Quantum Technologies — AI in a Box
SecurityOctober 5, 2026Nathan Drager2 min read

Cyber Hygiene for Small Businesses: The Ten Habits That Matter

Most small-business breaches don't involve a brilliant hacker. They come through a gap one of these ten habits would have closed.

Person wiping computer screen from virus and malware icons to security icons with a cleaning spray bottle nearby

"Cyber hygiene" sounds like jargon. It just means the routine habits that keep a business from being an easy target, the way locking the doors and checking the smoke detectors keep a building safe. Most small-business breaches don't involve a brilliant hacker. They come through a gap one of these habits would have closed.

Verizon's 2025 breach report found that stolen or abused passwords were the most common way in, at 22% of breaches, followed by unpatched software at 20% and phishing at 16%. The habits below are aimed squarely at those three.

The ten habits, in the order we'd tackle them

  • 1. Turn on multi-factor sign-in for email, remote access and every admin account. It stops most attacks that use a stolen password.
  • 2. Use a password manager, and give every account its own long password. Reused passwords are how one breach becomes five.
  • 3. Install updates automatically, and check that they actually installed. That includes Windows, browsers, firewalls and the software your business runs on.
  • 4. Protect every computer with endpoint detection and response, and make sure someone watches the alerts. Antivirus alone is not enough anymore.
  • 5. Back up the data that matters, keep a copy that ransomware can't reach, and test a restore every quarter.
  • 6. Give people only the access their job needs. Everyday accounts shouldn't have admin rights.
  • 7. Turn off access the day someone leaves: email, files, apps and shared passwords.
  • 8. Train the team with short, real examples a few times a year, and make reporting a suspicious email easy.
  • 9. Set up SPF, DKIM and DMARC on your email domain, so nobody can send email that looks like it came from you.
  • 10. Write a one-page plan for what happens when something goes wrong, and who calls whom.

The risks that don't show on the surface

The risk that worries me most isn't the hacker you can't see. It's the former employee whose account still works. The things that hurt small businesses most are rarely visible day to day:

  • A former employee whose account still works.
  • A router or server that stopped getting updates years ago.
  • A backup that has never been restored.
  • A shared password that half the office knows.
  • A vendor with remote access to your network that nobody remembers granting.

None of these cause a problem until the day they cause a big one. A yearly review that looks for them is the cheapest security work there is.

Start this week

If I could turn on one thing for every business in Door County, it would be multi-factor sign-in. If you do only three things, turn on multi-factor sign-in everywhere, confirm your updates are installing, and test a backup restore. Then work down the list. To see where you stand now, our free IT security scorecard covers the same ground in about two minutes.

Not sure where your business stands on this?

We’ll walk through how you handle it today and tell you straight whether it needs attention.

SecurityBusiness Technology

Let's talk about your technology.

A quick conversation about where you are, what's not working, and whether we're the right fit. No pressure, no jargon.

No obligation. No sales pressure. Just an honest conversation.

CallSchedule a Call