Knowledge · AI at work · 9 minutes
Cybersecurity for small business: where to start in 12 steps
Small business cybersecurity step by step: 2FA, 3-2-1 backups, SPF and DMARC, payment checks, staff training, an incident plan and when NIS2 applies.
Last updated: October 6, 2026
Cybersecurity in a company: where to start?
Company cybersecurity is a set of simple rules and settings that protect the company's accounts, data and money from fraud, leaks and outages. In a small company you do not start by buying an expensive system, but by knowing what needs protecting.
The problem is large. According to CERT Polska's annual report for 2025, the Polish national CERT received 658,320 reports and registered 260,783 incidents, 152% more than a year earlier. 97% of them were computer fraud, and phishing, meaning attempts to steal logins and passwords, made up 30% of all incidents.
The first step takes an hour: list the company's accounts (email, bank, accounting, domain, website, social media), devices, places where customer data is kept, and suppliers with access to your systems. ENISA's guide for SMEs starts in the same place: assign someone to be responsible for security and give them time and budget.
How to protect a business from cyber attacks: steps 1-6
1. Owner and inventory. One person is responsible for the list of accounts, devices and suppliers and updates it whenever someone joins or leaves.
2. Accounts and two-step verification. Turn on a second login factor wherever possible, starting with email, banking and the domain panel. Introduce a password manager. ENISA recommends long passphrases made of several random words, never reused on other services. Details in two-step verification: what it is.
3. 3-2-1 backups. The US agency CISA describes the rule like this: three copies of important files (the original and two backups), on two different types of media, one kept off site. ENISA adds: backups should be automatic, separated from the everyday environment, encrypted and regularly tested with a full restore. Cloud sync is not a backup: a file deleted or encrypted by ransomware disappears there too.
4. Updates. Turn on automatic updates for operating systems, browsers, phones and website plugins. Note which devices need manual updates, such as the router, printer or cameras.
5. Permissions. Everyone gets access only to what they need. The administrator account is separate and is not used for daily work. When someone leaves, remove their access the same day and change shared passwords.
6. Email: SPF, DKIM, DMARC. These are three DNS records for your domain that make it harder to spoof your address. CERT Polska recommends rolling out DMARC gradually: start with a p=none policy and analyse the reports, then move to quarantine or reject. A domain you do not send email from should also have SPF "v=spf1 -all" and DMARC with p=reject. You can check for free whether your domain has these records.
How to protect company data: steps 7-12
7. Payment procedure. Confirm every change to a supplier's bank account by phone, using a number you already have, not one from the email. Check the new account against the official VAT register. Large transfers are approved by two people. More in fake invoices and bank account change fraud.
8. Devices. Disk encryption on laptops and phones, screen lock, and the ability to remotely wipe company data from a lost device. ENISA also recommends centrally managed antivirus and no pirated software.
9. Staff training. Short, regular, based on real examples from your industry. Details below.
10. Incident plan. One page: who decides, who to call, what to disconnect, where to report. We cover it in a separate section.
11. Suppliers, SaaS and AI tools. List who has access to your data and systems and check the contracts. When a supplier processes personal data on your behalf, you need a data processing agreement under Article 28 GDPR. AI tools are suppliers too: set the rules in your company AI use policy.
12. Website and domain. Keep track of the domain renewal date and keep the website and its plugins updated. CERT Polska runs a free portal, moje.cert.pl, where a company can, among other things, have its domains scanned with the Artemis tool. You can also check your company website passively, like an ordinary visitor: encryption, headers, cookies, third-party services and email protection.
Cybersecurity training for employees
ENISA's guide for SMEs recommends regular awareness training for all employees, tailored to small businesses and based on real situations, plus specialised training for whoever is responsible for security.
Good training for a small company takes an hour and covers: how to spot phishing and fake invoices, what to do with a suspicious email or text, how two-step verification and a password manager work, what not to paste into AI tools, how to recognise someone impersonating the boss by phone or video, and who to report problems to. For phishing examples, see phishing: what it is and how to spot it.
The most important rule: reporting a mistake is never a reason for punishment. An employee who clicked and told you right away gives you minutes to react. One who is afraid gives you days.
Repeat the training at least once a year and after every incident. Keep a record of who attended. In companies covered by NIS2, the head of the organisation must complete training every year, and attendance has to be documented.
