Cyber security

A 15 minute security check any small business can do for free

Seven checks, about fifteen minutes, no cost and no technical knowledge needed. Each one tells you something specific, and each has a clear sign that something needs fixing.

Most incidents at small businesses do not need a clever attacker. They need one account without a second factor, one person who left and kept their access, or one backup nobody had tried to restore. The seven checks below look for exactly those, and none of them costs anything.

Set aside fifteen minutes, open a notepad, and write down what you find. A bad result on any of them is worth fixing. Two or more is worth a phone call.

1. Has your work email address turned up in a data breach?

Put each work address through our email breach checker. It uses the Have I Been Pwned data and tells you which known breaches an address appears in and what leaked each time.

Bad looks like: a breach that included passwords, where the same password might still be in use anywhere. That is the one to act on today: change it everywhere it was used and turn multi factor authentication on. A breach that only leaked email addresses mostly means more phishing, which is worth warning that person about. What a breach result actually means goes into this properly.

2. Is multi factor authentication on for every account?

Ask whoever looks after your Microsoft 365 to show you, on screen, which accounts have multi factor authentication switched on. Start with anybody who has admin rights, then everybody else.

Bad looks like: any account without it, and especially any admin account without it. A password on its own is no longer enough to protect an email account, because passwords leak in exactly the way step 1 shows. Switching it on costs nothing, and it is the single most effective thing on this list.

3. How many people can change everything?

In the Microsoft 365 admin centre, look under Roles at who holds the Global Administrator role. Those accounts can do anything, including deleting every mailbox and every file.

Bad looks like: more than a handful of names, or names of people who only needed it once. Microsoft’s own guidance is to give the role to fewer than five people, every one of them protected by multi factor authentication. Day to day, people should work from an ordinary account and use the admin one only when they need it.

4. Has everybody who has left actually gone?

Open the list of active users in the Microsoft 365 admin centre and compare it with your current staff list. Then think about everything else people log into: the accounts package, the CRM, the bank, the shared password for the router.

Bad looks like: any active account belonging to somebody who has left. It is one of the things we find most often when we take over a business’s IT, and it is often years old. A leaver’s account is an account nobody is watching.

5. Is your antivirus actually switched on?

Follow the steps on our antivirus and web filter test on one work laptop. It uses the EICAR test file, which is harmless and which every security product is built to recognise. If somebody manages your IT, tell them first, because it may set off an alert.

Bad looks like: the file downloads and nothing happens. That means the protection on that machine is off or not scanning files as they arrive, and it is worth checking every other machine too.

6. When did anybody last restore something from backup?

Ask the question that way round. "Are we backed up?" nearly always gets a yes. "When did we last get a file back from the backup, and how long did it take?" tells you whether the backup works.

Bad looks like: nobody knows, or the answer is "we have never needed to". A backup that has never been tested is a hope. It is also worth asking whether the backup covers Microsoft 365, because many businesses assume Microsoft keeps a copy of everything for them, and it is not a backup in the sense most people mean.

7. What does your website and your email domain say about you?

Two quick checks from the outside.

Put your website address into our security headers checker. It shows which of six protective headers your site sends and how to add the missing ones. Whether they matter for a small business site is a fair question, and the honest answer is: some of them, and they are cheap to fix.

Then put your domain into a free DMARC lookup, such as MXToolbox’s. DMARC is the record that tells other email systems what to do with messages pretending to come from you.

Bad looks like: no DMARC record at all, or one set to p=none, which watches forgeries go past without stopping them. That is how somebody sends your customers an invoice from your own address with different bank details. What it takes to fix is mostly careful setup rather than cost.

What to do with what you found

If everything passed, write the date down and do it again in three months. These things drift.

If one failed, fix that one. Most of these are an afternoon’s work for whoever manages your IT.

If two or more failed, the gaps are probably connected, because they usually come from the same place: nobody has been asked to look. Several of these also appear on the Cyber Essentials checklist and on a typical cyber insurance schedule, so fixing them pays twice. Tell us what you found and we will tell you what to fix first, whether or not you ever become a client.

Questions

The questions people ask us about this

We passed all seven. Are we secure?

You are in better shape than most small businesses, and these seven cover the routes most attacks actually use. They do not tell you whether anybody is watching for the attack that gets through anyway, which is the part software on its own does not do.

Do we need to be technical to do this?

No. Four of the checks are a matter of asking the right question and writing the answer down. The other three use free tools that explain their results in plain English.

How often should we repeat it?

Every three months is a sensible rhythm, and after anybody leaves. The results drift: new staff, new accounts, a laptop that missed its updates. A check you did once last year tells you about last year.

Read next

Cyber security

Your email address is on the dark web. Does it matter?

Usually it means an old breach at some company you once had an account with, not that somebody is inside your systems today. What matters is whether the password that leaked is still in use anywhere, and whether multi-factor authentication would make it useless if it is.

Read this

Cyber security

Will your cyber insurance actually pay out?

Only if the things you told the insurer you were doing were actually happening on the day you got hit. Your policy schedule lists them: multi-factor authentication, patching, endpoint protection, training, an incident response plan. If one of them was not true, a claim can be refused outright rather than reduced.

Read this

All posts

Next step

Talk to Tom, not a call queue

Ring the number below and you get Tom, the owner. No hold music, and no ticket reference before anyone has heard the problem. If we’re not the right fit, we’ll tell you that too.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.