SecOps Digest

Small Business Cybersecurity: A Founder's Guide to the 20% That Prevents Most Incidents

8 min readSecurity Basics for Founders

Most security advice written for small companies is either a product brochure or a 300-page framework. Neither is useful when you are the founder, you have 30 people, nobody owns security, and you have roughly two hours a month to think about it.

So here is the short version. There are five things that prevent the overwhelming majority of what actually happens to companies your size. They are not exotic. Four of them are free or nearly free. Most companies have done two of them badly and none of them completely.

Do these five, in this order, and stop reading security content until they are finished.

Why small companies get hit (it isn't personal)

The single most damaging belief in small business security is we're too small to be a target. It rests on a wrong mental model: that an attacker chose you.

Almost nobody chose you. The economics of the attacks that hit companies your size are the economics of volume. A credential-stuffing script does not know what your company does. A phishing kit that harvests Microsoft 365 logins does not care whether you are a dental practice or a Series A startup — it cares that you have a Microsoft 365 login. Automated scanning finds an unpatched device on your network the same afternoon it is exposed, without a human ever deciding you were interesting.

You are not being hunted. You are being trawled. That is worse in one specific way — you cannot make yourself boring enough to be skipped — and better in another: defenses that make the automated approach fail work extremely well, because the attacker moves on rather than escalating.

Which brings us to the second wrong belief: that the risk is "hackers". For a company of your size the realistic worst cases, in order, are:

  1. Someone sends money to a criminal because an email convincingly told them to. No malware involved.
  2. An account gets taken over — usually email — and is used to run (1) against your customers and suppliers, from your real domain.
  3. Everything gets encrypted and you discover your backups were a folder that also got encrypted.

Notice that two of the three are business-process failures wearing a technology costume. Your defenses should reflect that.

Get the 31-point security checklist

The checklist, then one email a week on what changed and what a company your size should do about it.

Weekly. Unsubscribe in one click. See the checklist first.

The five controls that do most of the work

1. Multi-factor authentication, on email, first

If you do exactly one thing, do this. Email is not one account among many — it is the master key. It is where every password reset lands. An attacker with your email does not need any of your other passwords; they can mint them.

Turn on MFA for every account in Google Workspace or Microsoft 365, and enforce it — an optional rollout is a rollout that reaches about a third of your staff and never finishes. Prefer an authenticator app or, better, a passkey. SMS codes are meaningfully better than nothing and meaningfully worse than an app; use SMS only as the bridge that gets a reluctant colleague enrolled this week rather than next quarter.

Then do the same for the accounts that hold money or customer data: your bank, your payroll system, your cloud provider, your domain registrar, your CRM, your code repository.

The domain registrar deserves a special mention because it is the one everybody forgets. Whoever controls your domain controls your email, and whoever controls your email controls everything else.

Full detail: MFA for small teams: what to turn on first.

2. A backup you have actually restored from

Two distinctions decide whether you survive a bad Monday.

Sync is not backup. Dropbox, OneDrive and Google Drive replicate changes. Encryption is a change. Deletion is a change. A sync client will faithfully propagate a ransomware event to every device and, if you are unlucky with retention settings, to the cloud copy too.

A backup you have never restored is a hypothesis. The failure mode is not "we had no backups". It is "we had backups, and the restore took eleven days, and three critical systems were not in scope, and nobody knew the decryption passphrase".

So: keep a copy that the attacker cannot reach even with your administrator password — that is what "immutable" or "offline" means in practice — and restore something real from it every quarter. Put it in a calendar. Time the restore. Write down the number. That number is your actual recovery time, and it is the only honest input to any conversation about how much resilience is worth buying.

Full detail: Ransomware protection: your backup is the plan.

3. A payment-change rule nobody is allowed to skip

This is the control that prevents the single most expensive thing likely to happen to you, and it costs nothing but a decision.

The rule: no change to bank details, and no unexpected urgent payment, is ever executed on the basis of an email. Ever. It is verified by calling a number you already had on file — never a number supplied in the message — and the person who calls is not the person who received the request.

Write it down. Tell your finance person that following the rule can never get them in trouble, that skipping it can, and that this applies with particular force when the request appears to come from you and appears to be urgent. That last clause is the whole point: the scam works by manufacturing an authority gradient your employee is reluctant to check.

