Skip to main content
Home >Blog >AI in Web Development

Cybersecurity for small businesses: 7 simple habits to avoid major issues

Unexpected bank details, forgotten access, or unusable backups: seven practical habits to better protect your small business's accounts and data.

Cybersecurity for small businesses: 7 simple habits to avoid major issues
Sur cette page7 sections
A supplier writes to you saying they have changed banks. The email looks like previous ones, the invoice seems normal, and they simply ask you to use the new bank details. You already have a lot to manage; paying and moving on to the next task seems logical enough.

Yet it is in this very ordinary moment that a company's security can be at stake. Not necessarily in a hacking scene with green lines on a black background, but in a credible request, at a time when no one takes the time to verify it.

For a small business, I would start by making a few habits easy to follow. The goal isn't for everyone to become an expert, but to ensure that an error on one account doesn't bring the entire business to a standstill.

1 A different password for every door

If you use the same key for the office, the workshop, and the storeroom, losing that key opens many doors. Reusing a password works much the same way: a leak from one service can allow someone to try the same access elsewhere.

A password manager avoids having to memorise an impossible collection. It creates and stores different passwords, while you specifically protect access to the manager itself. A long phrase can help you remember an important secret, but don't use the same phrase for every account.

Start with email, banking, invoicing, hosting, and your domain. These are access points that allow someone to either act on behalf of the business or recover other accounts. And avoid that 'passwords' document that everyone sends around when someone new joins.

2 Protect your email as a central account

Your email doesn't just contain exchanges. It often receives reset links for other services. Someone who gains access can try to recover much more than just an inbox.

Enable two-factor authentication whenever the service allows it. An authenticator app or a security key adds a layer of verification to the password. It's not absolute protection, but a stolen password is then no longer enough, on its own, to open the account.

Also prepare for recovery: backup codes kept securely, or a replacement device/method depending on the service. Otherwise, the day you change your phone, security could turn into a locked door for you too. Never approve a login request that you didn't initiate.

3 When pressured, switch channels

Let's go back to the new bank details. The right reflex isn't to judge whether the email has enough typos to be suspicious. It's to call your contact using a number you already know—not the one added to the message—and confirm the change.

The same principle applies to an unusual request from the director, an unexpected attachment, or an access that needs immediate renewal. Move away from the channel carrying the request. Replying to the same email to ask "is this really you?" doesn't help if that email account is compromised.

Above all, the team must be able to do this without fear of being a nuisance. If all urgent requests must be executed without question, it makes it easier for someone mimicking an emergency. A verification call should be a normal habit, not a lack of trust.

4 Keep updates current and know who is responsible

An update might change a feature, but it can also fix a known vulnerability. Leaving a browser, system, or extension unmonitored for months is like keeping a lock with a documented flaw.

On devices, enable automatic updates where appropriate. For the website, plan for component monitoring, backups, and post-intervention checks. Security patches shouldn't sit in a list that no one looks at.

The key question is "who is looking after it?". The host might maintain their infrastructure without updating your application. Your provider might monitor the site without managing the office computers. A small inventory of responsibilities helps spot gaps between contracts.

5 A copy that doesn't disappear with the original

Syncing a folder is convenient. But if an unwanted deletion or modification spreads everywhere, all synced copies may follow. This isn't automatically a backup that allows you to return to a previous state.

For your documents and your site, check what you can restore, over what period, and from where. A separate, protected copy prevents a single incident from taking down both the work and its backup. Then try to recover a file or restore a test environment: this small exercise helps discover problems before an emergency hits.

Le CNIL guide on backups reminds us in particular of the importance of protecting them and testing restoration. The right question isn't "are we backing up?", but "if this folder disappears this afternoon, how do we get it back?".

6 Individual access, not total power

The person editing a photo doesn't necessarily need to manage users or delete the site. Tailored permissions limit what an error or a compromised account can affect.

Individual accounts also allow you to remove access without changing the password for the whole team. When an employee or provider leaves, review the tools, remote access, and recovery methods. An unused account is still an account that could be used by someone else.

Keep a simple inventory of important services, their owners, and authorised personnel. The company domain shouldn't depend on an old personal email address that no one knows how to recover.

7 Prepare the first call before the problem occurs

The day you find encrypted files or an unknown login is not the right time to search for which contract covers what. Prepare the provider's contact details, account managers, and a short procedure tailored to the tools you use.

In case of serious doubt, quickly report what you've observed and keep useful messages and information. If a device seems compromised, isolate it from the network and seek assistance before trying multiple fixes. To secure accounts, use a reliable device. Restoring data without addressing the cause can simply put the problem back into circulation.

Depending on the incident, other steps will be necessary, particularly when personal data is involved. Cybermalveillance.gouv.fr offers an assistance path to guide victims. This doesn't replace the company's obligations, but it ensures you don't start alone with random attempts.

You don't have to overhaul everything today. Secure your email, check which access points remain open, and try to retrieve a document from a backup. These actions already provide answers to three very concrete questions: who can get in, how far can they go, and how do we start again if something goes wrong.