Do these five this week
Turn on multi-factor authentication for email and banking first - they are the accounts an attacker wants most
Set up a password manager and move your handful of most-used logins into it to start
Switch on automatic updates on every computer and phone the business uses
Check that your backup actually ran recently - and that you could restore from it if you had to
Send your team one short message: "if an email feels off, check with me before clicking - you will never be in trouble for asking"
None of this is exotic or expensive. It is the digital equivalent of locking the front door - simple habits that, done consistently, keep your business off the easy-target list. If you are not sure where you stand, a quick review is the fastest way to find out.
Frequently asked questions
Turn on multi-factor authentication, starting with your email. Email is the account attackers want most, because it can be used to reset every other password you have. MFA takes a few minutes to enable and blocks the vast majority of account takeovers on its own.
Yes - just not in the way people imagine. Most attacks are automated and untargeted: software scans the whole internet looking for accounts and devices with weak or missing protections. Being small does not make you invisible, it often makes you an easier win, because the basics are more likely to have been skipped.
No. The five fundamentals here are mostly built into tools you already pay for, like Microsoft 365 or Google Workspace. Getting the configuration right matters far more than buying another product. Expensive tools on top of missing basics is money spent in the wrong order.
Sarvesh
Operations and clients at Trivion - project management, onboarding, compliance and IT support for Sydney small businesses.
Back to all articles