1st October 2026·The Grizzlyware team

Cyber security for small businesses: nine things that cost nothing

padlock and keyboard keys

October is Cyber Security Awareness Month, making it a great time to share the advice we give to small businesses.

We’re not a cyber security company, but we do build software, and doing that properly means taking security seriously. We don’t sell firewalls or security audits – nothing in the list below costs anything at all. But a few hours of your attention could really help tighten your security.

Things that catch small businesses out are rarely sophisticated, targeted attacks – most come from seemingly mundane things like clicking a link in an email or backups that turn out to be broken. The good news is, there are lots of measures you can take to avoid falling victim to these.

Nine free ways to stay secure

1. Put two-factor authentication on your email

You can think of your email as the master key to all your other accounts. Every other account you have will have a ‘Forgotten password?’ link – meaning that if somebody can get into your inbox, they can get into anything else. Setting up two-factor authentication can be done in a matter of minutes. Once your email is done, it is worth doing the same on your banking and accounting logins.

2. Use a password manager

Using the same password in more than one place is one of the most common ways people are caught out. A password manager gives every account a different password so that you only have to remember one, and the free versions are enough for most small businesses.

3. Keep a record of what you are signed up to

You probably have more accounts open than you realise. A photo editing tool opened years ago, a domain registrar that nobody can remember the password for, and the list goes on. If you don’t know which accounts you have, you can’t ensure they are secure. Keeping a record of which accounts you have allows you to keep the important ones up to date and remove those that are no longer needed.

4. Close accounts when people leave

This is a pretty common one. When a member of your team leaves, their accounts should all be deactivated – even if they left on great terms. Although your former staff are (hopefully) unlikely to do anything malicious, leaving inactive accounts set up increases vulnerability.

5. Turn on updates and run them regularly

The majority of breaches are from known software vulnerabilities that have had fixes released for them already – so they could have been avoided if the software was kept up to date. Automatic updates are available for most packages, so the only real reason not to have them is if one is likely to introduce a breaking change. Even in these cases, the updates should be done regularly, just with more planning and aftercare.

6. Try restoring from your backup

Backups are only useful if they can be restored successfully. Test that your backups are working as expected before you need to use one.

Bonus tip: A single backup is better than no backup, but you should really have at least two separate backups for each thing your business couldn’t function without. Your future self may thank you for it.

7. Take a second look at links in emails

A lot of incidents start with somebody clicking something they shouldn’t have. The emails are usually convincing, and they rely on you being busy rather than careless. If a message asks you to log in somewhere, it is worth going to the site yourself rather than using the link provided. It also helps if your staff know they can flag something that looks odd without being made to feel silly about it.

8. Agree a rule for changing bank details

A lot of people are caught out by this. An email arrives claiming to be from a supplier that you use, saying their bank details have changed. The emails can be very realistic, sometimes even coming from the real account if somebody has gained access. A rule that can help prevent this is to ensure that any changes to payment details are confirmed by phone – from a number you already have, NOT the one in the email, prior to acting on them.

9. Decide on an emergency plan

If something does go wrong, acting quickly and calmly is essential. In order to do this you need to have a plan in place, consisting of who to contact if your computers, website, or bank encounter a problem – it’s often not the same person for all. This should be accessible to all staff, and they should know how to use it.

A few of these are worth a longer look. We went into passwords, shared logins, access control and untested backups in more detail in 5 security risks small businesses overlook.

If you want to go further

Cyber Essentials is a government-backed scheme that can really help you. It is a set of five basic controls, and certification is affordable for small businesses. It is also sometimes required if you are going to work for certain public sector or larger private companies, so it can be useful to have this in place if you are likely to go after that kind of work.

Beyond that, good cyber security for a small business doesn’t need to be expensive. Good habits and thorough procedures and staff training will go a long way in keeping you protected.

If you would like to read more, we have written about why security shouldn’t be an afterthought in your software, which covers what to ask about when you are choosing or commissioning something new.