A cybersecurity checklist for small businesses

    Small companies are attacked because they are reachable, not because they are interesting. The good news is that most successful attacks use a handful of routes, and closing those routes costs far less than people expect. This checklist is ordered by impact.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    Accounts first, because that is where attacks start

    The majority of small-business incidents begin with a stolen or reused password on email. Put every account into a business password manager, require multifactor authentication on email, accounting, banking and remote access, and prefer passkeys or hardware keys for administrators.

    Remove access the same day someone leaves. Dormant accounts belonging to former staff and contractors are a recurring finding in breach investigations.

    • Business password manager for everyone
    • Multifactor authentication on email, banking and accounting
    • Hardware keys or passkeys for administrator accounts
    • Same-day removal of departing staff access

    Devices and updates

    Deploy a managed endpoint product rather than consumer antivirus, so you can see which machines are protected and which are not. Bitdefender GravityZone, ESET PROTECT, Norton Small Business and Kaspersky's small office product all provide a central console at a price a small company can absorb.

    Enable automatic operating-system and browser updates, encrypt every laptop and phone, and require a screen lock. Unpatched software and an unencrypted laptop left in a taxi remain two of the most common causes of a reportable incident.

    Backups you have actually tested

    Keep at least three copies of important data on two types of storage with one held offline or otherwise not writable by everyday accounts. Ransomware groups specifically target backups that are reachable from the network.

    Test a restore once a quarter. A backup that has never been restored is a hypothesis, and the moment to discover it is wrong is not during an incident.

    • Three copies, two media, one offline
    • Backups outside the reach of everyday admin accounts
    • Quarterly restore test with a written result

    Payment and invoice fraud

    Invoice redirection costs small businesses more than malware does. An attacker studies your supplier relationships, then emails a change of bank details at a plausible moment. The defence is procedural rather than technical: never change payment details on the basis of an email, always confirm by telephone on a number already held on file, and require a second person to approve payments above a set amount.

    Write the rule down and apply it to the owner as well. Attackers impersonate the person nobody feels able to question.

    People, training and the plan for a bad day

    Short, specific training beats an annual slide deck: show real examples of the invoice scam, the fake delivery notice and the login page that copies your provider. Make reporting blameless and fast, because the first hour decides how much damage a compromised mailbox causes.

    Write a one-page incident plan: who to call, how to isolate a machine, where the backups are, which insurer and regulator must be notified and within what deadline. Print it, because you may not be able to open a file on the day you need it.

    • Short, example-led training twice a year
    • Blameless, immediate reporting culture
    • One-page printed incident plan
    • Known contacts for bank, insurer and IT support

    Frequently asked questions

    Is consumer antivirus enough for a small company?

    It protects an individual machine but gives no central visibility. A managed endpoint product tells you which devices are unprotected, which is the difference that matters at ten machines or more.

    What is the highest-value single change?

    Multifactor authentication on business email. It closes the route behind the largest share of small-business incidents.

    Do we need a VPN for remote staff?

    If they access internal systems, yes, or a modern zero-trust equivalent. For staff using only cloud services, strong account security matters more.

    How much should a small business spend?

    Less than most expect. A password manager, endpoint protection, backup and a domain-based email plan typically cost a few euros per person per month, far below the cost of a single fraudulent payment.

    Are we required to report a breach?

    In most jurisdictions, personal-data breaches must be reported to a regulator within a short deadline. Confirm the rules that apply where you operate and include them in the incident plan.