Small business cyber security handbook
Explore the practical steps small business can take to protect their systems, data, staff and customers from cyber threats.
- Published
-
- Last reviewed
-
Remote working security
Working remotely can introduce additional cyber security risks, as home environments may not have the same protections as office networks. Without proper safeguards, devices, accounts and data may be more vulnerable to cyber threats.
It is important to stay vigilant and follow secure practices to protect your devices, connections and information while working remotely.
Improve your network security
Make sure to secure your Wi-Fi network and router to prevent unwanted access. Cybercriminals will target weaker networks, putting your sensitive data at risk.
To improve your network security, you should:
- change your default Wi-Fi network name and password
- change your router’s default username and password
- use the strongest Wi-Fi encryption available
- keep your router up to date
- disable remote management and Universal Plug and Play
- enable guest Wi-Fi if required.
Consider segmenting your network by purpose or device. For example, set up smart home devices on a separate network from your main one to reduce the risk if they are compromised.
Avoid public Wi-Fi for work
Public Wi‑Fi networks are convenient but can be insecure and are often targeted by cybercriminals seeking to access sensitive information. Using these networks can increase the risk of data being intercepted or accounts being compromised.
Where possible, use trusted networks such as your home Wi‑Fi or a personal hotspot. If you must use public Wi‑Fi, limit what you access and avoid activities involving sensitive information, such as logging into accounts or making payments.
Secure your information
Protecting your information requires consistent and practical security measures. Regularly back up your data to ensure it can be recovered if lost, damaged or compromised during a cyber incident.
Use a dedicated work account to separate business and personal activities, reducing the risk of accidental exposure or compromise.
Take care when using online meetings or communication platforms. Meetings should be secured with appropriate settings, such as passwords or waiting rooms, to prevent unauthorised access and protect sensitive information.
Be aware of your surroundings
Avoid accessing sensitive information when in public locations. You could expose confidential work and customer details to anyone passing by. You should access this type of information when in a private or trusted location.
Check your workplace requirements for information security and privacy.
Transfer files securely
Avoid using removable media to transfer files between devices. Portable storage devices such as USB drives are easy to lose, steal or infect with malware.
Use secure methods of file transfer such as cloud storage from a reputable provider. Your workplace may already use this for online file management. If you don't have this option, you should encrypt your storage device with a strong password.
Use secure web conferencing systems
Web conferencing tools can expose your business to security risks if not configured properly. Taking simple precautions can prevent unauthorised access and protect sensitive information during meetings.
When hosting or joining online meetings, check for unknown participants, remain aware of your surroundings, and any information shared on screen. Only use trusted conferencing platforms with strong security features and follow your organisation’s approved providers where applicable.