What to do when an incident happens
An incident plan fits on one sheet of paper and hangs where everyone can find it. ENISA recommends a formal plan with defined roles and responsibilities. The minimum for a small company:
1. Who decides and who has the phone number of your IT person or support company. 2. What to disconnect from the network (an infected computer) and what not to switch off or delete (evidence). 3. Backups: where they are and who can restore them. 4. The bank's phone number for payment fraud. Reporting quickly gives a chance to stop the money. 5. In Poland, report to CERT Polska at incydent.cert.pl, forward suspicious texts to 8080 and report crimes to the police. 6. If personal data leaked: Article 33 GDPR requires notifying the data protection authority within 72 hours of becoming aware of the breach, unless it is unlikely to pose a risk to people.
After the incident, change passwords, check email forwarding rules and write down what worked and what did not.
When does NIS2 apply to a company?
In Poland, NIS2 was implemented by an amendment to the National Cybersecurity System Act (Journal of Laws 2026, item 252), in force since 3 April 2026. It mainly covers medium and large companies in the sectors listed in the act's annexes, such as energy, transport, healthcare, digital infrastructure, manufacturing and food.
A medium-sized company is, roughly, one with at least 50 employees or annual turnover and balance sheet total above 10 million euro. Micro and small companies are usually not covered directly, unless they operate in an area covered regardless of size, such as DNS services. They often end up in the supply chain of a covered customer, though, and receive security requirements in their contracts.
Covered companies need a security management system, must send an early warning about a serious incident within 24 hours of detecting it, and their managers must complete cybersecurity training once a year. Details in NIS2: who it applies to.
In short
- Start with an inventory of accounts, devices, data and suppliers, and one person responsible.
- Two-step verification, 3-2-1 backups with a restore test and automatic updates give the most protection for the least cost.
- A procedure for confirming bank account changes protects against the most expensive type of fraud in small companies.
- Training should be short, regular and based on real examples, and reporting a mistake must never lead to punishment.
- NIS2 mainly covers medium and large companies in specific sectors, but smaller companies receive requirements from their customers.
Have a website, app or email address that looks suspicious?
Frequently asked questions
Where should a small business start with cybersecurity?
With an inventory of accounts, devices, data and suppliers, and by naming a responsible person. Then two-step verification on email and banking, and backups with a restore test.
Does a small business have to comply with NIS2?
Usually not directly. The Polish implementing act mainly covers medium and large companies in listed sectors, but a customer covered by NIS2 can require specific safeguards from you in a contract.
Where do I report a security incident in Poland?
To CERT Polska at incydent.cert.pl, suspicious texts to 8080, crimes to the police, and payment fraud immediately to your bank. A personal data breach goes to the data protection authority within 72 hours.
How often should employees get cybersecurity training?
At least once a year, when they join and after every incident. Short reminders with current examples work better than one long session.
Are files in the cloud a backup?
Sync is not a backup. If a file is deleted or encrypted by ransomware, the change reaches the cloud too. A backup has to be separate and regularly tested.
Are there free tools to check a company's security?
Yes. CERT Polska offers a free portal, moje.cert.pl, with domain scanning, and with arLET'S you can passively check your company website and domain, including SPF and DMARC, for free.
Sources
- ENISA: Cybersecurity guide for SMEs, 12 steps to securing your business (28 June 2021)
- CERT Polska: Polish internet security landscape in 2025 (annual report, in Polish)
- CERT Polska: Email sender verification mechanisms (SPF, DKIM, DMARC), 28 October 2021
- CISA: Data Backup Options (3-2-1 rule)
- CERT Polska: moje.cert.pl, free tools for organisations
- CERT Polska: Report an incident
- Polish act of 23 January 2026 amending the National Cybersecurity System Act (Journal of Laws 2026, item 252)
- Regulation (EU) 2016/679 (GDPR), Articles 28 and 33
Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.
See also
- NIS2: who it applies to and how to comply in Poland in 2026
- Fake invoices and bank account change emails: how to check
- Two-factor authentication (2FA): what it is and how to use it
- How to implement AI in your business safely: step by step
- AI hallucinations: what they are and can you trust ChatGPT?
- AI use policy for companies: template and what it must cover