Full detail: Business email compromise: how a single email moves your money.

4. Automatic updates, everywhere, on by default

Attackers do not usually spend novel exploits on small companies. They use vulnerabilities that were published, patched, and then ignored — often for months. CISA maintains a public catalog of vulnerabilities known to be actively exploited in the wild, which is a fair description of what is actually being thrown at you.

Turn on automatic updates for operating systems, browsers, and phones, and set them to install rather than to notify. Do the same for anything of yours that is reachable from the internet: a VPN appliance, a firewall, a router, a self-hosted application. Internet-facing devices are the priority — they are what gets scanned within hours.

The unglamorous corollary: get rid of things you are not maintaining. The forgotten server running the 2019 marketing site is not a small problem. It is a door into your network that nobody is watching.

5. One person who owns the list of accounts

Not a security officer. Just one named person whose job includes knowing which SaaS tools exist, who administers each, and who has access to what.

You need this because the alternative — access that accumulates and never gets removed — is how a departed contractor still has your production credentials fourteen months later, and how nobody notices for another fourteen. Start by opening your Google Workspace or Microsoft 365 admin console and reading the user list out loud. Most founders find at least one account that should not exist. Then look at which apps employees have connected to that account.

Two habits fall out of this: someone leaves and their access is revoked the same day, and administrator rights are given to the two or three people who genuinely need them rather than to everyone who once asked.

Full detail: The offboarding checklist nobody writes until it's too late.

What to do in your first 30 days

If you are starting from nothing, this is a realistic sequence. None of it requires hiring anyone.

Week 1 — the two-hour block. Enforce MFA on your email tenant. Enable MFA on your bank, payroll, domain registrar, and cloud provider. Write the payment-verification rule in one paragraph and send it to whoever touches payments.

Week 2 — the account audit. List every SaaS tool the company pays for, including the ones on someone's personal card. Name an owner for each. Remove accounts belonging to people who have left. Reduce the number of administrators.

Week 3 — the backup test. Identify what would actually stop the business if it disappeared: customer data, financial records, code, the shared drive. Confirm each has a backup outside the systems it protects. Then restore one thing and time it.

Week 4 — the people part. Fifteen minutes at a team meeting, not an e-learning course. Cover three things: how to check a suspicious email, the payment rule, and — the one that matters most — that reporting a mistake fast is always the right move and will never be punished. The gap between a click and a report is where the damage compounds.

What to ignore for now

Being clear about what not to do is half the value of a list like this.

You do not need a SIEM. You do not need a penetration test — a pentest tells you how a determined expert could get in, which is not your current question; your current question is whether the front door is locked. You do not need a security awareness platform with phishing simulations, not yet; a 15-minute conversation and a no-blame reporting rule outperform a simulation program at a company where everyone knows each other. You do not need SOC 2 unless a customer is actually asking, in which case it is a sales problem with a deadline attached, not a security problem.

And you do not need a Chief Information Security Officer. What you need is for the five things above to be somebody's job.

How to tell if it's working

Security has no scoreboard, which is why it gets neglected. Use these four questions as one, and re-ask them every quarter:

  • Can any single stolen password reach anything that matters, without a second factor?
  • If everything were encrypted tonight, what is our measured — not estimated — recovery time?
  • Could an email alone cause money to leave the company?
  • Does access end when employment ends, on the same day, every time?

Four honest answers. If they are all good, you are in better shape than most companies many times your size — because most of them have a security team and still have not closed all four.

Where to go from here

Each control above has its own guide in this cluster. Start with whichever answer above made you uncomfortable — that discomfort is well-calibrated.

The other thing worth doing is staying current without making it a job. New attack patterns show up, defaults change, and a control that was adequate in 2024 sometimes is not now. That is the whole reason this newsletter exists: one issue a week, the things that changed, what to actually do about them, and nothing else.

Get the 31-point security checklist

One email a week: what changed in security, what it means for a company your size, and the one thing worth doing about it. No vendor pitches, no fear.

Weekly. Unsubscribe in one click. See the checklist first.

More on Security Basics for Founders, or browse every article.