Knowledge hub · Security basics
Security for a small business starts with four habits: inventory, updates, permissions and backups. None of them is a one-off task.
- 01
Know what you own
Domains, servers, admin panels, mailboxes and third-party services belong in one list. An asset that is not on the list gets neither updated nor monitored.
- 02
Updates and backups
Put updates on a schedule and test at least once a year that a backup can actually be restored. An untested backup is not a backup.
- 03
Permissions
Do not give everyone administrator rights; close a leaver's access the same day and use a second factor on admin accounts. Reviewing permissions once a year prevents most incidents.
- 04
If something happens
Write down in advance who is called, what gets shut off and how logs are preserved. In an incident, the most expensive thing is deciding on the spot.
- 05
Passwords and a second step
Turn on a second verification step for everyone who signs in to the panel; a stolen password is still the most exploited way in. Do not share accounts, give each person their own user so the audit log can tie an action to a person. Keep passwords in a password manager, never in a chat message or a spreadsheet.
- 06
Getting tested
A security test is only run with the owner's written permission and a written scope stating which addresses, on which dates and by which methods. A good report shows each finding with evidence, explains its impact and proposes a fix. A finding that is not retested after the fix does not count as closed.
- 07
Order of work for a small team
If time is short, work in this order: restore a backup once to prove it works, turn on the second step for administrators, close the access of people who have left, and put server and plugin updates on a calendar. These are cheap and effective. A detailed test makes sense after that; while the basics are missing, a test only repeats what you already know.
Related pages
Articles that complete this topic, plus the matching service page.
Let's talk about your project.
Tell us what you need; we will define the scope together.