"I'm too small, nobody will target me." It is the most repeated sentence and the one that helps attackers most. Most attempts are not aimed at anyone in particular: they are automated messages and programs trying their luck on thousands of businesses at once, and the one with the open door is the one that falls. A small accountancy, a garage or a corner shop is as good a target as any.
The good news is that the measures that protect you most are not very technical. You do not need to buy anything expensive: you need a few clear habits. Here are the ones that pay off most.
Passwords: a different one for everything, and a manager to remember them
The most common failure is reusing the same password across several services. If one of those sites suffers a breach, criminals try that email and password combination on your email, your bank and your social accounts. That is why every account needs its own, and nobody can memorise dozens of long passwords.
The solution is a password manager: an app that generates them, stores them encrypted and fills them in for you. You only have to remember one master password, long and used nowhere else (a phrase of several words works better than a word with symbols). Avoid jotting them on sticky notes on the monitor, in a phone note or in a spreadsheet shared by the team.
Two-step verification: so a password alone is not enough
Two-step verification adds a second requirement at login: a temporary code or a confirmation on your phone. That way, even if someone steals your password, they cannot get in without that second element. Turn it on first for what hurts most to lose: email, bank, social media, your website admin panel and invoicing tools.
If you can choose, an authenticator app is better than SMS codes, although SMS is still better than nothing. And never share those codes with anyone, not even someone claiming to be from your bank.
Backups and updates: your insurance against disaster
A backup helps with a virus that encrypts your files, a computer that dies, an employee who deletes something by mistake or a theft. A simple, well-known rule is 3-2-1: three copies of your data, on two different types of media, with one of them off-site. What almost nobody does, and it is essential: test that you can restore it. A backup you have never opened is a hope, not a guarantee.
Updates to your system, browser and website (if you use a content manager like WordPress) usually fix known security holes. Putting them off is leaving a door open that anyone knows how to open. Turn on automatic updates wherever you can.
Phishing and scams by email and WhatsApp
Phishing is a message pretending to be someone you trust (your bank, a supplier, a courier, your boss) to get you to click a link, open an attachment or hand over details. The warning signs repeat: urgency ("your account will be locked today"), an odd sender even if the name looks right, strange wording or errors, links that do not match the official site, and requests for money or for a change of account number.
A very typical case in business: an email, apparently from a supplier, says their bank details have changed. Before paying, call the number you already had, not the one in the message. The same goes for the WhatsApp messages saying "hi, I've changed my number" that ask for urgent money. If in doubt, do not click, and check through another channel.
What to do if you get hacked
If you suspect someone has got in, act calmly and in order:
- Disconnect the affected device from the internet.
- From another, clean device, change the passwords of your important accounts, starting with email, and turn on two-step verification.
- Tell your bank if there are suspicious transactions or if you gave out payment details.
- Restore from a backup made before the problem.
- Ask for help: in Spain, INCIBE runs a free helpline on 017; elsewhere, look for your national cybersecurity authority.
If customers' personal data is affected, data protection rules may require you to notify the supervisory authority (in Spain, the AEPD) within 72 hours of becoming aware. It is worth checking this as soon as possible.
Frequently asked questions
Is it safe to keep all my passwords in one place?
With a good password manager, yes: it stores everything encrypted and only you hold the master key. It is far safer than reusing passwords or writing them on paper or in a loose file.
Do I need a paid antivirus?
Current systems come with reasonable basic protection. More than the software, habits matter: updating, not opening suspicious attachments, keeping backups and using different passwords. If your work handles sensitive data, talk to a professional.
How often should I back up?
It depends on how much work you can afford to lose: if you invoice daily, the backup should be daily and automatic. What matters is that it does not depend on someone remembering to do it.