
A common assumption is that security is expensive and requires a team. Neither is true for a small business. What matters is discipline and automation. If you automate the things that are tedious, you can afford to do them well. If you eliminate tedious steps, your team will actually follow the process.
This article outlines a security programme that works for a business of 5-50 people.
The foundation
Everything else rests on three things.
Passwords. Every person gets a password manager (Bitwarden is cheap and open-source) and a strong unique password for everything. No sharing passwords, no writing them down, no reuse.
Multi-factor authentication. Enabled on email first, then any system with administrative access, then anything with sensitive data. SMS-based 2FA is better than nothing. App-based codes are better than SMS. Hardware keys are best but not necessary for a small business.
Backups. Daily backups of anything important. Stored offline or in a read-only snapshot so ransomware cannot delete them. Restored and tested monthly so you know they actually work.
These three things prevent the majority of attacks. Everything else is refinement.
What to buy
You do not need to spend a fortune. Here is the minimum:
Email security. Proofpoint Essential, Mimecast, or equivalent. Catches phishing and malware. £100-300 per month. Worth every pound.
Password manager and identity management. Bitwarden for password management (£30/user/year if self-hosted), or a cloud offering. For larger teams, add single sign-on (SSO) so everyone uses the same credentials everywhere. Okta or similar. £5-10 per user per month.
Endpoint protection. Windows Defender and macOS’s built-in malware detection are adequate for small businesses if kept updated. If you want something more sophisticated, CrowdStrike or Sophos. £100-500 per endpoint per year.
Backup solution. Backblaze or Wasabi for automated backups. £5-20 per machine per month.
Network monitoring. If you have on-premises servers, Nagios (free) or NewRelic (paid). For cloud services, most include basic monitoring.
Total for a team of ten: roughly £200-500 per month.
That is the baseline. Everything else is either nice-to-have or situation-dependent.
What to automate
Updates. Turn on automatic updates for everything. Yes, automatic updates sometimes break things. Unpatched systems get compromised more often. The trade-off favors updates.
Password expiration. Do not require password changes every 90 days — that leads to weak passwords. Do require passwords to be changed when compromised. Have a policy and a process.
Backup verification. Automate a monthly restore test. Pick a random backup, restore it to a test system, verify it works. This catches backup failures before you need the backup.
Security patch management. Automate deployment of non-emergency patches to non-critical systems. Have a manual process for critical systems where you test first.
Access control. Use groups in your identity system. Instead of giving people individual permissions, put them in a group (engineers, finance, marketing) and assign permissions to the group. When someone leaves, remove them from the group and revoke all their access.
Logs. If you have the budget, centralise logs and alert on suspicious patterns (unusual logins, privilege escalation attempts, large file access). If you do not have the budget, enable local logging and make sure someone looks at the logs monthly.
The process
Onboarding. New person gets an account in your identity system, is added to the appropriate groups, gets a password from the password manager, enables 2FA, and gets a device encrypted and with updates enabled.
All of this should take an hour and be mostly automated.
Security roles and responsibilities. One person owns security (this can be a part-time responsibility for a small business). That person owns incident response, coordinates with IT, and tracks vendor security. They are not solely responsible for keeping the company secure — that is everyone’s job — but they drive the process.
Incident response plan. Before something happens, you should know:
- Who do you call if something smells wrong?
- What is the first person’s job? (Usually to isolate the system and notify the security person.)
- What is the security person’s job? (Gather information, decide if it is a real incident, escalate if needed.)
- Do you have offsite backups? How fast can you restore?
- Who talks to customers or lawyers if there is a breach?
Write it down. Share it. Drill it once a year.
What to tell your people
Security is not about being paranoid. It is about being thoughtful. Everyone has a role.
Phishing. If something seems off, report it. A message from your bank asking for your password is weird. A message from your boss asking you to download something from an unusual source is weird. Trust your instinct.
Passwords. Use the password manager. Never share passwords. Never reuse passwords. If a password is compromised in a breach (your security person will tell you if this happens), change it.
Devices. If your device is lost, stolen, or acts weird, tell someone immediately. Do not try to fix it yourself.
Physical security. Lock your door if you have one. Do not leave a laptop unattended in a coffee shop. Do not write down passwords.
Spend an hour per year on security training, not because people are dumb but because the landscape changes and you want people on the same page.
What you cannot do alone
There are some things a small business without a security team should not try to handle:
Advanced threat detection. Detecting a sophisticated attacker hiding in your network requires tools and expertise you probably do not have. If you suspect a breach, bring in an incident response firm.
Compliance and regulation. If your business handles payment cards, healthcare data, or is regulated in some other way, you need specialist help. This is not optional. Get a consultant.
Penetration testing. A once-a-year penetration test by a professional is worth the cost. It is insurance that your defences actually work.
These are not cheap, but they are one-time or annual expenses that prevent catastrophic problems.
The honest assessment
A small business with discipline around passwords, backups, updates, and multi-factor authentication will be more secure than a larger business that skips these things. Security is mostly about hygiene, not sophistication.
The companies that get compromised are usually the ones that thought they were too small to matter or too busy to spend time on basics. Realistically, you are not too small and the time is less than you think if you automate well.