cybersecurity

Small Business Security on a Budget: The 80/20 of Not Getting Hacked

You don't need a big budget to avoid getting hacked. The practical 80/20 of small business cybersecurity in 2026 — the handful of basics that stop almost everything.

There’s a comforting story small business owners tell themselves about cybersecurity: that it’s a big-company problem, that attackers go after the banks and the corporations, that there’s nothing on a modest business worth stealing. It’s a comforting story and it’s wrong. Small businesses are targeted precisely because they assume they’re not targets — they have money, customer data, and access to bigger partners, combined with few defenses and no security staff. To an attacker running automated, indiscriminate campaigns, that’s not a small target. It’s an easy one.

The other unhelpful story is the opposite: that real security requires a big budget, a consultant, and a wall of products. Also wrong. The uncomfortable truth most vendors won’t lead with is that the overwhelming majority of small-business breaches exploit a handful of basic failures, and fixing those costs very little. This is the 80/20 — the short list of unglamorous basics that stop almost everything, before you spend a penny on anything fancy.

First, understand what actually hits small businesses

You can’t prioritize defenses without knowing the real threats, and they’re more mundane than the headlines suggest. Small businesses overwhelmingly get hurt by a few things: someone’s password getting stolen or guessed and reused; an employee getting tricked by a phishing message or a fake invoice; ransomware that locks up the business’s files; and a payment getting redirected to a criminal through a convincing impersonation.

What’s striking is how ordinary that list is. These aren’t sophisticated, targeted operations against your specific company. They’re automated, opportunistic, and they work by finding the businesses that left the basics undone. Which is excellent news, because it means the basics are also what stop them.

The short list that does most of the work

If you do nothing else, do these. In rough order of impact-per-effort.

Turn on multi-factor authentication everywhere it’s offered. This is the single highest-value security action available to a small business, and it’s usually free. MFA means that even if an attacker has a password — stolen, guessed, or bought in bulk from a breach — they still can’t get in without the second factor on the employee’s phone. It neutralizes the most common attack there is. Turn it on for email first (the master key to everything else), then for every account that touches money or customer data, then for everything. Where the option exists, prefer an authenticator app or a passkey over text-message codes, but text-message MFA is still vastly better than none. Done across the business, this one step closes the door most attackers walk through.

Get backups right, and test that they restore. Ransomware’s entire leverage is that it holds your files hostage. A good backup removes that leverage completely — you wipe and restore instead of paying. The rule worth remembering is to keep multiple copies, with at least one kept separate and offline or in a service the attacker can’t reach from your main systems, because ransomware will happily encrypt a backup that’s permanently connected. And here’s the part everyone skips: actually try restoring from your backup once, before you need it. An untested backup is a guess, and the day you discover it never worked is the worst possible day to find out.

Keep things updated. A huge share of breaches exploit known weaknesses that were already fixed — the patch existed, nobody installed it. Turn on automatic updates for your operating systems, browsers, phones, and the software you depend on. It’s free, it’s mostly hands-off once enabled, and it shuts a door that attackers actively scan for. Unglamorous, and one of the highest-return habits there is.

Train the team on the two scams that actually target them. Your people are the real perimeter, and they don’t need a security degree — they need to recognize two things. One: be suspicious of any message creating urgency around money, login details, or clicking a link, even when it appears to come from the boss or a known supplier. Two: confirm any request to send money or change payment details through a separate, known channel before acting. Most successful attacks on small businesses route through a person doing something reasonable-seeming under pressure. A team that pauses on those two triggers defeats the bulk of it.

The cheap-or-free tools worth having

Beyond habits, a few inexpensive tools earn their place without a real budget.

A password manager for everyone in the business solves password reuse and weak passwords in one move — it generates and remembers strong, unique passwords so your team doesn’t have to, which means one breached site no longer endangers the others. Per person it’s the price of a coffee a month, and it removes an entire category of risk.

Reputable security software on the devices you use — much of it built into modern operating systems already — handles the baseline of malware. You very likely don’t need to buy an expensive suite; you need to make sure what’s there is switched on and updating.

And separating access so people can only reach what their job requires limits the blast radius when something does go wrong. If a single compromised account can touch everything, one mistake becomes a catastrophe. If it can only touch one person’s work, it stays a contained problem. This costs nothing but a little setup.

What you can safely ignore for now

Permission to not worry about some things is part of an honest 80/20. As a small business, you probably don’t need expensive enterprise security platforms, a dedicated consultant on retainer, or the long tail of niche products sold on fear. Those are for organizations that have already nailed the basics and have specific, larger exposures. Buying advanced tools while MFA is still off somewhere is like installing a high-end alarm and leaving the front door open. Do the basics first. They’re where nearly all the protection actually is, and they’re nearly free.

Have a plan for the bad day

One last cheap investment: decide, in advance and on one page, what you’d do if it happened. Who you call, where the backups are and how to restore them, how you’d reach customers, which accounts you’d lock down first. You will never think clearly in the middle of an incident, so the thinking has to be done beforehand. A simple written plan, reviewed once a year, turns a potential disaster into a stressful but survivable bad week. It costs an afternoon.

A first-week plan you can actually follow

The basics only protect you if they get done, and “improve our security” is too vague to ever happen. So here’s a week, broken into pieces small enough that none of them is a project you’ll postpone.

Monday: turn on multi-factor authentication for your business email — every account, every person. It’s the highest-value hour you’ll spend all year, and email first because it’s the master key. Tuesday: switch on automatic updates everywhere — computers, phones, browsers, your core software — and confirm they’re actually running, not just available. Wednesday: sort out backups. Make sure your important files are backed up, that at least one copy is somewhere ransomware can’t reach from your main systems, and — the step everyone skips — actually restore one file from the backup to prove it works.

Thursday: get a password manager and roll it out to the team, so reused and weak passwords stop being a thing that can hurt you. Friday: spend twenty minutes with your people on the only two things they really need to internalize — be suspicious of urgency around money, logins, or links, and always confirm payment requests or changes through a second known channel before acting. That’s the training. It doesn’t need a course; it needs everyone to actually hear it from you.

Over the following week, write the one-page “bad day” plan — who to call, where the backups are, what to lock down first — and review who can access what, trimming anyone’s reach to what their job actually requires. None of these days is hard. The reason most small businesses don’t have these protections isn’t difficulty or cost; it’s that “do security” never became five specific, finishable tasks. Now it has.

The actual point

Small business cybersecurity has a reputation for being expensive and complicated, and that reputation mostly serves the people selling expensive, complicated things. The reality is that a short list of cheap, boring basics — multi-factor authentication everywhere, tested backups, automatic updates, a password manager, and a team that pauses on urgent money requests — stops the overwhelming majority of what actually hurts businesses your size.

You don’t need a budget. You need a weekend and the discipline to do the unglamorous things properly. Start with MFA on your email today. It’s free, it takes ten minutes, and it closes the door attackers try first.