Small business cybersecurity: the protections that matter first.
You do not get breached because someone chose you. You get breached because an automated attack swept a million doors and yours was unlocked. Here are the locks that matter, in the order that matters, and what each one actually costs.
Almost every small-business breach traces back to the same short list of missing basics, not to a Hollywood hacker. Attackers automate: they buy leaked passwords by the million, spray them at logins, and send phishing emails to whole industries at once. The good news buried in that fact is that the defenses are also basic, mostly free, and mostly a one-time afternoon of work. The trick is doing them in the right order, because a firewall appliance means nothing if your team reuses one password across every account.
The order is the whole point
Security spending has sharply diminishing returns if you start at the wrong end. A founder who buys a fancy security product while still logging in with a reused password has spent money to feel safer without being safer. Work the list top to bottom. The first four items stop the attacks that actually happen to small firms; the rest harden what is left.
1. Multi-factor authentication, everywhere
This is the single highest-value move you can make, and it is free. Multi-factor authentication (MFA) means a password alone will not get anyone in; they also need a code from your phone or a tap on an app. Since the most common attack is simply logging in with a password that leaked somewhere else, MFA quietly defeats the majority of real-world break-ins. Turn it on for email first, then banking, then everything that offers it. On Microsoft 365 or Google Workspace an administrator can require it for the whole team in one setting.
2. A password manager for every person
Reused passwords are how one leaked account becomes ten. A password manager generates a long, unique password for every site and remembers it, so a breach at one vendor cannot cascade into your email and your bank. It costs a few dollars per person per month and removes the single most common human weakness in one step. The rule that follows for free: every account gets its own password, and none of them live in a spreadsheet or a sticky note.
3. Full-disk encryption on every device
A laptop left in a rideshare should be a bad afternoon, not a data breach. Full-disk encryption scrambles everything on the drive so a lost or stolen device is a useless brick to whoever finds it. It is built into modern operating systems (FileVault on Mac, BitLocker on Windows) and costs nothing but a checkbox and a saved recovery key. Turn it on before a device ever carries client information.
4. Backups you have actually tested
Ransomware and a spilled coffee end the same way if your only copy is gone. Real backup means important files exist in more than one place, one of them offline or version-controlled, and you have restored a file from it at least once to prove it works. Microsoft 365 and Google Workspace keep file history and are a strong start, but confirm the retention window and test the restore path. A backup you have never restored from is a hope, not a plan.
5. Least privilege: who can reach what
Not everyone needs access to everything, and the day someone leaves is the day that matters. Give each person access to only what their job needs, use shared company accounts rather than personal ones for business tools, and keep a short list of who can reach the sensitive systems. When a laptop is lost or a contractor rolls off, you want to revoke one identity, not chase a dozen scattered logins. This is free and lives in your Microsoft 365 or Google admin console.
6. Automatic updates, turned on and left on
Most malware walks through a hole that was patched months earlier on machines that installed updates. Set operating systems, browsers, and phones to update themselves, and do not defer them for weeks. It is the cheapest protection there is: the work is already done by the vendor, and all you have to do is stop postponing it.
7. Lock down your email domain
Email is both your most-used tool and the most common way attackers impersonate you to your own clients. Three DNS records (SPF, DKIM, and DMARC) let receivers verify that mail claiming to be from you really is, and a strict DMARC policy makes it far harder for anyone to spoof your domain in a phishing attack aimed at your customers. We wrote the full plain-English walkthrough in business email that actually lands.
8. Train the humans, briefly and often
The most sophisticated attack most small firms will ever face is a convincing email asking someone to click a link, pay a fake invoice, or approve an MFA prompt they did not start. No product fixes this completely; a five-minute habit does. Teach the team to slow down on anything urgent about money or passwords, to verify unusual requests on a second channel, and to never approve a login prompt they did not trigger. Awareness is free and pays for itself the first time it stops a fraudulent wire.
9. A one-page incident plan
When something goes wrong, the difference between a scare and a catastrophe is knowing what to do in the first hour. Write one page: who to call, how to lock accounts and reset passwords, where the backups are and how to restore them, and who tells clients if their information was involved. You do not need a binder. You need one page that exists before you need it.
What this actually costs
Add it up and the picture is reassuring. Items 1, 3, 5, 6, 8, and 9 cost nothing but time. Item 2, the password manager, is a few dollars per person per month. Item 4, backup, is usually already inside the Microsoft 365 or Google Workspace subscription you pay for anyway. Item 7 is a one-time DNS job. There is no line here that requires an enterprise budget, and every line prevents a category of loss that routinely costs small firms far more than the fix.
The mistake we see most
The classic pattern is security theater: a business buys a product that sounds protective, feels safer, and skips the boring free basics that would actually have stopped the breach. The attackers are not defeating clever defenses. They are walking through unlocked doors. Close the doors first, in order, and the expensive tools become a genuine next step rather than an anxious substitute for the fundamentals.
What we do here at Alpha Momin
Locking down the basics is part of our IT and admin setup: multi-factor authentication enforced for the whole team, devices shipped with encryption and automatic updates, a company password manager, sharing set to least privilege, tested backups, and email authentication ramped to a strict policy. Done once, documented in plain English, and checked after. It is the "secure your foundation" half of what we do, and it is usually the fastest peace of mind a founder can buy.
Frequently asked
What is the single most important cybersecurity step for a small business?
Turn on multi-factor authentication everywhere, starting with email. Most break-ins are not clever hacks; they are someone logging in with a password that leaked in an unrelated breach. Multi-factor authentication stops a stolen password from being enough on its own, and on Microsoft 365 or Google Workspace it is free and takes an afternoon to enforce for the whole team.
How much should a small business spend on cybersecurity?
The protections that prevent the most damage are free or nearly free: multi-factor authentication, device encryption, automatic updates, and staff awareness cost nothing but time. A password manager runs a few dollars per person per month, and tested cloud backup is often already included in your Microsoft 365 or Google Workspace plan. Serious spending only becomes necessary at a scale most small firms have not reached; buying it before the basics are in place is fitting a vault door to a house with open windows.
Does a small business need cyber insurance?
For many small businesses it is worth having, but insurers increasingly require the basics (multi-factor authentication, backups, a patching routine) before they will pay a claim, and sometimes before they will write the policy at all. Put the free protections in place first; they lower both your risk and your premium.
Is Microsoft 365 or Google Workspace secure enough on its own?
The platform is secure; the default settings are not the whole job. Both give you enterprise-grade tools, but multi-factor authentication, least-privilege sharing, and backup retention have to be turned on and configured. Out of the box you have a strong lock that nobody has yet decided to actually engage.
This post is general information, not a security audit. Every business has its own systems and risks; matching these steps to yours is what the discovery call is for.
Want the basics locked down without the jargon?
Tell us what your team uses and where it feels exposed. We will tell you exactly what to fix first, within one business day.