Skip to main content
Security & Privacy

Locking down your online business in the next 30 days

Three real breach stories and the week-by-week plan that would have stopped each one, from password managers to a tested incident response plan.

Tom ran a digital marketing agency managing social media for 200 clients. One phishing email fooled a single employee into entering their password on a fake login page. Within hours, criminals had access to every client account the agency managed. They posted inappropriate content, sent spam, and Tom lost 40% of his clients within a month. He spent $75,000 on legal fees and crisis management, and sold the agency two years later because it never fully recovered.

None of this required a sophisticated attacker. It required one employee, one convincing email, and no second factor standing between a stolen password and the accounts it opened. That's the pattern across most small-business breaches: the technique is ordinary, and the business hadn't done the one boring thing that would have stopped it.

Small businesses absorb a disproportionate share of attacks for a mundane reason: they hold real customer and payment data behind consumer-grade defenses, because security got deprioritized while the business was busy growing. The fix doesn't require a security budget most solo operators don't have. It requires doing a specific, ordered set of things, in order, over about a month.

The 30-day plan, and what it would have stopped

Online Business Security Best Practices structures its recommendations as a month-long implementation plan rather than a reading list, and the ordering matters as much as the content: each week closes the gap that the previous breach stories exploited.

Week one is account security: sign up for a business password manager, migrate your financial, email, and admin credentials into it first, and turn on two-factor authentication for every critical account, using an authenticator app rather than SMS. This single week would have stopped Tom's breach outright: a second factor means a stolen password alone doesn't open the account. It's also the week most businesses skip, because it feels like the least urgent one until the day it isn't.

Week two moves to the website and email layer: verify your SSL certificate is actually installed, update every plugin and piece of website software to its current version, and turn on enhanced spam and phishing filtering in your email provider. Maria, who ran a fifteen-employee clothing business, lost control of her site to ransomware that encrypted her product photos, orders, and inventory. She had backups: three weeks old. That gap points straight at week three.

Week three is backup and training: automated backups following the 3-2-1 pattern (three copies, two media types, one off-site), a test restoration to confirm the backups actually work, and a short team session covering phishing identification and a simple process for reporting anything suspicious. Maria's outdated backups cost her two weeks of sales data and $30,000 in emergency IT help: money a tested, current backup would have made unnecessary.

Week four is monitoring: install free website monitoring that alerts you to downtime or malware, set a Google Alert for your business name as an early warning system, and (the step almost everyone skips) write an actual incident response plan. Lisa's productivity software company had a security flaw in its customer portal exposed 10,000 users' data, including financial information. The response cost $150,000 in fines plus $200,000 in security improvements, and three enterprise clients cancelled. A written plan doesn't prevent a breach, but it's the difference between a coordinated response in the first hour and a scramble in the third day.

None of these four weeks requires specialized technical skill. The plan works because it's sequenced to close the gap each real breach exploited, not because any single step is sophisticated.

Where people go wrong

The most common mistake is treating security software as a substitute for account hygiene. A firewall and antivirus subscription feel like "doing security," but the businesses in this chapter weren't beaten by malware getting through a firewall: they were beaten by a password that worked everywhere, or a role that never got revoked. Software protects against a different threat than the one that actually lands.

The second is skipping the offboarding step. When someone leaves (an employee, a contractor, a freelancer who finished a project), their access needs to be disabled the day they leave, not whenever someone remembers. Old permissions accumulate quietly, and each one is a door nobody's watching.

The third is running the 30-day plan once and calling it done. Security drifts: new apps get connected, new team members get added, old integrations keep permissions nobody remembers granting. The book's own answer is a recurring 30-minute monthly review and a quarterly team refresher: short enough that it actually happens, unlike the annual audit that gets postponed every year it's scheduled. The account and backup fundamentals in weeks one and three overlap heavily with the personal version of this problem, covered in the full digital safety guide.

What's in the kit

Inside Online Business Security Best Practices

Going deeper

  • AudioCyber-Safe Business
  • BookOnline Business Security Best Practices
  • ChecklistOnline Business Cybersecurity Implementation
  • GuideBusiness Password & Access Protection Plan
  • GuideData Backup Strategy for Online Businesses
  • Listicle21 Free Security Upgrades to Protect Your Online Business
  • Listicle7 Digital Security Blind Spots That Could Destroy Your Business
  • Mini-CourseSafeguard Your Online Business in 7 Days
  • Prompt PackProtect Your Online Business
See the full kit: $9

Online Business Security Best Practices is one of 5 bundles in The Digital Safety Pack, or take the whole pack for $29.