Most small-business incidents succeed because a few basics were left off: reused passwords, no multi-factor login, nobody shown a fake invoice, and no backup anyone has restored. Fix those and you have closed the door on a large share of the boring, real cases. None of that needs a security team, and none of it needs a horror story with a made-up percentage. I am not going to invent breach statistics. The National Cyber Security Centre publishes small-business guidance if you want a public-sector view.
Antivirus is one layer, not the plot. Whether Defender or a paid suite is enough is covered in do I need antivirus in 2026. This post is the habits around it.
What actually goes wrong for small firms?
The pattern is almost always identity and email, not a genius in a hoodie.
Someone clicks a link that looks like a supplier, a bank, Microsoft, HMRC or “the owner”. They type a password. The inbox is then used to reset everything else, or to send a new bank detail to your bookkeeper. No exotic malware required.
Someone uses the same password on the mailbox and a shop they forgot they joined. That shop leaks. The mailbox opens.
Someone ignores updates for six months. A known hole stays open. Automated scans find it. You were not chosen. You were easy.
Someone has no second copy of the accounts. A dead laptop or an encrypted folder becomes a bad month.
That is the list. Treat it as operations, the same way you treat van insurance and a lock on the unit. You do not need a “cyber strategy” document. You need a short list that is actually true on a Tuesday.
Why are passwords and MFA the first job?
Because email is the master key. Reset a bank, a domain, a supplier portal, and you start from mail. If mail is one password and that password is Hassocks2024!, the rest of the conversation is theatre.
A password manager gives each account a long unique password and remembers it. Staff learn one strong master password. That is the highest-value change most small firms can make. Good managers exist at the cheap end. I will not name a winner. Pick one the team will use. Sharing a spreadsheet of passwords in a shared inbox is the old problem with extra steps.
Multi-factor authentication (MFA) adds a second step, usually a code from an app. A leaked password is then not enough. Turn it on for email first, then for any admin login, then for the bank and the accounts tool. Prefer an authenticator app over a text message where you can. SMS is better than nothing and worse than an app.
Turn it on for the shared mailbox too. Shared mailboxes with a password on a sticky note are how a leaver, or a stranger, keeps reading quotes.
Approve-prompt fatigue is a real trick. If a phone suddenly asks you to approve a login you did not start, deny it and change the password. Do not tap yes to make the noise stop.
None of this is a Microsoft-versus-Google point. Both suites offer MFA. Check their current admin docs. Leave it off and the logo on the login screen will not help.
How do you stop staff clicking a fake invoice?
You spend half an hour, once, and you repeat it when someone new starts.
Show real examples from your own junk folder if you have them. The tells are ordinary: urgency, a slightly wrong domain, a payment-detail change, a “your mailbox will close today” threat, a link that does not match the text. Ask people to hover and read. Ask them to phone the supplier on a number they already have, not the number in the email, before they pay a new account.
Write two rules on a card:
- We do not change bank details from an email alone.
- We do not give a password or an MFA code to a page we reached from a link in a panic message.
That card beats a laminated “cyber awareness week” poster.
Owners are not exempt. The “finance, pay this now” message that pretends to be you is aimed at the person who wants to be helpful. If you are often out on site, agree a phrase or a callback rule so staff have permission to slow down.
You will not reach zero clicks forever. You reduce the chance, and you make sure a click without MFA and without a backup is not the whole company.
Where do updates and backups sit?
Updates close holes that are already public. Turn automatic updates on for Windows or macOS, for the browser, and for the office apps. The prompt people dismiss is often the patch for last month’s problem. Running a machine that has not been restarted since Easter is a choice.
Phones that read work mail should update too.
Backups are how a bad day stays a bad day. Three copies, two kinds of storage, one copy off-site, then a restore you have tried. Sync is not the same job. Antivirus and MFA do not bring back last year’s invoices.
Leavers are a control. Disable the account the same day. Collect the laptop. Remove them from the password manager. Do not use the admin login for everyday mail.
Are you too small to bother?
Being small is not cover. A lot of the mail and the scanning is automatic. It does not check your turnover. A two-person firm with a reused password is a quicker win than a company that turned MFA on.
You do not need a stack that looks like a bank. Paid monitoring or an MSP can be right when you have many devices or a contract that insists. They are a poor substitute for MFA on the mailbox. Defender on an updated PC counts as antivirus for most insurer forms. Write down what you actually do.
If decisions already feel like guesswork, see what is a fractional IT director. Advisory. Not a helpdesk.
What can you get help with, and what is not on offer?
A one-off review is a sensible product: list accounts, turn on MFA, set a password manager, write the two email rules, confirm the backup restores, turn on updates. Then you own the list.
Page Forge will do that as a quoted project. We are not a managed security provider. We do not watch your network overnight or run a helpdesk. If you need tickets when a PC fails, use an MSP. Website care is a different product. Do not mix a site subscription with a security operations pitch.
Frequently asked questions
What is the single most useful cyber security step for a small business?
Unique passwords in a manager, plus MFA on email, starting with admin. Mail resets everything else. Those two steps block a large share of account takeovers without a product tour.
Do small businesses really get targeted?
They get hit by the same automated mail and scans as everyone else. You do not need to be famous. You need to be reachable and loosely locked. I will not quote a scary percentage. The NCSC’s small-business pages are a calmer place to read.
How much does the basic setup cost?
Less than people expect. Password managers, MFA, a half-hour briefing and automatic updates are cheap or free. Paid antivirus and monitoring are optional extras, not the foundation. I will not invent a consulting fee here. Projects are quoted.
Is antivirus enough on its own?
No. It is one layer. Phishing and a reused password walk around it. Keep the built-in protection on, then do MFA, passwords, updates and a tested backup. See the antivirus post linked above for Windows and Mac detail.
Should I pay for staff “phishing training” every month?
A short, specific briefing with your own examples beats a generic video course you forget. Repeat when you hire. Monthly theatre is optional. The callback rule for bank details is not.
Will Page Forge monitor us after the review?
No. We close the obvious gaps as a project and hand over. Ongoing monitoring is not our product. If you want that, hire the kind of firm that sells it.
If you want a straight list of gaps and a finish line, that is the work we take on. See IT and AI consulting, or get in touch. Bring how many people and where mail lives. That is enough to start.