IT services

Cybersecurity for small business: 10 practical steps to protect your office network and data

You do not need a big budget or an in-house IT department to close the most common gaps — you need a clear order of priorities and a little discipline.

IT services 📖 10 min read Select IT team

Most small businesses are convinced that "we have nothing worth stealing." In practice, attacks are rarely aimed at a specific company — automated scripts scan the internet for exposed services, weak passwords and unpatched software, and email campaigns go out to thousands of addresses at once. A small office is an easy target precisely because it usually has no security specialist, and the same person is the accountant, the computer administrator and "the one who deals with the internet."

The good news is that much of the risk can be closed with a few inexpensive but consistently applied measures. This guide is a practical plan: what threatens you, ten steps, and finally a priority table.

What actually threatens a small office

The threats are far more mundane than movie hackers. Almost everything comes down to a handful of recurring scenarios:

ThreatHow it most often happensFirst defence
PhishingA message imitating a courier, bank, supplier or boss that urges a click, a login to an "account" or a paymentTrained people and MFA
RansomwareA malicious file encrypts documents on the computer and on reachable network folders, then demands a ransomBackups the attacker cannot reach
Weak and reused passwordsOne password is used everywhere; after a leak from one site it is tried on the othersPassword manager and MFA
Unpatched devicesA known vulnerability in a computer, router or camera stays open for monthsRegular updates
Exposed remote accessA remote desktop service is reachable directly from the internetAccess only through a VPN

None of these threats requires a sophisticated attack. That is why protection starts not with the most expensive product, but with discipline around the basics.

Step 1: backups following the 3-2-1 rule

If you do only one thing from this article, make it this. A backup is the only defence that still works when everything else has failed — ransomware, a failed disk, human error, theft or fire. The 3-2-1 rule is a proven and easy-to-remember guideline:

  • 3 copies of important data — the original plus at least two backups.
  • 2 different media or systems — for example a NAS and an external drive, not two folders on the same hard disk.
  • 1 copy off-site — in the cloud or at another physical location, so that a fire or theft does not take both the original and the copies.

An often-overlooked detail: at least one copy must be unreachable from an infected computer — offline, behind separate credentials, or with an immutability feature. Ransomware encrypts everything the computer can access, including permanently connected network folders and external drives.

A backup that has not been tested is an assumption. At least once a quarter, actually restore a few files, and once a year restore a whole system in a test environment. It is not unusual to find that the job has been "successfully" copying for months but never included the important folder, or that the password for the encrypted archive is not written down anywhere.

Steps 2–4: accounts, updates and computer protection

Step 2: MFA and a password manager

Multi-factor authentication (MFA) adds a second check on top of the password. Even if the password has leaked or been typed into a fake page, the attacker cannot get in without the second factor. Turn it on first where the damage would be greatest: business email, cloud storage, accounting and banking systems, router panels, hosting and domain. When you have a choice, prefer an authenticator app or a hardware key over SMS — text messages are easier to intercept and redirect.

People cannot remember dozens of long, different passwords, so they start reusing them or writing them under the keyboard. A password manager solves this: it remembers everything, generates long random passwords and fills them in only on the genuine site address, which also protects against fake pages. One strong master password plus MFA on the manager itself is far better than any "clever" scheme.

Step 3: updates

Most successful attacks exploit vulnerabilities for which the vendor has already released a fix. Turn on automatic updates for the operating system and applications. Do not forget devices that do not look like computers: routers, switches, access points, NAS units and printers — they get firmware updates rarely and often stay unpatched for years. Make a simple list of everything on the network — model, location, who maintains it, when it was last updated. A device that no longer receives fixes is a candidate for replacement, or at least for strict isolation.

Step 4: endpoint protection

Every computer and server should run modern protection against malicious code that updates itself and is managed centrally, rather than left to each user. Enable disk encryption on laptops — a lost or stolen laptop is then an inconvenience, not a data leak. If employees do not work with administrator rights, a large share of malware simply cannot install.

Steps 5–6: Wi-Fi, firewall and remote access

Step 5: secure Wi-Fi and network separation

Use WPA3 for wireless, and where the equipment does not support it, WPA2 with AES encryption and a long password. Abandon legacy modes (WEP, the original WPA, TKIP) and turn off WPS — the quick-connect feature using a button or PIN that has long been known as a weak point. Change the Wi-Fi password when someone who knew it leaves.

Guests and personal phones should not share a network with the accounting computer and the server. Set up a separate guest network that provides internet only and has no route to internal devices — most modern routers and access points support this with a few settings.

The next level is segmentation. Instead of one flat network where every device sees every other, the network is split into zones — for work computers, for servers and storage, for guests, for cameras and printers. This is done with VLANs on a managed switch, while the rules about who may talk to whom are set on the firewall. That way, if one zone is compromised, the attacker does not automatically get access to everything else.

Step 6: firewall and remote access

The firewall is the boundary between your network and the internet. Check three things: its firmware is current, its admin panel is not reachable from outside, and inbound connections are reduced to what is truly necessary. Turn off UPnP unless you know exactly why you need it — it lets devices open ports to the internet on their own.

