Small business cyber security handbook
Explore the practical steps small business can take to protect their systems, data, staff and customers from cyber threats.
- Published
-
- Last reviewed
-
Securing accounts and identities
By enabling multi-factor authentication (MFA), using strong passwords and applying proper access controls, you can make it harder for cybercriminals to access to your accounts and limit the damage if an account is compromised.
Turn on multi‑factor authentication
MFA is one of the most effective ways to protect business accounts. It adds an extra step to logging in, such as a one‑time code from an authenticator app, meaning a stolen password alone can’t be used to gain access to an account.
Authentication methods
- Passkey – a more secure way to log in to your online accounts than using a password. Using a passkey helps to prevent cybercriminals tricking you to log in to a fake website.
- Physical token – a small device like a USB stick. It shows a new code on its screen at regular intervals. When you want to access an account, you need to check the token and enter the displayed code.
- Security key – a small physical token without a display screen. It’s either plugged into your device via a USB port or connected wirelessly.
- Biometrics – with biometrics, your unique characteristics are used to confirm your identity. An example of biometrics is using your face or fingerprint to access your device or mobile apps.
- Authenticator app – applications that generate a random one-time password. Consider using a well-known authentication app, such as Google or Microsoft.
- SMS / email code – one-time codes received via SMS or email. This is the least secure option due to the ease in which SMS and email accounts can be compromised.
Getting started
Turn on MFA wherever it is available. Start with high-risk accounts like email, banking, cloud storage, accounting software and social media.
MFA settings are usually found under account security. Some services may call it two factor authentication or two-step verification.
Use strong passwords (where the use of passkeys is unavailable)
Weak or reused passwords are a common cause of cyber security incidents in small businesses. Each account should have a strong and unique password to help prevent cybercriminals from accessing multiple systems if a single account is compromised.
Where MFA is enabled, businesses should still use strong passwords and make them as long as practical with a minimum of 6 characters per password. Where MFA cannot be used, passwords should be at least 15 characters long.
Businesses should:
- use a unique password for every account
- avoid reusing passwords across multiple systems
- use a password manager to generate and securely store passwords
- change passwords if they are suspected of being compromised.
Use a password manager
Keeping track of different passwords can be challenging, but a password manager makes it easy. It helps you create, manage and store your passwords and passkeys in one secure place.
Password managers allow you to:
- create long, unpredictable and unique passwords
- store your account logins in one place from any device
- save time and effort by auto filling your account logins
- reduce the risk of someone intercepting your passwords.
Use a strong master password
Your password manager protects many of your important accounts, so it’s important to secure how you access it. Using weak authentication is like putting your valuables in a safe and leaving the unlock code beside the door. Secure authentication should include a strong, unique master password along with MFA.
Getting started
Choose a trusted password manager and protect it with MFA and a long, unique master password. Add your business accounts and use the manager to create passwords that are at least 15 characters long. Start with your most important accounts.
Manage shared accounts
Shared accounts increase security risks and make it harder to track activity. Where shared access is needed, it should be tightly controlled.
Getting started
- Create individual accounts for staff wherever possible.
- Keep a record of shared accounts and who has access and reduce access where you can.
- Change login details when staff leave or change roles.
Implement access controls
Limiting access helps reduce the impact of cyber incidents. Staff should only have access to the systems and data they need to do their job.
Getting started
Review what each staff member can access and remove access to anything unnecessary, including files, applications and online accounts. Follow the principle of least privilege and only give administrator access to those who need it. Remove access promptly when staff leave.