One hour of security for people who don't do IT

A plain checklist for households and small offices: sign-in, passwords, updates, copies of your files, scams, and what to do when an account gets taken.

security small-business guide passwords phishing

October is Cybersecurity Awareness Month, and most of the advice that comes with it is written for companies that have a security team. This is for everyone else: a family, a five-person office, a shop with one computer at the counter. If you have an hour this week, do these in order. The first two cover most of what actually goes wrong.

1. Put a second lock on your email (10 minutes)

Start with email, not your bank. Your email is the reset button for every other account you own. Whoever controls it can click "forgot password" on your bank, your payroll, your social accounts, and read the reset link.

Turn on two-step sign-in (sometimes called 2FA or multi-factor). If you're offered a passkey or an authenticator app, pick that over a text message code, because text codes can be redirected by someone who talks your phone carrier into moving your number. A text code is still far better than nothing. Once email is done, do the same for your bank and anything that holds money.

2. Stop reusing passwords (20 minutes to start)

When a website gets breached, the stolen passwords get tried on every other site within days. If you use the same password in five places, one breach at a site you forgot you signed up for opens all five.

You can't remember a different long password for every account, and you shouldn't try. Use a password manager. The one built into your phone or browser (Apple Passwords, Google Password Manager) is fine, and so is a standalone one like Bitwarden. Pick one and let it generate passwords from now on.

You don't have to fix every account today. Change the important ones first: email, bank, anything with a card saved. Then check your address at haveibeenpwned.com, which lists the known breaches it has appeared in, and change those next.

3. Let updates happen (10 minutes)

Most break-ins on small networks don't need anything clever. They need a machine that hasn't been updated in a year. Turn on automatic updates for your phone, your computer and your browser. Then restart the computer, because a lot of updates sit downloaded and waiting for a restart that never comes.

Don't forget the router, the box your internet comes through. Log in to it (the address is usually printed on a sticker on the bottom), check for a firmware update, and change the admin password if it's still the one on the sticker. If the maker no longer puts out updates for your model, that's a good reason to replace it.

4. Keep a second copy of what you'd miss (15 minutes)

Ask yourself what would hurt to lose: family photos, the business's invoices, tax records, the customer list. Make sure there's a copy somewhere that isn't the same device. A cloud storage account works, and so does an external drive that you plug in, copy to, and unplug.

The unplugging matters. Ransomware encrypts every drive it can reach, including that spare drive if it's always plugged in. And once you've made a copy, try opening one file from it. A copy you've never opened is one you're only hoping works.

5. Learn the three scams you'll actually see

Most fraud aimed at small businesses and families comes in a few shapes:

  • "Our bank details have changed." An email that looks like it's from a supplier, a contractor or a title company, asking you to pay the next invoice to a new account. Often it really is from their address, because their email was taken first.
  • The fake sign-in page. A message says a document is shared with you, or your mailbox is full, or a package is held. The link goes to a page that looks exactly like your email login.
  • The helpful caller. Someone from "Microsoft", "your bank" or "the IRS" says there's a problem and needs you to install something, read back a code, or pay with gift cards.

One rule handles all three: check on a channel you already had. Call the supplier on the number you've always used, not the one in the email. Type the website address yourself instead of clicking. Hang up and call the number on the back of your card. No real company will ever ask for payment in gift cards, and nobody legitimate needs you to read them a sign-in code.

6. Know what to do on the bad day (5 minutes to read)

If an account gets taken over, the order matters:

  1. From a device you trust, change the password and sign out every other session (most services have a "sign out everywhere" option).
  2. In email, check the forwarding rules and the recovery phone and email. Attackers often add a quiet rule that forwards or deletes certain messages, so they can keep watching after you change the password.
  3. If money was sent, call your bank right away. Speed matters more than anything else on this list.
  4. Report it. In the US, fraud goes to the FTC at reportfraud.ftc.gov and online crime to the FBI at ic3.gov. Banks and insurers will often ask whether you did.

Write those four steps on a card and keep it somewhere you'll find it. On the bad day, nobody remembers the order.

If you'd rather hand this to someone

None of this needs special tools, and a careful person can do all of it. If you run a small business and would rather it was someone's job, that's what managed IT is for. We start every conversation with a free written audit of what you're running, and the report is yours whether you sign or not. Details are on our IT services page.

Want this handled for you?

SentinelGrid Managed IT is in open beta: monitoring, remote support, patching and a real helpdesk for one flat monthly fee, plus a free infrastructure audit whether you sign or not.