[{"data":1,"prerenderedAt":36},["ShallowReactive",2],{"$fGrwVy7d5mfkYU7hymty-4oHR9RVV_sEG9AmfmsKFf_o":3},{"id":4,"slug":5,"url":6,"date":7,"modified":8,"title":9,"excerpt":10,"content":11,"featuredImage":12,"featuredImageAlt":13,"tags":14},575,"cyber-security-for-small-businesses-nine-things-that-cost-nothing","https://blog.grizzlyware.com/cyber-security-for-small-businesses-nine-things-that-cost-nothing/","2026-10-01T10:14:22","2026-10-01T10:14:23","Cyber security for small businesses: nine things that cost nothing","\u003Cp>Good cyber security for a small business doesn&#8217;t have to mean spending money. Most of what catches people out &#8211; reused passwords, forgotten accounts, untested backups- can be sorted out in an afternoon. Here are nine things you can do this month that cost nothing.\u003C/p>\n","\n\u003Cp class=\"wp-block-paragraph\">October is Cyber Security Awareness Month, making it a great time to share the advice we give to small businesses.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">We&#8217;re not a cyber security company, but we do build software, and doing that properly means taking security seriously. We don&#8217;t sell firewalls or security audits &#8211; nothing in the list below costs anything at all. But a few hours of your attention could really help tighten your security.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Things that catch small businesses out are rarely sophisticated, targeted attacks &#8211; most come from seemingly mundane things like clicking a link in an email or backups that turn out to be broken. The good news is, there are lots of measures you can take to avoid falling victim to these.\u003C/p>\n\n\n\n\u003Ch2 class=\"wp-block-heading\">Nine free ways to stay secure\u003C/h2>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">1. Put two-factor authentication on your email\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">You can think of your email as the master key to all your other accounts. Every other account you have will have a &#8216;Forgotten password?&#8217; link &#8211; meaning that if somebody can get into your inbox, they can get into anything else. Setting up two-factor authentication can be done in a matter of minutes. Once your email is done, it is worth doing the same on your banking and accounting logins.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">2. Use a password manager\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Using the same password in more than one place is one of the most common ways people are caught out. A password manager gives every account a different password so that you only have to remember one, and the free versions are enough for most small businesses.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">3. Keep a record of what you are signed up to\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">You probably have more accounts open than you realise. A photo editing tool opened years ago, a domain registrar that nobody can remember the password for, and the list goes on. If you don&#8217;t know which accounts you have, you can&#8217;t ensure they are secure. Keeping a record of which accounts you have allows you to keep the important ones up to date and remove those that are no longer needed.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">4. Close accounts when people leave\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">This is a pretty common one. When a member of your team leaves, their accounts should all be deactivated &#8211; even if they left on great terms. Although your former staff are (hopefully) unlikely to do anything malicious, leaving inactive accounts set up increases vulnerability.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">5. Turn on updates and run them regularly\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">The majority of breaches are from known software vulnerabilities that have had fixes released for them already &#8211; so they could have been avoided if the software was kept up to date. Automatic updates are available for most packages, so the only real reason not to have them is if one is likely to introduce a breaking change. Even in these cases, the updates should be done regularly, just with more planning and aftercare.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">6. Try restoring from your backup\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Backups are only useful if they can be restored successfully. Test that your backups are working as expected before you need to use one.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Bonus tip: A single backup is better than no backup, but you should really have at least two \u003Cem>separate\u003C/em> backups for each thing your business couldn&#8217;t function without. Your future self may thank you for it.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">7. Take a second look at links in emails\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">A lot of incidents start with somebody clicking something they shouldn&#8217;t have. The emails are usually convincing, and they rely on you being busy rather than careless. If a message asks you to log in somewhere, it is worth going to the site yourself rather than using the link provided. It also helps if your staff know they can flag something that looks odd without being made to feel silly about it.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">8. Agree a rule for changing bank details\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">A lot of people are caught out by this. An email arrives claiming to be from a supplier that you use, saying their bank details have changed. The emails can be very realistic, sometimes even coming from the real account if somebody has gained access. A rule that can help prevent this is to ensure that any changes to payment details are confirmed by phone &#8211; from a number you already have, NOT the one in the email, prior to acting on them.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">9. Decide on an emergency plan\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">If something does go wrong, acting quickly and calmly is essential. In order to do this you need to have a plan in place, consisting of who to contact if your computers, website, or bank encounter a problem &#8211; it&#8217;s often not the same person for all. This should be accessible to all staff, and they should know how to use it.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">A few of these are worth a longer look. We went into passwords, shared logins, access control and untested backups in more detail in \u003Ca target=\"_blank\" rel=\"noreferrer noopener\" href=\"https://www.grizzlyware.com/blog/5-security-risks-small-businesses-overlook\">5 security risks small businesses overlook\u003C/a>.\u003C/p>\n\n\n\n\u003Ch2 class=\"wp-block-heading\">If you want to go further\u003C/h2>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Cyber Essentials is a government-backed scheme that can really help you. It is a set of five basic controls, and certification is affordable for small businesses. It is also sometimes required if you are going to work for certain public sector or larger private companies, so it can be useful to have this in place if you are likely to go after that kind of work.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Beyond that, good cyber security for a small business doesn&#8217;t need to be expensive. Good habits and thorough procedures and staff training will go a long way in keeping you protected.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">If you would like to read more, we have written about \u003Ca target=\"_blank\" rel=\"noreferrer noopener\" href=\"https://www.grizzlyware.com/blog/why-security-shouldnt-be-an-afterthought-in-your-software\">why security shouldn&#8217;t be an afterthought in your software\u003C/a>, which covers what to ask about when you are choosing or commissioning something new.\u003C/p>\n","https://blog.grizzlyware.com/wp-content/uploads/2026/09/flyd-zAhAUSdRLJ8-unsplash1-scaled.jpg","padlock and keyboard keys",[15,18,22,26,29,32],{"id":16,"name":17,"slug":17},127,"backups",{"id":19,"name":20,"slug":21},130,"cyber essentials","cyber-essentials",{"id":23,"name":24,"slug":25},66,"cyber security for SMEs","cyber-security-for-smes",{"id":27,"name":28,"slug":28},126,"passwords",{"id":30,"name":31,"slug":31},128,"phishing",{"id":33,"name":34,"slug":35},129,"two-factor authentication","two-factor-authentication",1790846305604]