A small business does not need an enterprise security stack on day one. It does need a minimum set of controls that make common attacks harder and recovery possible. This plan is designed for small Indian teams using cloud email, laptops, phones, UPI/net banking and common SaaS tools.
1. Know what you are protecting
Create a one-page inventory: employee devices, email accounts, cloud drives, website/admin accounts, banking/payment access, customer data and the services that would stop the business if unavailable. Assign an owner to each critical system.
2. Secure email before anything else
Email is the reset key for many other accounts. Require MFA, disable dormant accounts quickly, use separate admin accounts where possible and review forwarding rules after any suspected compromise. Train staff to treat requests to change bank details or payment instructions as verification events, not ordinary email.
3. Patch devices and remove local-admin habits
Turn on automatic security updates for supported operating systems, browsers and productivity software. Employees should not use administrator privileges for routine browsing and email. Replace unsupported operating systems rather than trying to “secure” software that no longer receives fixes.
4. Use password managers and stronger MFA
Every important service should have a unique password. For email, cloud admin and finance accounts, prefer passkeys or FIDO security keys when the service supports them. SMS MFA is better than no MFA, but it is not the strongest option for high-value accounts.
5. Back up for recovery, not just storage
Maintain more than one copy of critical data and keep at least one copy isolated from ordinary user accounts. Test a restore. If ransomware can encrypt the backup using the same credentials as the laptop, the backup is not giving you enough separation.
6. Control payments
Use maker-checker or second-person approval for meaningful transfers when possible. Never change a vendor’s bank details solely from an email. Verify through a known phone number or another independent channel.
7. Write a two-page incident plan
List who can disable accounts, contact the bank, isolate devices, speak to customers and preserve evidence. Include external contacts: IT provider, hosting company, legal/privacy adviser where relevant and cybercrime reporting channels. The plan should work even if the main email account is unavailable.
8. Review access every quarter
Remove former staff, stale contractors, unused API keys and unnecessary administrator rights. Review shared inboxes and cloud-sharing links. Security improves as much by removing old access as by buying new tools.
A practical 30-day rollout
- Week 1: inventory + MFA on email/admin/finance.
- Week 2: patching + password manager + remove unused accounts.
- Week 3: backup and restore test.
- Week 4: payment-verification rule + phishing drill + incident contact sheet.
Sources and further guidance
This is a baseline, not a compliance certification. Businesses handling regulated, sensitive or high-volume personal/financial data should obtain professional advice appropriate to their obligations.
Editorial basis
This guide is written as a defensive, India-focused response guide. It does not claim a personal incident unless that experience is documented, and it does not guarantee recovery after fraud. Official reporting and payment/identity sources take priority over anecdotes.
