Cyber security basics
Simplifying cyber security for small businesses
A basic guide to making cyber security approachable for a small business.

Cyber security matters to small businesses, but fear, jargon and worries about cost can make it feel harder than it is. You do not need a technology degree to improve your security. A useful place to start is the CIA triad.
Why cyber security feels overwhelming
- Fear. News coverage can make it sound as though every small business is under constant attack. Basic protections still make a meaningful difference.
- Technical language. Terms such as phishing and firewalls can get in the way of understanding the actual risk.
- Cost. Good security does not begin with an expensive product. It begins with knowing what matters and putting sensible controls around it.
Understanding the CIA triad
The CIA triad groups information security into three areas: confidentiality, integrity and availability.
1. Confidentiality
Confidentiality means keeping customer information, financial records and other private business data away from people who should not have access.
Start with these steps:
- Use a unique password for every account. A password manager makes this practical.
- Turn on two-factor authentication wherever it is available.
- Protect phones, laptops and other devices with a PIN, password or biometric lock.
2. Integrity
Integrity means knowing that your information is accurate and has not been changed, corrupted or deleted without permission.
Start with these steps:
- Back up important files to a separate, secure location.
- Treat unexpected email attachments and links with caution.
- Keep devices and software up to date.
3. Availability
Availability means being able to reach the information and systems your business needs when it needs them.
Start with these steps:
- Keep a backup internet option, such as a mobile hotspot, for critical work.
- Store essential files in a reliable system that authorised staff can reach.
- Test backups. A backup you cannot restore is not useful.
How to begin
Look at each part of your business through those three questions.
Assess confidentiality
Who can access customer data, financial records and business accounts? Remove access that is no longer needed, then add a password manager and two-factor authentication.
Check integrity
Could you tell if an important file was changed or lost? Keep reliable backups, update devices and help staff recognise phishing attempts.
Plan for availability
What stops if your internet, computer or cloud service is unavailable? Document a workaround for the systems that would cause the most disruption.
Cyber security is not about reaching perfection. It is about reducing avoidable risks and knowing how the business will recover when something goes wrong.