The most common assumption small business owners make about security policies is that they’re an enterprise problem. Policies are for companies with IT departments, legal teams, and compliance budgets. A three-person operation doesn’t need any of that.
It’s a reasonable assumption. It’s also wrong, and it tends to be expensive to discover.
The Size Assumption Is the Vulnerability#
Attackers don’t sort their target lists by headcount. They sort them by ease. A three-person accounting firm with no written policies, shared passwords, and no offboarding process is considerably easier to compromise than a 200-person company that has those things locked down. Small businesses get targeted precisely because this assumption is so common.
The other one I hear is “we don’t have anything worth stealing.” If you have client data, payment information, or business email accounts (and most small businesses are running entirely on a couple of laptops and cloud services like Microsoft 365, Google Workspace, or QuickBooks Online), you absolutely have something worth stealing. Ransomware doesn’t care whether your revenue is $80,000 or $80 million. It just needs a foothold.
What “Policy” Actually Means for a Small Business#
I’m not talking about a 90-page document with appendices. For a two or three person operation running on laptops and cloud apps, a coherent security policy might be four pages. Here’s what it needs to cover and why each piece matters:
Who has access to what, and how access gets revoked when someone leaves. Former employees with active credentials are one of the most common entry points in small business breaches. If you don’t have a written process, offboarding becomes an afterthought, and that shared Microsoft 365 login or QuickBooks account stays active long after the person is gone.
How passwords are managed. Shared passwords written on sticky notes, texted between employees, or stored in a spreadsheet are a single point of failure. One lost laptop or one disgruntled employee and everything is exposed. A password manager solves this, works just as well for a two-person shop as a two-hundred-person company, and costs less per month than a cup of coffee.
What to do when something looks wrong. When an employee clicks a suspicious link, every minute of delay makes the damage worse. If there’s no written procedure, the natural response is to minimize it, hope it was nothing, and not say anything. That instinct is how a minor incident becomes a major one.
How data gets backed up, and how you verify it works. A lot of small businesses assume their cloud apps handle this automatically. Sometimes they do. Often the retention window is shorter than you think, the backup doesn’t cover everything you’d need to restore, or the “backup” is just syncing files that are already corrupted or encrypted. A policy that specifies what gets backed up, how often, and how you confirm it actually works is the difference between a ransomware incident being a bad week and being a business-ending event.
What devices can connect to business accounts. An employee checking work email on a personal phone that hasn’t had a software update in months is a risk. So is a contractor logging into your cloud apps from an unknown machine. You need a defined answer to who can connect and under what conditions, even if the answer is just “work laptops only, and they have to have the latest updates installed.”
That’s it. The goal isn’t a compliance binder. It’s making sure everyone in the business knows the rules, the rules actually reflect how you operate, and there’s a plan when something goes wrong. Something will eventually go wrong.
The businesses that recover cleanly from incidents are almost never the ones who got lucky. They’re the ones who had a plan.
The Honest Bottom Line#
Most small businesses don’t have a security problem because they were targeted by sophisticated attackers. They have a security problem because nobody ever sat down and thought through the basics. Written policies (even simple ones) force that conversation. They make the implicit explicit. They give you something to hand a new employee and something to point to when someone asks why you do things a certain way.
If you’re not sure where to start, or you want someone to look at what you have and tell you honestly whether it’s enough, that’s exactly what I do. Get in touch and we can talk through it.