What cybersecurity does a small business actually need?

Almost everything sold as small business cybersecurity is aimed at threats you are unlikely to face. The things that actually happen to businesses your size are duller, and cheaper to prevent.

Start with how small businesses actually get hurt

Three patterns account for most of it:

  • Someone gets into an email account. Usually through a reused password or a convincing login page. From there they read, wait, and insert themselves into a real conversation about money.
  • Someone sends money to the wrong place. A payment request that looks like it came from a supplier, or from the owner. No malware involved at all.
  • Files get encrypted and the backup does not restore. The backup existed. Nobody had ever tried to use it.

Notice what is missing: nothing here required a sophisticated attacker. Which is good news, because the defences are correspondingly ordinary.

The baseline, in the order worth doing it

# What Why it is in this position
1 Multi-factor authentication on email, banking and accounting Email resets everything else. This is the highest-value hour available.
2 A password manager for everyone Removes reuse, which is what makes one breach into five.
3 A tested restore, not just a backup An untested backup is a belief, not a control.
4 A written rule for payment changes Verify bank-detail changes by phone, on a number you already had. Stops the most expensive category outright.
5 Automatic updates everywhere Closes the holes automated attacks look for. Free.
6 A real offboarding checklist Access removed from every system, not just email.

That list is the baseline for most small businesses. It is deliberately short, and finishing it puts you ahead of a great many businesses of your size.

What can wait

Not because these are bad, but because they cost real money and address risks that only matter once the baseline is done:

  • Security monitoring services, until there is something worth monitoring
  • Penetration testing, which tells you what an attacker could do to a system you have not yet secured
  • Cyber insurance bought before the baseline — most policies now ask whether you have multi-factor authentication anyway
  • Advanced tooling of any kind while passwords are still being reused

If you handle regulated data — health information, card payments, client financial records under a professional obligation — the baseline above is a floor, not a finish line. The requirements come from the regulation, not from your risk appetite, and they are worth getting explicit advice on.

How this connects to the books

The payment-verification rule is a bookkeeping control as much as a security one, which is a fair illustration of why we treat technology and the back office as one thing. If your books are current, an unusual payment gets noticed in days. If they are three months behind, it does not. Bookkeeping support and Hanson Tech are on the same side of that problem.

For the wider context, see small business technology, explained. If you are working out what protection is worth paying for, how much a small business should spend on IT support covers the money side.

Not sure where your technology actually stands?

The Tech Clarity assessment is a free 60-minute review of your setup — what you are running, what it costs, and where the gaps are. No obligation, and you keep the findings either way.