Most small business breaches are not sophisticated. They come through a reused password, an unpatched plugin, or a convincing email that someone clicked on a busy Monday. That is good news: it means most of the risk is closed with habits, not a security team.

The habits that cover most of it

  • A password manager and two-factor authentication on every account that touches money, customer data, or your website. This one habit closes the most common entry point by itself.
  • Updates on a schedule, not "whenever someone notices." Set a recurring calendar reminder if nothing else. Most exploited vulnerabilities were already patched months before they were used against someone who had not updated.
  • Backups that are tested, not just taken. A backup nobody has ever restored from is a guess, not a safety net. Test it once, then on a schedule.
  • A short, current list of who has admin access to what, reviewed when someone leaves. Former employees and contractors with live access is a common, avoidable gap.
  • Basic phishing awareness for anyone who checks email on behalf of the business. Most people can spot a bad email once they know what to look for; almost nobody is taught what to look for.

What to do in the first hour if something looks wrong

Change the passwords on anything that might be affected, starting with email (it is usually the key to everything else). Turn on two-factor authentication if it was not already on. Tell the people who need to know before you have every answer; a fast, honest heads-up beats a polished explanation three days late. Then find out what actually happened, so the same gap does not open twice.

None of this requires a big budget. It requires deciding it matters enough to schedule, which is exactly what a Care Plan retainer is built to do: updates, monitoring, and a monthly check-in, without you having to remember to ask for it.