Skip to content

Cybersecurity: 5 steps to browse safely

Five habits that protect your small business from the most common attacks: passwords, two-factor authentication, updates, phishing and backups.

Published Updated 2 min readAdbify

In May 2017, the WannaCry ransomware encrypted files on hundreds of thousands of computers in more than 150 countries, including hospitals and large companies. It exploited a Windows flaw that had been patched two months earlier: the victims simply hadn’t updated.

That’s the pattern we see most often in small businesses. Most incidents don’t require a sophisticated attack; a reused password, an unpatched system or a click on the wrong link is enough. These five habits close those doors.

1. Use a password manager

A different password for every account is impossible to remember, which is why people reuse them. A password manager creates and stores them for you; you only remember one.

  • Prefer long passphrases over short passwords with symbols: length protects more.
  • Never reuse your email password on another service. If another site is breached, that password is the first thing attackers will try.
  • Modern browsers and phones include a built-in manager; there are also dedicated options like Bitwarden or 1Password.

2. Turn on two-factor authentication

With two-factor authentication, a stolen password isn’t enough to get in. Turn it on first where losing access hurts most: your business email, banking, hosting, domain and social media.

If the account allows it, use an authenticator app or a passkey instead of SMS codes.

3. Update everything, preferably automatically

Operating system, browser, apps and, if you have a website, its platform and plugins. Abandoned or outdated plugins are one of the most common ways into WordPress sites.

Turn on automatic updates wherever you can and remove what you no longer use.

4. Be suspicious of urgency

Phishing no longer arrives only by email: it also comes through SMS, WhatsApp and phone calls. It almost always follows the same recipe: urgency (“your account will be locked today”) and an unusual request (a code, a payment, a password).

  • Verify through another channel before acting: call the number you already know, not the one in the message.
  • Your bank will never ask for your PIN or the codes it texts you.
  • If someone on your team asks for an urgent payment to a new account, confirm it in person or by phone.

5. Back up using the 3-2-1 rule

Keep 3 copies of your important data, on 2 different types of storage, with 1 off-site (for example, in the cloud). And the most forgotten part: test from time to time that you can restore a backup. A backup you can’t restore isn’t a backup.

An extra step if you have your own domain

Set up SPF, DKIM and DMARC on your domain. They’re DNS records that tell the world which servers may send email on your behalf. Without them, anyone can send emails that look like yours to your customers, and your legitimate emails are more likely to land in spam.

Want help with this?

See how we handle it in our service: Digital security assessment.

Ready to take your business digital?

Tell us what you need and we’ll suggest the next step.