Protecting a small business from cyber attack
Small businesses are targeted precisely because they're small: valuable enough to extort, rarely defended well enough to make it difficult. Attackers don't pick you personally — automated tooling finds exposed and unpatched systems at scale.
The good news is that the defences that work are not exotic. A handful of unglamorous measures stops the overwhelming majority of what we actually see.
How attacks actually start
Nearly every incident we deal with begins in one of a few ways.
- A convincing phishing email that harvests an email password
- A reused password exposed in someone else's data breach
- An unpatched machine or remote access tool exposed to the internet
- A malicious attachment or download opened by a member of staff
- An invoice fraud email sent from a genuinely compromised supplier mailbox
The measures that matter most
In rough order of protection gained per pound and hour spent.
- Multi-factor authentication on email, banking and remote access — the single highest-value control there is
- A password manager, so passwords are unique and nobody reuses one across accounts
- Patching operating systems and applications promptly, automatically where possible
- Managed antivirus that is licensed and monitored, not installed and forgotten
- Off-site, encrypted backup with version history, tested by actually restoring something
- Least privilege: staff work from standard accounts, not administrator accounts
Email fraud deserves its own paragraph
Invoice redirection fraud costs UK small businesses far more than ransomware does. It works by compromising a mailbox — yours or a supplier's — watching for a genuine invoice, and sending a near-identical follow-up with different bank details.
The defence is procedural, not technical: verify any change of bank details by phoning a number you already had on file, never one from the email. Make that a rule for everyone who pays invoices, and enforce it even when the request appears to come from a director.
Staff awareness, without the annual video
Long compliance training is largely forgotten. What works better is a short, specific set of rules everyone actually knows: verify bank detail changes by phone, never approve an MFA prompt you didn't trigger, report suspicious emails without fear of looking silly, and never install software because a web page said to.
Make reporting blameless. Most breaches are made worse by the hour or two someone spends hoping they got away with it.
Assume something will get through
Prevention is never complete, so judge your setup by how bad the worst day would be. Could you restore every machine? How long would it take? Would you know which data had been accessed?
That is why backup, monitoring and logging matter as much as antivirus. They are what turn a catastrophe into an expensive inconvenience.
Where ARK Care fits
ARK Care Pro covers the technical half of the list above on every device: EDR, DNS filtering, patching, monitoring and 500GB of monitored UK backup, with a monthly report so you can see it's actually working. The procedural half — MFA, password hygiene, invoice verification — is yours, and we'll happily help you set it up.