Working From Home
7 min readBy ARK Computer Repair technicians

Protecting a small business from cyber attack

Small businesses are targeted precisely because they're small: valuable enough to extort, rarely defended well enough to make it difficult. Attackers don't pick you personally — automated tooling finds exposed and unpatched systems at scale.

The good news is that the defences that work are not exotic. A handful of unglamorous measures stops the overwhelming majority of what we actually see.

How attacks actually start

Nearly every incident we deal with begins in one of a few ways.

  • A convincing phishing email that harvests an email password
  • A reused password exposed in someone else's data breach
  • An unpatched machine or remote access tool exposed to the internet
  • A malicious attachment or download opened by a member of staff
  • An invoice fraud email sent from a genuinely compromised supplier mailbox

The measures that matter most

In rough order of protection gained per pound and hour spent.

  • Multi-factor authentication on email, banking and remote access — the single highest-value control there is
  • A password manager, so passwords are unique and nobody reuses one across accounts
  • Patching operating systems and applications promptly, automatically where possible
  • Managed antivirus that is licensed and monitored, not installed and forgotten
  • Off-site, encrypted backup with version history, tested by actually restoring something
  • Least privilege: staff work from standard accounts, not administrator accounts

Email fraud deserves its own paragraph

Invoice redirection fraud costs UK small businesses far more than ransomware does. It works by compromising a mailbox — yours or a supplier's — watching for a genuine invoice, and sending a near-identical follow-up with different bank details.

The defence is procedural, not technical: verify any change of bank details by phoning a number you already had on file, never one from the email. Make that a rule for everyone who pays invoices, and enforce it even when the request appears to come from a director.

Staff awareness, without the annual video

Long compliance training is largely forgotten. What works better is a short, specific set of rules everyone actually knows: verify bank detail changes by phone, never approve an MFA prompt you didn't trigger, report suspicious emails without fear of looking silly, and never install software because a web page said to.

Make reporting blameless. Most breaches are made worse by the hour or two someone spends hoping they got away with it.

Assume something will get through

Prevention is never complete, so judge your setup by how bad the worst day would be. Could you restore every machine? How long would it take? Would you know which data had been accessed?

That is why backup, monitoring and logging matter as much as antivirus. They are what turn a catastrophe into an expensive inconvenience.

Where ARK Care fits

ARK Care Pro covers the technical half of the list above on every device: EDR, DNS filtering, patching, monitoring and 500GB of monitored UK backup, with a monthly report so you can see it's actually working. The procedural half — MFA, password hygiene, invoice verification — is yours, and we'll happily help you set it up.

More from the advice centre