Which cybersecurity basics should a one-person business put in place first?

Business Tech & Tools

Which cybersecurity basics should a one-person business put in place first?

The short answer

Protect the accounts that can unlock everything else. Start with your email, password manager, cloud files, website, banking, payment processor, and domain registrar. Give each a unique password, turn on strong multifactor authentication, save recovery codes safely, and update the devices you use for work.

Then add automatic backups, a short client-data inventory, and one written incident page. You do not need an enterprise security department to become much harder to fool and much easier to recover.

Do these seven jobs in order

1. Secure your main email account

Your email can reset many other passwords, so treat it like the front door. Change any reused password, enable multifactor authentication, review recovery email addresses and phone numbers, sign out unknown sessions, and remove old connected apps.

2. Put passwords in a password manager

Use a different generated password for every business account. Protect the manager with a long master password and multifactor authentication. Never store the master password in the same unprotected note as your recovery codes.

3. Turn on multifactor authentication for critical accounts

Prioritize email, password manager, cloud storage, financial services, payment processor, website administrator, social accounts, domain registrar, and tax or government portals. Prefer passkeys, security keys, or authentication apps when the service offers them. Text-message codes are still better than password-only protection, but they are not the strongest choice.

CISA calls multifactor authentication a simple, effective step that can reduce account compromise. See its small-business MFA guidance.

4. Let devices and software update

Turn on automatic updates for your computer, phone, browser, office software, password manager, website platform, and plugins. Remove software you no longer use. An abandoned plugin is not harmless just because the page still looks fine.

5. Back up the files you cannot afford to recreate

Keep a separate backup in addition to cloud sync, protect its account, and test a restore. Include client work, financial exports, website material, contracts, and any original content that would be expensive to rebuild.

6. Limit the information you collect

Make a list of where customer names, addresses, forms, recordings, contracts, and payment-related records live. Delete unnecessary copies according to appropriate retention rules. Give contractors only the access they need and remove it promptly when the work ends.

The Federal Trade Commission's data-protection guide for businesses recommends knowing what personal information the business holds, keeping only what is needed, restricting access, protecting disposal, and planning for incidents.

7. Write the “something is wrong” page

Keep a printed or separately protected page with:

  • how to contact your email, bank, payment, website, and cloud providers.
  • where backups and recovery codes are stored.
  • the person who can help with technical recovery.
  • how to pause payments or website access.
  • where to report fraud or a cybercrime.
  • which clients, insurers, regulators, or professionals may need notice.

Do not wait for an incident to research local breach-notification or industry requirements. Laws and contractual duties vary, so check the current rules that apply to your business and get qualified help when sensitive information is involved.

Use a thirty-minute weekly safety check

Pick one recurring time. Look for update warnings, failed backups, unfamiliar login alerts, new account recovery options, and old contractor access. Review one suspicious email together with its real destination before clicking anything.

CISA's small and medium-sized business resources group practical help around passwords, MFA, updates, logging, backups, and encryption. Use that official collection to deepen one area at a time.

If you discover an unknown login, payment change, mass file edit, or malware warning, stop normal work. Use a separate trusted device to contact the provider or a qualified security professional. Do not keep experimenting inside an account that may be compromised.

Sources and further reading

A free next step

You don't have to build this alone

Bring your questions, share what you're working on, and meet other women building businesses from home. It is free to join.

Join Our Community Free

Related Questions

← All questions