Educational guide

The cybersecurity stack a small business actually needs.

Small businesses are rarely compromised by sophisticated attacks. They are compromised by reused passwords, unpatched laptops and untested backups — which is why the order you buy things in matters more than the brands.

Updated 8/8/2026 · The Tool Money Lab editorial team · Foundation · 9 min read

Cybersecurity Learning Centre

Key takeaways
  • Identity is layer one. Multi-factor authentication and a password manager remove the majority of realistic small-business compromise.
  • Backups only count if you have restored from them. An untested backup is a hope, not a control.
  • Endpoint protection and prompt patching cover the commodity malware and known-vulnerability attacks that make up most incidents.
  • A VPN protects traffic on untrusted networks; it does not protect accounts, devices or data at rest.
  • Security testing belongs after the fundamentals — otherwise you pay experts to report what you already know.

Order matters more than product choice

Small businesses are usually sold security in the wrong sequence, because the loudest products are not the highest-value ones. The realistic threat model is not a targeted adversary; it is credential reuse, phishing, commodity ransomware and an unpatched device.

Everything below is ordered by risk removed per pound and per hour of setup. Working down this list is more effective than buying an expensive platform at step five while step one remains unfinished.

Priority order for a 5–50 person business
PriorityLayerWhy it comes hereTypical effort
1Identity: MFA everywhere, password manager, least privilegeStolen and reused credentials are the most common entry pointDays, mostly policy and rollout
2Backups: automated, offsite, tested restoresThe only control that reliably survives ransomwareHours to set up, ongoing to verify
3Endpoints: reputable protection, disk encryption, automatic updatesCovers commodity malware and known-vulnerability exploitationHours per device, then automated
4Email and collaboration hardening: filtering, DMARC, sharing defaultsPhishing and over-shared documents are routine causes of lossDays, with occasional review
5Network and remote access: VPN for untrusted networks, no exposed admin interfacesProtects work on the road; removes casual exposureHours
6Testing: continuous vulnerability assessment, then penetration testingFinds what remains once the obvious is fixedOngoing subscription

Layer one: identity

If you do exactly one thing, enforce multi-factor authentication on email, the identity provider, finance systems and anything holding customer data. Phishing-resistant methods — passkeys or hardware keys — are stronger than app codes, and app codes are far stronger than SMS.

Pair it with a password manager for the whole team, not just the technical staff. The point is not memorability; it is that every account gets a unique credential, so one breached third-party service cannot cascade into your systems.

Then reduce standing privilege. Most small businesses have several accounts with administrative rights nobody needs day to day, and shared logins whose password left with a former employee.

Layer two: backups you have actually restored

Ransomware turns a security incident into a business-continuity event, and the deciding factor is always the backup. Three properties matter: it runs automatically, a copy is somewhere an attacker with your credentials cannot delete, and you have performed a restore recently enough to trust it.

The third is the one that fails. Teams discover during an incident that the backup covered the file server but not the SaaS data, or that nobody knows the restore procedure, or that the retention window was shorter than the time the attacker spent inside. Schedule a restore test and write down how long it took.

Layers three to five: devices, email and network

Endpoints need three things: reputable protection running and reporting, full-disk encryption enabled, and automatic operating system and browser updates. Patching promptly closes the known vulnerabilities that make up a large share of successful attacks, and it costs nothing but discipline.

Email is where most incidents begin. Turn on the filtering your provider already includes, publish SPF, DKIM and DMARC records so your domain is harder to spoof, and check the default sharing settings in your document platform — public link sharing is a routine cause of quiet data exposure.

A VPN belongs here rather than higher up. It is genuinely useful for staff working on untrusted networks and for reaching internal services, and it does nothing about weak passwords, unpatched laptops or a phished account. Buy it for what it does.

Layer six: testing, once the basics hold

Testing is where small businesses tend to start when a customer questionnaire arrives, and it is the least efficient first purchase. Against an estate with no MFA and inconsistent patching, a test produces an expensive restatement of the obvious.

Once layers one to five are in place, continuous vulnerability assessment of your internet-facing surface is inexpensive and worthwhile, and a scoped penetration test of anything bespoke — a customer portal, an API, a payment flow — becomes genuinely informative.

This is also the point at which security spend starts paying commercially rather than only defensively: reports, retest records and a documented policy are what unblock enterprise procurement and insurance questions.

What not to buy yet

Two categories consistently arrive too early. Enterprise detection-and-response platforms assume someone is available to investigate alerts; without that person they generate noise and a licence cost. Security validation platforms assume you already own controls whose efficacy needs proving — which is not the case at this stage.

Compliance automation tools are a partial exception: if a customer or regulator is genuinely demanding a framework, they save real time. Bought speculatively, they document a programme you have not built yet.

FAQ

What is the single most valuable security control for a small business?

Enforced multi-factor authentication on email and the identity provider. Credential compromise is the most common realistic entry point, and MFA removes most of it for close to no cost.

Do we need antivirus if we use Macs?

Endpoint protection is still worthwhile on macOS, and disk encryption plus prompt updates matter regardless of platform. Platform choice reduces exposure to some commodity malware; it does not remove phishing or credential risk.

Is a VPN enough to secure remote workers?

No. A VPN protects traffic in transit and can gate access to internal services. Remote workers still need MFA, an encrypted and patched device, and a managed password store.

How much should a small business spend on security?

The first layers cost far less than most owners expect — MFA is usually free, a password manager and backups are modest per-user costs. Spending scales with regulatory obligation and with how much bespoke software you run.

Do we need a penetration test to win enterprise customers?

Frequently yes, once deals reach a certain size, because vendor questionnaires ask for testing evidence. Get the fundamentals in place first so the test finds subtle issues rather than basic ones.

Should we hire someone or use a managed provider?

Below roughly fifty people, a managed IT or security provider is usually more practical than a hire — provided you retain ownership of decisions rather than delegating accountability with the work.

How do we know if our backups are working?

Restore something. Pick a file and a system, restore them, and record how long it took and what went wrong. Anything short of that is monitoring the backup job, not the backup.

Where to go next

This guide is deliberately vendor-neutral. When you are ready to evaluate products, these are the TTML pages that continue the topic.

Glossary:multi factor authenticationpassword managervpnend to end encryptionzero trust

Continue the curriculum
Editorial process

Our reviews are based on vendor documentation, publicly available product information, independent testing where available, and ongoing editorial updates. We do not sell rankings. Where a page carries affiliate links we may earn a commission at no additional cost to you, and that relationship never changes the conclusion — see our affiliate disclosure and review methodology.

Last reviewed
Reviewed by
The Tool Money Lab Editorial Team — independent software research
Evidence sources
Vendor Documentation · Public Standards Documentation (NIST CSF, UK NCSC Cyber Essentials)
Intelligence Brief

Stay Ahead of AI

Receive our weekly Intelligence Brief. Independent AI reviews, comparisons, new tools and practical recommendations delivered every Friday.

  • New AI tools
  • Honest reviews
  • Best AI deals
  • New comparisons
  • Industry trends
  • No spam.