PreyTech
Menu

You Don't Need an Enterprise Security Budget — You Need These 3 Things

Small businesses may think they’re not a target, but in practice, they’re the ones missing three basic practices. Here’s what actually matters, in order.

1. A password manager (not a sticky note)

If your team reuses passwords across multiple logins — or writes them on a sticky note, or keeps them in a spreadsheet named “passwords” — one leaked account becomes every account.

Start using a password manager, something like 1Password, where each user has their own MFA/biometric account to store their personal passwords but passwords crucial to operations can be shared from a central vault. This cuts down on onboarding and the hassle of changing passwords when you offboard staff. You do change passwords when staff departs, right?

2. MFA on everything that matters

Multi-factor authentication (MFA) means a stolen password alone isn’t enough to get into your accounts — the attacker also needs your phone, a code, or a hardware key (the second factor).

You don’t need to turn on MFA for every tool you’ve ever signed up for. Start with accounts that would hurt if compromised: email, banking, domain registrar, cloud provider, and anywhere with customer data.

It may be tempting to use email for MFA, if someone gets into your email, they now own that account and can reset passwords everywhere at will. Using MFA on email accounts is non-negotiable, SMS is better than not having MFA but a hardware key like YubiKey is how the pros secure their accounts.

3. Backups that are test restored

Everyone thinks they have backups until it’s time to restore from them.

A failed hard drive or accidentally deleting a folder are recoverable problems if you can successfully restore from your backup. If you can’t, it could cost you your business.

Pick a schedule, automate it so it doesn’t depend on someone remembering, and once a month, actually restore a file from it to confirm it works. Your backup schedule is dictated by your tolerance to data loss and time it takes to be back online (RPO and RTO). Taking full backups once a week and daily incremental backups ensures you aren’t overpaying while allowing you to quickly get back up and running losing only a small amount of data - typically less than 24 hours.

That’s a big chunk of your risk, handled

None of this requires a security team, a compliance framework, or a big budget. A password manager, MFA on what matters, and backups you trust — that’s the foundation. Everything past this point (network segmentation, formal incident response plans, security awareness training programs) matters more as you grow, but it’s not where the risk is concentrated for most small businesses today.

Start here. The expensive stuff can wait.

What’s the one security thing you’ve been putting off? If you’re not sure where to start, book 30 minutes with me — this is exactly the kind of thing I help small businesses sort out.