed IT
and security for small businesses and is worth a conversation. For anything hands-on in
Brisbane — a device that’s behaving oddly, a setup that needs sorting out properly —
that’s us, and you can reach us on 1300 600 004.