Small business cyber security handbook
Explore the practical steps small business can take to protect their systems, data, staff and customers from cyber threats.
- Published
-
- Last reviewed
-
Educate staff on good cyber security practices
Cyber security is continuously changing. As business owners, you have a legal responsibility to keep your business and customer information secure. Keeping your employees up to date on cyber security could prevent a cybercriminal accessing your business, money or data.
Cyber security awareness training
Cyber threats evolve quickly, so training should be ongoing rather than a one-time activity.
- Provide regular, up-to-date training sessions on common threats like phishing, ransomware and social engineering.
- Educate staff on safe browsing habits and how to avoid malicious websites.
- Emphasise the risks of downloading unknown files or using unsecured external devices.
- Promote security-first culture by emphasising that cyber security is everyone's responsibility.
- Create a positive cyber security culture by encouraging staff to report any suspicious activities.
- Provide up-to-date information and alerts in staff common areas.
Be aware of email security and phishing techniques
Being aware of email security risks and phishing techniques is essential for protecting your business from cyber threats. Cybercriminals commonly use phishing emails to trick users into revealing sensitive information or installing malicious software. If you are not vigilant, cybercriminals may gain access to and take control of your business email account.
Common email phishing techniques
- Email spoofing – cybercriminals imitate the sender’s address so the email appears to come from a trusted source like your manager or IT team.
- Business email compromise – cybercriminals impersonate executives or suppliers to trick you into sending money, for example via a fake invoice. Always verify payment recipients before sending money.
- Malicious attachments – emails include infected files that install malware when opened.
- Credential harvesting – emails contain links to fake login pages that look real and are designed to steal login credentials.
Business email compromise
- Business email compromise is a form of targeted phishing, or spear phishing.
- Cybercriminals use email to pretend to be trusted business contacts.
- Cybercriminals can use this method of cyberattack to intercept invoices or payment requests.
- Their aim is to trick organisations or customers into sending money or goods.
Verify payment requests
Cybercriminals frequently use business email compromise to redirect payments or alter supplier banking details. Small businesses are often targeted because payment processes may rely on trust, email communication and limited verification processes. Establishing simple verification procedures, for example confirming an email address, can significantly reduce the risk of financial loss.
Data protection and privacy awareness
- Regularly review and update organisational policies and privacy regulations and encourage staff compliance.
- Explain the importance of data classification and train staff to handle sensitive and confidential information safely.
- Teach staff how to prevent accidental data leaks, such as verifying recipients before sending emails or files.
- Prohibit the installation of unauthorised software or applications on work devices.
- Encourage staff to promptly report any suspected data loss, leak or unauthorised access.
- Follow privacy laws, regulations and internal policies for data handling and privacy.