Skip to content
Syncwright

Blog / Security

Security basics every small business gets wrong

By Liam Mitchell · Security lead · 8 min read

Remote worker securing a home-office laptop setup

Most breaches we respond to don't involve exotic hackers. They involve a password reused since 2019, a backup that never ran, and a patch everyone meant to install. The good news: the fixes are cheap and boring — which is exactly why they work.

Backups nobody tested

A backup you haven't restored from is a hope, not a backup. Test a full restore quarterly, keep one copy offline, and time the process — recovery speed is the number that matters.

Shared logins

One password for the whole team means you can't revoke one person's access without chaos. Give everyone their own account, turn on multi-factor authentication everywhere, and use a password manager.

Patches three months late

Attackers automate exploitation within days of a patch release. Enable automatic updates on workstations, and schedule server patching monthly — then actually keep the appointment.

No phishing muscle memory

Your staff are the firewall's front door. Short, regular simulations beat one long annual training every time. Celebrate the people who report suspicious mail; never punish them.

Wi-Fi and devices on trust

Separate guest Wi-Fi from business Wi-Fi, encrypt every laptop drive, and require a PIN or biometrics on every phone that touches company mail.

Where to start

Pick the two items above you winced at and fix them this month. Then book a proper security audit — an outside look finds the blind spots every team misses in its own setup.