Most cyber attacks on small businesses are not sophisticated. They rely on a stolen password, a missed update, or a staff member clicking a convincing link. New Zealand’s National Cyber Security Centre (NCSC) keeps returning to the same fundamentals because they stop most of these attacks.
1. Multi-factor authentication
Turn on multi-factor authentication (MFA) for email, Microsoft 365 or Google Workspace, accounting software, remote access and any admin account. With MFA, a stolen password alone isn’t enough to get in. Prefer an authenticator app or security key over text messages where you can.
2. Keep software updated
Attackers use known weaknesses in out-of-date software. Set operating systems and applications to update automatically, check that updates are actually installing, and remember routers, firewalls and printers too. Replace anything that no longer receives security updates.
3. Backups you have tested
Back up the data your business can’t run without: files, email, accounting and practice data. Keep at least one copy separate from your main systems so ransomware can’t reach it, and test a restore regularly. A backup you haven’t restored from is a hope, not a plan.
4. Staff awareness
Show your team what phishing and invoice scams look like, and make it easy and blame-free to report something suspicious. Agree a rule that any change to bank details is confirmed by phone using a number you already have.
Where to start
- Check which accounts don’t have MFA yet and fix those first.
- Confirm updates are installing on every device.
- Restore one file from backup this week.
- Brief your team on how to report a suspicious email.
Want a second opinion on where your business stands? Call 04 282 0045 or see how we help businesses like yours.
