As you may have noticed, I have pivoted the focus of this newsletter.
I am now focusing on cybersecurity tips for individuals and small to medium enterprises.
I’ll focus on simple but impactful steps to help small businesses improve their security.
Why is this important?
Many small businesses change rapidly. This is what drives growth.
But much like the tech world in general, this means that security is often left behind.
Profit often comes at the expense of security, because its hard to justify spending on protection when growth feels more urgent.
You can lose a lot of money with this mindset!
This newsletter aims to fill that gap. Most content is free, and even paid pieces cost far less than hiring a dedicated security role.
The biggest challenge is awareness at leadership level. By reading this, you’re already ahead.
Today, let’s look at some of the easiest cybersecurity wins you can make without a big budget.
5 Cybersecurity Wins You Can Do Today
Number 1: Turn on Multi-Factor Authentication (MFA)
Your password can be stolen.
MFA adds a second lock.
Think of it like needing a key and a code to get in.
Start with email and banking
Email (SMEs):
If the business uses Google Workspace (Gmail) → Admins can enforce MFA for all users. This is done in the Admin Console → Security → Authentication → 2-Step Verification. Users then follow the same setup as individuals, but the policy ensures no one can skip it.
If the business uses Microsoft 365 (Outlook/Exchange) → MFA can be enforced via the Microsoft 365 Admin Center. Admins can create a policy requiring MFA for all users or specific groups.
If the business uses another provider → look for an “enforce MFA” or “two-factor” policy in the admin settings.
Bank (SMEs):
Most business bank accounts in the UK/EU already require MFA due to regulation (like PSD2), typically this is through:
The banks mobile app (approving login/transactions)
A hardware token or card reader
The main difference is that with business accounts, multiple authorised users may need their own MFA setup. The account administrator usually assigns roles and permissions, and each person has to register their MFA seperately.
For Individuals:
Email → Turn on 2FA in Gmail (Google Account → Security → 2-Step Verification) or Outlook (Security Info → Add sign-in method → Authenticator app).
Banking → Most banks already use MFA. Prefer app-based approvals or biometrics over SMS if offered.
Number 2: Keep Everything Updated
Why it matters:
Outdated software is one of the easiest ways for an attacker to get in.
For individuals:
Turn on auto updates for your laptop, phone, and apps.
Don’t ignore update notifications
For SMEs:
Enable auto-updates across company devices
If you have servers or specialist software, assign someone to check patching regularly
Consider a central tool (like Intune, Jamf, or similar) to make sure staff devices are patched.
Number 3: Use Strong, Unique Password
Why it matters:
Reused passwords are a gift to attackers.
For individuals:
Use a password manager (e.g 1Password, Bitwarden)
Let it generate random, unique passwords.
For SMEs:
Provide a password manager for staff.
Ban password reuse via policy.
Use admin settings in Google Workplace / Microsoft 365 to ensure minimum password length and complexity
Number 4: Back up Your Data
Why it matters:
Ransomware can destroy your only copy of important files
For individuals:
Turn on automatic cloud backups (Google Drive, iCloud, OneDrive)
Or use an external hard drive, unplugged after backup
For SMEs:
Use a business grade backup service (local + cloud)
Test recovery, don’t just assume backups work
Keep at least one offline backup (not connected to your network)
Number 5: Watch Out for Phishing
Why it matters:
Phishing is still the number one attack method.
Generative AI has changed the landscape.
For individuals:
Pause before clicking
Check sender addresses carefully
Hover over links to see where they really go
For SMEs:
Train staff with regular phishing awareness (short sessions work)
Use email filters (built into Gmail and Microsoft 365)
Report suspicious emails, create a clear process for this
Final Word
These 5 steps aren’t complicated.
They don’t require a big budget.
But they do put you ahead of most individuals and SMEs.
Start here. Build from here.
Security doesn’t have to be overwhelming.
Here are some helpful links if you want to read further into these topics:
U.S. Small Business Administration (SBA): Strengthen Your Cybersecurity
CISA (Cybersecurity & Infrastructure Security Agency): “More Than a Password” & MFA Toolkit
NIST (National Institute of Standards and Technology): MFA Guidance
Microsoft 365 Official MFA Setup
FTC (Federal Trade Commission): Cybersecurity Basics for SMEs
Wikipedia: NIST Cybersecurity Framework
Authors Note
I hope that you found this article interesting and useful. Please let me know what you think about this new format with some feedback in the comments below.
Looking forward to writing more about this soon.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.