Basic cybersecurity for SMEs: protect your business without being an expert
Passwords, backups, phishing, and more. The fundamentals every business owner should know.
David Lucas
Nexora

You don't need to be a hacker to protect your business
Cybersecurity sounds intimidating, but the reality is that 90% of successful attacks on small businesses are due to basic mistakes anyone can avoid: weak passwords, phishing emails, lack of backups.
You don't need an IT department or spend thousands. With these basic practices you can protect your business from most threats.
1. Passwords: your first line of defense
The password "123456" is still the most used in the world. If your password is your birthday, your pet's name, or "password1," you're giving away access to your business.
Basic rules:
1. Use passwords of at least 12 characters with uppercase, lowercase, numbers, and symbols.
2. Never use the same password on two different sites.
3. Use a password manager (Bitwarden is free and excellent) to generate and store unique passwords.
4. Enable two-factor authentication (2FA) on ALL accounts that allow it: email, banking, social media, hosting.
2. Phishing: the most effective trick
Phishing is when someone sends you an email, message, or link that looks legitimate but is fake. The goal is for you to click, enter your data, or download something malicious.
How to detect it:
1. Check the sender. An email from "your bank" coming from `support@bankx-security.xyz` is not from your bank.
2. Be suspicious of urgency. "Your account will be blocked in 24 hours" is the most common tactic.
3. Don't click suspicious links. Hover over them (without clicking) to see where they actually lead.
4. If in doubt, contact the company directly through their official channel, not through the email link.
Train your team. The weakest link is always human. A basic 30-minute training can prevent a disaster.
3. Backups: your insurance against disasters
Imagine tomorrow you lose everything: your computer breaks down, ransomware encrypts your files, or an employee accidentally deletes something. How long would it take you to recover?
The 3-2-1 rule:
3 copies of your data.
2 on different media (hard drive + cloud).
1 in a different location (offsite).
Accessible tools: Google Drive, Dropbox, or Backblaze for automatic cloud backups. If you use WordPress, plugins like UpdraftPlus do automatic daily backups.
Test your backups. A backup you've never restored is a backup you don't know works.
4. Updates: don't ignore them
Those "update available" notifications you always postpone exist for a reason: every update includes security patches that fix known vulnerabilities.
Always update:
1. Operating system (Windows, macOS, iOS, Android).
2. Web browser (Chrome, Firefox, Safari).
3. WordPress and its plugins (if you have a website).
4. Business applications (accounting, CRM, email).
Enable automatic updates wherever possible.
5. Business WiFi: don't leave it open
If your business has WiFi, make sure it's protected:
1. Change the router's default password.
2. Use WPA3 encryption (or WPA2 at minimum).
3. Create a separate network for customers/visitors and another for your team.
4. Change the password every 3-6 months.
6. Access and permissions: not everyone needs everything
Principle of least privilege: each person should have access only to what they need to do their job. Don't give your intern admin access to everything.
When someone leaves: Revoke their access immediately. Email, systems, social media, hosting — everything. It's surprising how many companies forget this.
7. Your website: protect it
If you have a website (and you should), these are the security basics:
SSL/HTTPS — We already discussed this. It's mandatory.
WordPress/plugin updates — The #1 cause of WordPress hacks are outdated plugins.
Strong admin passwords — Don't use "admin" as your username.
Web firewall — Services like Cloudflare (free) protect your site from common attacks.
Monitoring — Tools like Sucuri or Wordfence alert you if something suspicious happens on your site.
What to do if you get hacked?
1. Don't panic. Document what happened and when.
2. Disconnect the affected system from the internet.
3. Change ALL your passwords from a clean device.
4. Restore from your last verified backup.
5. Notify your customers if their data may have been compromised.
6. Contact a security professional to investigate the root cause.
Security isn't an expense, it's insurance
A cyberattack can cost you from a few hundred dollars (in lost time) to business bankruptcy (from data or reputation loss). Basic security measures cost little or nothing, but they protect you from most threats.
At Nexora, all the systems we develop include security practices from the architecture. If you need a security audit or consulting to protect your business, we're here to help.

