SecurityMay 2, 20263 min read
Network Security Basics Every Small Business Skips
You do not need an enterprise security programme. You need six controls that stop the attacks small businesses actually face.
By C-Media360 Team

Small businesses tend to assume they are too small to be a target. In reality they are targeted more often, precisely because the defences are predictable and the attacks are automated.
Nobody is choosing your company. A script is scanning everything and stopping where it finds a door open.
The good news is that most of these attacks are stopped by a handful of unglamorous controls.
1. Multi-factor authentication, everywhere
The single highest-value change available. A stolen password becomes almost useless when a second factor is required.
Enable it on email first — email is the account that can reset every other account. Then banking, then your website admin, then anything storing customer data.
Use an authenticator app rather than SMS where the option exists.
2. A password manager, so passwords stop being reused
Password reuse is how one breach becomes six. A manager makes unique credentials the path of least resistance, which is the only way this ever holds.
The list of passwords in a spreadsheet is not a system. Neither is the same base word with a rotating number on the end.
3. Updates, on a schedule someone owns
Most successful attacks exploit vulnerabilities that were patched months earlier. Operating systems, browsers, plugins, phones.
The failure mode is not ignorance — it is that updating is nobody's specific job. Assign it, put it on a calendar, and confirm it happened.
"Remind me later" is a security policy, and it is the one most businesses are running.
4. Backups you have actually restored
An untested backup is a hope. The only way to know a backup works is to restore from it.
Follow the simple version of the rule: three copies, two different media, one off-site and offline. Ransomware routinely encrypts network backups along with everything else, which is what makes the offline copy matter.
Test a restore quarterly. It takes an hour and tells you something you cannot otherwise know.
5. Least privilege on accounts
Not everyone needs administrator access. A compromised account with limited permissions is an incident; a compromised admin account is a crisis.
Review this when people join, change roles, and leave. Dormant accounts belonging to former staff are a common entry point and an easy fix.
6. Train the team on the realistic attack
The threat is rarely technical. It is an email that appears to come from a director asking for an urgent payment, or an invoice with changed bank details.
What works is a simple rule everyone knows: any payment or credentials request gets verified through a second channel, no exceptions, no matter who appears to be asking. Make it a policy so nobody has to feel awkward following it.
What to do this month
Pick the two that are currently missing:
- Turn on multi-factor authentication for email and banking
- Restore one backup and confirm the data is intact
- Remove accounts for anyone who has left
- Write down the payment verification rule and send it to the team
None of this requires new software or a consultant. It requires deciding that it is someone's job.
If you want a review of where your systems stand, get in touch.
- Security
- Operations
- Risk


