All questions › Security Essentials
Security Essentials
What small businesses actually need for cybersecurity, without the scare tactics. 23 questions, answered in plain English.
- What cybersecurity does a small business actually need?The non-negotiables: MFA everywhere, managed endpoint protection, email filtering, patched systems, tested backups, and basic staff training. Most breaches exploit the absence of these basics, not exotic hacking.
- Why does my IT provider insist on multi-factor authentication (MFA)?Because stolen passwords are the #1 way businesses get breached, and MFA stops the vast majority of those attacks cold. The minor daily friction buys an outsized security win; there's no better trade in IT.
- What does cyber insurance require from our IT?Insurers now demand proof of specific controls (MFA, EDR, tested backups, patching) and can deny claims if your application overstated them. Your MSP should be able to complete the security questionnaire truthfully with you.
- I'm not comfortable with an MSP being able to remote into computers with private information. How is that access controlled?Legitimate MSP remote access is individually accountable, logged, and auditable: every session tied to a named technician with a record of when and what. You can also require on-screen consent prompts for attended machines. Demand these controls; good providers already have them.
- Do I really need antivirus? I only use my computer for business and never visit sketchy websites.Careful browsing stopped being protection years ago: attacks arrive through email attachments, compromised legitimate sites, poisoned ads, and stolen passwords. Business machines need modern endpoint protection (EDR) precisely because they are business machines; that is what attackers want.
- How should our team actually handle passwords? Everyone reuses the same few and shares them by text.A business password manager fixes this in one move: unique strong passwords for everything, shared vaults instead of texted logins, instant revocation when someone leaves, and one master password per person. It is cheap, and it eliminates the single most common way businesses get breached.
- If we get hit by ransomware, what actually happens next? Would we have to pay?The first hours are isolation and assessment: disconnect affected systems, determine spread, and check backups. Whether you even face the pay-or-not question is decided in advance by one thing: whether an immutable, tested backup exists. With one, recovery is restoration; without one, every option is bad.
- Some of our staff work from home. What does that mean for our security?Home workers extend your business onto networks and habits you do not control. The fixes are established: company-managed devices with EDR, MFA everywhere, encrypted access to business systems, and clear rules about family computers. Remote work is safe when the security travels with the laptop.
- Is security awareness training for employees actually worth it?Yes, with caveats. Most successful attacks on small businesses start with a person, not a firewall: a convincing email, a fake invoice, an urgent wire request. Short, regular training with simulated phishing measurably cuts how often people click. What it is not: a substitute for the technical protections.
- Our email was breached and our customers were contacted. Some lost money, and our reputation took a hit. How do we make sure this never happens again?What happened to you is called business email compromise, and it is one of the most common and costly attacks on small businesses. The fix is layers: MFA everywhere, a hardened business email platform, monitoring for suspicious activity, staff training, and verification procedures for anything involving money.
- I'm a small business. Hackers go after the big fish, so why would they bother with me?Because most attacks are not aimed at anyone. They are automated nets that sweep the whole ocean, and small businesses get caught more often precisely because they have fewer defenses. Attackers are not after your size; they are after your bank account, your email, and your customers' trust.
- What are the most common email attacks on small businesses? Give me the rundown.Five account for most of the damage: phishing for passwords, mailbox takeovers where attackers watch quietly and strike when money moves, lookalike domains slipped into real conversations, boss and vendor impersonation scams, and malicious attachments. Nearly all of them end at the same place: your money or your passwords.
- Windows 10 support ended, but our computers still work fine. What are we actually risking by keeping them?The machines keep working, but they stopped being defended. Every security hole found since support ended stays open on them permanently unless they are enrolled in paid updates, and attackers specifically scan for exactly these computers. The risk is not that they break. It is what they let in.
- What is a passkey, and is it really more secure than a texted code?A passkey replaces typed-in codes with your device itself: you sign in with the fingerprint, face, or PIN you already use, backed by cryptography. There is no code to phish, nothing for a SIM-swapper to steal, and it is usually faster than waiting for a text. It is one of the rare security upgrades that makes life easier.
- We got a request for a quote from a company we have never heard of. How do I tell if it is real?Fake RFQs are a real and growing scam that targets your sales inbox instead of your fears. The strongest tells are a reply that arrives from a different domain than the first message, a project with no actual details in it, and a document delivered as a one time download link.
- I opened a suspicious attachment but did not click any links or sign in to anything. Am I compromised?Almost certainly not. In these scams the attachment is only a wrapper, and the actual attack is the fake sign in page it tries to send you to. The question that decides whether you have a problem is narrow: did you type your email and password into anything?
- A scam email used the name of a real, well known company. Should we block that company's domain?Usually no. Scammers borrow the identity of real businesses on purpose, so the company being named is often an innocent third party. Block the specific sending address and any unrelated reply domain, not the impersonated brand's whole domain.
- Someone on our team entered their password into a fake login page. What do we do right now?Act quickly but calmly, and in this order: change that password, confirm multi-factor authentication, check for sneaky mailbox forwarding rules, and review recent sign in activity. The mailbox rule check is the step almost everyone forgets and the one attackers rely on.
- If we start checking out every new inquiry, won't we look paranoid and lose real customers?Not if you put the check in the right place. Verification belongs between the friendly reply and the free work, not in front of the reply itself. A real buyer hands over a business name, an address, and a working phone number without any friction, so the ten minutes it costs you is invisible on a genuine lead.
- Someone new wants to do business with us. What should we actually check before we spend time on them?Ask for the legal business name, a physical address, and a website. Then look the company up independently rather than through anything in their message, and call a phone number you found yourself. It takes about ten minutes and it works on fake customers, fake vendors, and most of whatever replaces them next year.
- A vendor emailed asking us to update their bank details before the next payment. How do we know it is really them?Treat every change to bank details as suspect by default, including one that arrives inside a real email thread from an address you recognize. Call the vendor on a number you already had on file, not one from the message, and confirm the change out loud with a person you know. That phone call is the whole defense.
- We went back and forth with a scammer a few times before we caught on. Nothing was clicked. What happens now?As long as nobody typed a password into a page from those messages, there is nothing to clean up. The real consequence of replying is that you have confirmed a live person reads that address, so expect more attempts, and expect the next one to reference the conversation you already had.
- Our staff have all had phishing training and one of them still nearly fell for a fake quote request. What went wrong?Probably nothing. Almost all phishing training is built around spotting bad news: a threat, a warning, an urgent invoice. A scam that arrives as good news, like a request for a quote, routes around every habit that training builds.
Want a straight answer about your setup?
Asheville Computer Company is a local managed IT provider based in Arden, minutes from most of Asheville.
Call (828) 290-9092 or visit ashevillecomputercompany.com for a free, no-pressure consultation.