Insights

5 security mistakes almost every small business makes

Most small-business breaches are not sophisticated. They exploit the same five gaps, year after year. Check yourself against this list — it takes two minutes.

1. Shared passwords, no 2FA

One spreadsheet of passwords, shared over WhatsApp, reused across services. When one account leaks — and statistically, one already has — everything falls. Fix: a password manager for the team and two-factor authentication on email, banking and admin panels. One afternoon of setup.

2. The forgotten WordPress plugin

Websites built years ago and never updated are the most common entry point we see. Outdated plugins have public, automated exploits. Fix: monthly updates, or a static/modern rebuild that removes the problem entirely.

3. Email that anyone can spoof

Without SPF, DKIM and DMARC records, criminals can send emails that look exactly like yours — to your customers, asking for payments. Most businesses have never heard of these three records. Fix: they are free DNS entries; setting them up takes under an hour.

4. Ex-employees who still have access

The developer who left last year still has the hosting password. The intern still has admin on Instagram. Fix: an offboarding checklist — accounts removed the same day someone leaves.

5. Backups that were never tested

Having backups is not the goal; restoring from them is. Ransomware groups specifically target backups first. Fix: automatic backups to a separate location, and one actual test restore every quarter.

None of these fixes require enterprise budgets. If you want a professional to check all five for you, our security audit does exactly that — and our free scan at karleesh.com/tools/security-scan checks your website's headers right now.

Free download

Website Security Checklist (PDF)

25 practical checks every business website should pass — from our security team.

← All articles