The most common mistake in remote work is forwarding a port directly to a computer or service "so we can connect from home." A remote desktop exposed to the internet is constantly scanned and attacked with automated password guessing. The better solution is a VPN to the office firewall, with individual accounts and MFA. An outside vendor who supports one of your systems gets access only for the period needed and through a separate account that is then disabled.

Steps 7–8: least privilege, cameras and IoT devices

Step 7: the principle of least privilege

Every user should have only the access they need. Daily work is not done with an administrator account — that is separate and used only when needed. That way, if an employee opens a malicious file, the damage is limited to what they can access, not the whole company. Keep shared folders at department level rather than "everyone sees everything." When someone leaves or changes role, review their permissions the same day. Avoid shared accounts — in an incident you will not know who did what.

Step 8: video surveillance and IoT

Cameras, video recorders (NVR/DVR), access control, smart TVs and printers are full computers on the network, but they are rarely treated as such. The problems repeat:

  • Default passwords. Change the default password on every device at installation and do not use the same one for all cameras.
  • Direct access from the internet. Do not forward ports to the recorder in order to watch remotely — use a VPN.
  • No updates. Watch for new firmware and replace equipment that is no longer supported.
  • Same network as the computers. Put the cameras and recorder in a separate network (VLAN) with no path to the accounting server.

Isolation is one of the most effective things you can do: if a camera is breached, it stays in a "cage" and is not a bridge to the rest of the network. Video recordings contain personal data, so access to them should be restricted and use individual accounts.

Steps 9–10: people and the incident plan

Step 9: employee awareness

Technology closes some of the risks, but the final decision is often made by the person at the screen. You do not need a heavy presentation — short, regular conversations and a few clear rules are enough: check the real sender address; do not open unexpected attachments; do not enter a password through a link in a message, open the site yourself; for a request for an urgent transfer or a change of bank account, call a known phone number, not the one in the email. Culture matters most: an employee who clicked and reported it immediately deserves thanks, not blame.

Step 10: a simple incident plan

When something happens, there is no time to invent a procedure. The plan is one page, in a visible place and with a copy outside the company network, containing:

  1. Who is responsible and who is their deputy, with phone numbers that do not depend on company email.
  2. The first actions: disconnecting the affected computer from the network (cable or Wi-Fi), without wiping traces.
  3. Whom to notify: the IT specialist or provider, management, the bank if there is financial risk.
  4. How passwords on affected accounts are changed and where data is restored from.
  5. Who judges whether personal data is affected and how what happened is recorded.

Review the plan once a year and rehearse it with a short drill: "what do we do if all files are encrypted tomorrow morning?"

Personal data: the basics not to skip

Even the smallest company processes personal data — of customers, employees, job applicants, and camera recordings count too. Without going into legal detail (consult a specialist for that), sensible practices are:

  • Know what personal data you collect, where it is kept and who has access.
  • Collect only what is necessary and do not keep it forever — set a retention period and delete after it expires.
  • Restrict access by role and encrypt laptops and portable media.
  • Have a written procedure for what to do in a data leak. A personal data breach comes with deadlines for notifying the supervisory authority (in Bulgaria, the Commission for Personal Data Protection), so seek legal advice immediately.

Priority checklist: where to start

Not everything has to happen in one week. The order follows the principle of "the biggest risk reduction for the least effort" — start at the top.

#MeasureEffort
13-2-1 backups with one unreachable copy and a restore testMedium
2MFA on email, cloud, bank and admin panelsLow
3Password manager, an end to reused passwordsLow
4Change default passwords on router, cameras and NVRLow
5Automatic updates and a device inventoryLow to medium
6Close direct remote access, VPN with MFAMedium
7Endpoint protection, laptop encryptionLow to medium
8Guest Wi-Fi network and WPA2/WPA3Low
9Least privilege and separate admin accountsMedium
10Team awareness and a one-page incident planLow
11VLAN segmentation, isolating cameras and IoTMedium to high

Frequently asked questions

Is antivirus enough to be protected?

No. It is important, but it does not help against stolen passwords, phishing, an unpatched router or open remote access. That is why the plan combines several layers — backups, MFA, updates, network protection and awareness.

Is the cloud automatically a backup?

Not necessarily. Sync services keep the current state — if a file is deleted or encrypted, the change is carried over there too. You need a real backup with version history. Check the terms of the specific service and still test restoring.

Do cameras need a separate network?

It is strongly recommended. Cameras and recorders often have weak firmware and are rarely updated, and a separate network limits the damage if one device is breached. Even without VLANs, you can change the passwords and close access from the internet.

Can we manage on our own, or do we need an outside specialist?

Many of the first steps — MFA, a password manager, changing passwords, awareness — can be done in-house. Segmentation, VPN, the firewall and the backup system are best designed by someone experienced and then maintained by a clear procedure. For a network or video surveillance assessment you can also turn to the Select IT team.

Not sure where to start with securing your office?

We will review your network, backups and video surveillance and propose a concrete plan that fits your budget.

📍
Address15 Balgaria St, Dobrich, 9300
📞
Phone+359 876 601 099
✉
Emailoffice@selectit.bg
🕘
Working hoursMon – Fri: 9:00 – 18:00