There is a comforting myth that cybercrime is something that happens to big companies. The bank, the retailer, the listed firm with millions of records. Small businesses tell themselves they are too small to bother with, and so they skip the basics and hope. The reality is the opposite. Small businesses get hit constantly, precisely because they assume nobody is looking, and because the basics are so often left undone.

Most breaches are not clever. They are not some genius cracking your firewall at three in the morning. They are a weak password, a missing update, or a staff member clicking a link they should not have.

That is actually good news. It means you do not need a security team or a big budget to protect yourself from the bulk of what is out there. You need to cover the basics, properly and consistently. The attackers hitting small businesses are mostly running automated, scattergun attempts, looking for the easy door left open. They are not interested in a fair fight, they are interested in a quick win. Close the easy doors and most of them simply move on to the next target. Here is the checklist we walk small businesses through.

The high-value checklist

None of these are exotic. They are the cheap, unglamorous habits that stop the overwhelming majority of attacks before they start.

Phishing is the number one way in

If you only take one thing seriously, make it this. The most common way attackers get into a small business is not technical at all. It is an email that tricks someone into handing over a password or clicking a malicious link. It might look like it comes from your bank, a supplier, or even the boss asking for an urgent payment.

What to watch for

Teach your team a few simple tells. A sense of urgency designed to make you act before you think. A request for login details or payment that arrives out of the blue. A sender address that is almost right but slightly off. A link that does not quite match where it claims to go. When something feels wrong, the right move is always to stop and check through a separate channel, not to click. A quick phone call to confirm an unusual payment request has saved many a business from a costly mistake, and it costs nothing but a minute.

You can spend a fortune on security software and still get breached by one tired employee clicking one convincing email. The cheapest defence you have is a team that knows what to look for.

Turn on MFA this week

If your to-do list feels long, start with one thing: switch on multi-factor authentication for your email and your banking. Email is the master key to most of your other accounts, because that is where password resets land. Protecting it with a second step is the single highest-value hour you can spend on security, and it costs nothing.

Cheap habits beat expensive tools

It is tempting to think security is something you buy: a fancy product, a subscription, a piece of software that promises to handle it all. Those have their place, but they are not where the real protection lives. The businesses that stay safe are the ones with good habits, strong passwords, MFA, updates installed, backups tested, staff who pause before they click.

None of that requires a big budget. It requires consistency, which is genuinely harder, but it is within reach of any small business that decides to take it seriously. You do not have to be unbreakable. You just have to be a harder target than the next business along, and covering these basics puts you well ahead of most. Start with one item this week, and keep going.