Tuesday, August 25, 2026 Practical tech, cyber-safety and money guidance for India
Cyber Awareness

Small-Business Cybersecurity in India: A Minimum Viable Security Plan

Mahesh·April 1, 2026

A small business does not need an enterprise security stack on day one. It does need a minimum set of controls that make common attacks harder and recovery possible. This plan is designed for small Indian teams using cloud email, laptops, phones, UPI/net banking and common SaaS tools.

1. Know what you are protecting

Create a one-page inventory: employee devices, email accounts, cloud drives, website/admin accounts, banking/payment access, customer data and the services that would stop the business if unavailable. Assign an owner to each critical system.

2. Secure email before anything else

Email is the reset key for many other accounts. Require MFA, disable dormant accounts quickly, use separate admin accounts where possible and review forwarding rules after any suspected compromise. Train staff to treat requests to change bank details or payment instructions as verification events, not ordinary email.

3. Patch devices and remove local-admin habits

Turn on automatic security updates for supported operating systems, browsers and productivity software. Employees should not use administrator privileges for routine browsing and email. Replace unsupported operating systems rather than trying to “secure” software that no longer receives fixes.

4. Use password managers and stronger MFA

Every important service should have a unique password. For email, cloud admin and finance accounts, prefer passkeys or FIDO security keys when the service supports them. SMS MFA is better than no MFA, but it is not the strongest option for high-value accounts.

5. Back up for recovery, not just storage

Maintain more than one copy of critical data and keep at least one copy isolated from ordinary user accounts. Test a restore. If ransomware can encrypt the backup using the same credentials as the laptop, the backup is not giving you enough separation.

6. Control payments

Use maker-checker or second-person approval for meaningful transfers when possible. Never change a vendor’s bank details solely from an email. Verify through a known phone number or another independent channel.

7. Write a two-page incident plan

List who can disable accounts, contact the bank, isolate devices, speak to customers and preserve evidence. Include external contacts: IT provider, hosting company, legal/privacy adviser where relevant and cybercrime reporting channels. The plan should work even if the main email account is unavailable.

8. Review access every quarter

Remove former staff, stale contractors, unused API keys and unnecessary administrator rights. Review shared inboxes and cloud-sharing links. Security improves as much by removing old access as by buying new tools.

A practical 30-day rollout

  • Week 1: inventory + MFA on email/admin/finance.
  • Week 2: patching + password manager + remove unused accounts.
  • Week 3: backup and restore test.
  • Week 4: payment-verification rule + phishing drill + incident contact sheet.

Sources and further guidance

This is a baseline, not a compliance certification. Businesses handling regulated, sensitive or high-volume personal/financial data should obtain professional advice appropriate to their obligations.

Editorial basis

This guide is written as a defensive, India-focused response guide. It does not claim a personal incident unless that experience is documented, and it does not guarantee recovery after fraud. Official reporting and payment/identity sources take priority over anecdotes.

Check before you act.

Product features, prices, security guidance and financial rules can change. For important decisions, use the linked primary or official source and confirm that the information is still current.

Read our editorial & corrections policy →