Cybersecurity is often treated as a technology problem, but technology is only part of the equation. For many businesses, the biggest risks come from basic security practices that have been missed, delayed or applied inconsistently.
Here are six easy improvements you can make this week to reduce cyber risk.
1. Turn on multi-factor authentication
If you haven’t enabled multi-factor authentication (MFA), it should be your top priority. MFA requires users to verify their identity in more than one way before gaining access to an account or resource. In practical terms, this means providing something besides a password or PIN. Typically, that’s a code sent to them via SMS or an authentication app, a security key, or biometric identification like a fingerprint or face scan.
With MFA in place, if an attacker steals or guesses a password, it usually isn’t enough to access an account. The attacker would also need to get past the second verification step.
Enable MFA first for:
- Microsoft 365 or Google Workspace
- Banking and payroll applications
- Cloud storage
- VPN access
- Business-critical applications
Most platforms offer MFA at no extra cost. Turning it on closes one of the easiest gaps attackers can exploit.
2. Remove accounts not in use
Accounts belonging to former employees, temporary contractors and vendors you no longer work with can remain active long after they’re needed. Because these accounts are often overlooked, they can offer attackers an easier way into your systems.
Review your user accounts and ask:
- Does this person still work with us?
- Does this account still serve a business purpose?
- Does the account need the level of access it has?
If the answer to any of these questions is no, adjust permissions or remove the account.
3. Stop giving everyone administrator access
Administrator accounts have broad control over your systems. They can install software, change settings and disable security protections, making them especially valuable to attackers.
Take stock of access across your business and ask:
- Does this person need to be an admin to do their job?
- Are there account levels better suited for their function within the tool?
- Is administrative access appropriate for the accounts that currently have it?
Remove administrator privileges where they’re not required. Giving people only the access they need helps limit the impact of a compromised account.
4. Turn on automatic updates
Attackers often target software with known vulnerabilities. Updates help close those gaps.
Check that automatic updates are enabled for:
- Windows and macOS
- Phones and tablets
- Web browsers
- Microsoft Office
- Antivirus software
- Key business applications
Keeping systems up to date closes known gaps before attackers can exploit them.
5. Start using a password manager
A password manager helps users:
- Create strong passwords
- Store them securely
- Avoid password reuse
- Share credentials safely when needed
The fewer passwords employees have to remember, the less likely they are to reuse weak ones.
6. Confirm your backups work
Having backups isn’t enough. You need to know you can restore your data when something goes wrong.
Check your backups and ask:
- When did our last successful backup run?
- Has anyone tested a restore recently?
- How long would recovery take?
A backup protects your business only if it works when you need it.
Small changes can make a big difference
The six steps discussed in this article reduce common risks without adding cost.
What matters is putting them into practice and keeping them in place. We can help you turn these recommendations into a focused action plan that fits your team, systems and risk level.