7 Low-Cost Ways Small Businesses Can Fight Cybercrime

Small businesses often assume cybercriminals are interested only in banks, telecom companies and large corporations. But smaller firms can also become targets because they often have weaker security, fewer trained employees and limited plans for responding to attacks.

A Kaspersky study covering small and medium-sized businesses across 16 countries in Europe and Africa found that only 29 per cent of those surveyed had fully implemented cybersecurity plans. More than one in five said they lacked skilled staff to manage security, while 34 per cent were unsure how to respond properly after an attack.

These findings should not be treated as statistics for all Nigerian SMEs. However, they show problems that many small businesses face: weak passwords, outdated software, poor staff awareness and unclear response plans.

Basic security steps cannot prevent every cyberattack. They can, however, make a business harder to attack and reduce the damage when something goes wrong.

1. Turn On Two-Step Verification

A password should not be the only protection for a company’s email, bank account or social media page.

Two-step verification, also known as multifactor authentication, asks users to provide another form of proof after entering a password. This could be a code from an authentication app, a fingerprint or a physical security key.

This extra step means that stealing a password may not be enough to enter the account.

Businesses should begin with their most important accounts:

  • business email;
  • online banking;
  • payment platforms;
  • cloud storage;
  • website administration;
  • social media accounts.

Many platforms provide two-step verification free of charge.

Authentication apps and physical security keys are generally safer than codes sent by text message. No method removes every risk, but stronger forms of verification make account theft more difficult.

2. Stop Reusing Passwords

Using one password across several accounts may be convenient, but it creates a serious weakness.

When criminals obtain a password from one breached platform, they often test it on other services. A password stolen from a shopping website could therefore be used to attack a business email, social media account or payment platform.

Every important account should have a different password.

A password manager can help business owners and employees create and store strong passwords without having to remember each one.

Businesses should also avoid sending passwords through WhatsApp, email or group chats. Each employee should have a separate account where possible.

This makes it easier to remove access when someone leaves without changing the login details for every other worker.

3. Keep Devices and Software Updated

Software updates may interrupt work or consume mobile data, but delaying them can leave known security weaknesses open.

Attackers often take advantage of flaws that software companies have already fixed. Installing updates closes many of those gaps.

Small businesses should turn on automatic updates for:

  • phones and computers;
  • web browsers;
  • accounting applications;
  • payment software;
  • antivirus tools;
  • website themes and plugins.

Businesses using WordPress should pay particular attention to outdated plugins and themes. Unused software should be removed rather than left connected to the website.

Updates alone will not stop every attack. But they reduce the chance that criminals can use an old and well-known weakness to enter a company’s systems.

4. Teach Staff to Check Before They Click

Employees are often the first people targeted during a cyberattack.

A criminal may send a fake invoice, delivery notice, password-reset message or payment request that appears to come from a customer, supplier, bank or senior employee.

Attackers may also take control of a real business email account and use it to request money or change payment details.

Staff training does not have to involve an expensive consultant. A business can hold short monthly sessions showing workers how to:

  • check the sender’s full email address;
  • avoid unexpected attachments;
  • question urgent payment requests;
  • confirm changes to bank details by phone;
  • report suspicious messages;
  • avoid entering passwords through email links.

One simple rule can prevent serious losses: no employee should change a supplier’s bank details or make an unusual payment without confirming the request through another channel.

For example, a worker who receives payment instructions by email should call a known contact before sending the money.

5. Back Up Important Business Files

A cyberattack can lock a company out of its files, damage devices or delete important records.

Regular backups can help the business recover without starting from nothing.

Important information may include:

  • customer records;
  • invoices and receipts;
  • supplier details;
  • payroll information;
  • contracts;
  • stock records;
  • tax documents;
  • product photographs.

A business can keep one copy in secure cloud storage and another on an external drive. The external drive should be disconnected after the backup is completed.

This matters because malware can damage backups that remain permanently connected to an infected computer.

Business owners should also test their backups occasionally. Saving files is not enough. The business must confirm that the information can actually be opened and restored.

6. Give Workers Only the Access They Need

Not every employee needs access to every account.

A salesperson may need customer records but not payroll information. A social media manager may need access to Instagram but not the company’s online banking platform.

Limiting access reduces the damage that one stolen or misused account can cause.

The business owner should keep a basic record showing:

  • each company account;
  • who has access;
  • what each person can do;
  • when access was last reviewed.

Access should be removed quickly when an employee, freelancer, accountant, developer or agency stops working with the company.

Old accounts are often forgotten. They can later become an easy route into the business.

7. Prepare a Simple Response Plan

Many small businesses do not know what to do when an email is hacked, a phone is stolen or an unauthorised payment is discovered.

A simple one-page plan can help employees respond quickly.

It should answer:

  • Who should staff contact first?
  • Which devices should be disconnected?
  • Who will contact the bank?
  • Who will change passwords?
  • Where are the backup files?
  • Which customers or partners may need to be informed?
  • Who will record what happened?

The plan should also contain the contact details of the company’s bank, hosting provider, software supplier and technical support person.

Not every technical problem needs to be reported to the Nigeria Data Protection Commission. However, under Nigeria’s data-protection rules, a business may need to notify the commission within 72 hours when a personal-data breach is likely to create a serious risk to the people affected.

The business should therefore assess whether customer, employee or supplier information was exposed, not just whether a device stopped working.

Where Should a Small Business Begin?

A business does not need to complete all seven steps at once.

It can begin by protecting its most important email, banking and payment accounts with two-step verification. It should then update its devices, back up important files and review who has access to company systems.

The next step can be a short staff meeting about fake payment requests, suspicious links and changes to supplier bank details.

Cybersecurity is not only an information technology issue. It protects the company’s money, customer information, reputation and ability to continue operating.

Low-cost measures will not make a business impossible to attack. They can make it less vulnerable, improve its response and prevent a small mistake from becoming a serious business crisis.


Expert View

The National Institute of Standards and Technology created a cybersecurity guide specifically for small businesses with little or no formal security plan.

Its approach is straightforward: businesses should identify what they need to protect, reduce obvious weaknesses, detect unusual activity, prepare a response and decide how operations will recover after an incident.

That matters because small businesses do not need to copy the complex security systems of large corporations. They need controls that match their size, risks and daily operations.

Frequently Asked Questions

Do small businesses really need cybersecurity?

Yes. Small businesses hold customer information, payment details, company emails and financial records that criminals can steal or misuse. Their weaker security can also make them easier targets than larger organisations.

What is the cheapest way to improve business security?

Start by turning on multifactor authentication, using separate passwords, updating software and training staff to check payment requests. These steps cost little or nothing on many platforms.

What should a small business do after a cyberattack?

Disconnect affected devices, change passwords from a safe device, contact the bank or service provider and record what happened. Businesses should also assess whether customer information was exposed and whether the incident must be reported to the NDPC.

Leave a Reply