Security in small businesses
Back to Blog
IT security for small businesses: answers to the 10 most common questions
If you run a small business, you probably don't have your own security department or dedicated resources. You might have an IT provider, some cloud services, and a feeling that "we should do more", without really knowing what. This guide gives you simple, practical answers to the questions we are most frequently asked about information security, data security, and privacy in small businesses.
You don't have to do everything at once. The point is to start with what matters most and build on that at your own pace.
1. Where should we begin with IT security?
Start with three things that deliver high impact for low effort:
Turn on multi-factor authentication on all key services.
Ensure secure backups of data you cannot do without, and test that it can actually be restored.
Get an overview: Which systems do you use, what information do you hold, and who has access?
Once this is in place, the next step is a simple risk assessment. This means sitting down and asking: What is the worst that could happen to us, and what are we doing to prevent it? A risk assessment does not need to be a massive document. For a small business, a table showing the key threats and measures is often enough.
2. Aren't we too small to be targeted?
No. Most cyber attacks on small businesses are not targeted specifically at you. They are automated and hit anyone with a vulnerability: a reused password, an employee clicking the wrong link, or an email account without multi-factor authentication.
In fact, small businesses are often an easier target than large ones because they have fewer security measures in place. The most common cyber attacks against small businesses are:
Phishing: fake emails designed to trick employees into giving away passwords.
Invoice fraud: scammers pretending to be a supplier or managing director requesting payment to a new account number.
Ransomware: malware that locks your files and demands payment to unlock them again.
The question is therefore not whether you are interesting enough, but whether you are easy enough to trick.
3. Which information security requirements apply to the business?
For most small businesses, the General Data Protection Regulation (GDPR) is the most important piece of legislation. If you process personal data about customers, employees, or others, you must have an appropriate level of security and be able to demonstrate what you are doing. This applies regardless of your business size.
Many also ask about cyber security laws and NIS2. What applies today is the Norwegian Digital Security Act (Act 2023-12-20-108), which entered into force on 1 October 2025. It is based on the EU's original NIS Directive and applies to providers of essential and digital services in Norway. The newer NIS2 Directive extends the requirements to far more organizations, but the directive must first be incorporated into the EEA Agreement, and as of June 2026, a final entry into force date in Norway has not been set. Check nsm.no for current status.
Does NIS2 apply to my business? Most likely not directly, if you are a small business outside the designated sectors. However, you could be affected indirectly: Large clients who are covered themselves must follow up on their suppliers, and will ask you questions about your security.
A useful starting point in any case is NSM's fundamental principles for ICT security. These are free recommendations from the Norwegian National Security Authority that serve as a practical checklist, even for small businesses.
4. What do we need to have in place for GDPR?
In practice, GDPR for small businesses involves a few specific actions:
Privacy policy: a clear explanation to customers and others about what information you collect, why, and how long you store it.
Record of processing activities: an overview of what personal data you process and for what purpose. Most businesses should have one, although some small organizations are partially exempt.
Data processing agreements: contracts with suppliers who process personal data on your behalf, such as accounting systems, CRM, payroll systems, or cloud services.
Breach management procedure: If personal data is compromised, you must as a rule report the breach to the Norwegian Data Protection Authority (Datatilsynet) within 72 hours.
Access control: Only those who need the data should have access to it.
A GDPR checklist covering these points covers most bases for a typical small business. Datatilsynet offers helpful guides and templates at datatilsynet.no.
5. How much does IT security cost, and how much time does it take?
Less than many think. The most critical basic measures, such as multi-factor authentication, updates, backups, and training, cost little to nothing beyond time. Often, these features are already included in the tools you already pay for.
The main cost is actually the time it takes to get started and maintain it. For a small business, a realistic goal is:
a couple of days to get the foundation in place,
followed by a few hours a month for maintenance.
Compared to the cost of ransomware, a paid fraudulent invoice, or a lost contract because you couldn't answer a client's security questionnaire, it is a sound investment.
6. Doesn't our IT provider handle security?
Partially. Your IT provider can set up and run technical measures like firewalls, updates, antivirus, and backups. But the responsibility for IT security always lies with your business, not with the provider. This applies both under GDPR and in relation to your customers.
The provider also cannot know which data is most important to you, who should have access to what, or how your employees actually work. Therefore, ask your IT provider directly:
What security measures have you set up for us?
Are backups being taken, and when did we last test that they work?
What do you do if we are attacked, and how quickly?
Is security responsibility defined in our contract?
The answers will give you a clear picture of what is covered and what you need to handle yourself.
7. What are the most important security measures?
This is the essential IT security that all small businesses should have in place:
Multi-factor authentication on email, cloud services, accounting, and banking. This alone stops a huge percentage of account breaches.
Updates of PCs, phones, and software, preferably set to automatic.
Backups stored separately from your main systems, so a ransomware attack cannot encrypt them as well.
Strong, unique passwords using a password manager.
Restricted access: Not everyone needs administrator rights.
Correct setup of cloud services: Microsoft 365 and Google Workspace have excellent security features, but many are not enabled by default. Ask your IT provider to review your security settings.
This list works well as a simple IT security checklist for your business.
8. A client is asking about information security. Do we need ISO 27001?
More and more small businesses are receiving security questionnaires from clients or requirements in tenders. This does not necessarily mean you need to get certified. Often, it is enough to show that you have an overview, have assessed risks, and have taken concrete action.
ISO 27001 is the international standard for information security management. A certification builds trust, but is a major project, requiring documentation, internal audits, and external audits. For many small businesses, it is best to wait until a client or market actually demands it.
The key point is that the work you do now is not wasted. Fundamental measures like risk assessments, access management, backups, supplier follow-up, and incident response are the very things ISO 27001 is built on. If you start correctly, you will have already laid much of the groundwork for when you decide to seek certification.
9. What do we do if we are hit by a cyber attack?
Have a simple plan ready before it happens. The most important thing is knowing who does what in the first few hours.
If an email account is hacked:
Change the password immediately and sign out of all active sessions.
Turn on multi-factor authentication if it wasn't already active.
Check if any email forwarding rules have been created.
Warn contacts that they may have received fake emails from you.
In case of invoice fraud:
Contact your bank immediately. The quicker you act, the greater the chance of stopping the payment.
Report the incident to the police.
In case of ransomware:
Disconnect affected machines from the network.
Contact your IT provider.
Do not pay any ransom without getting professional advice first.
If personal data is affected, you must evaluate whether to report the breach to Datatilsynet within 72 hours. Note down what happened and what actions you took. This helps both for post-incident review and for any potential insurance claims.
Should we have cyber insurance? It can be a sensible option, especially if your operations grind to a halt without IT. However, insurers often require that basic measures like multi-factor authentication and backups are in place. The measures in this guide are therefore a prerequisite, not an alternative.
10. Can we use ChatGPT, Copilot, and other AI tools safely?
Yes, but with some simple rules. The main risk is employees pasting customer data, personal data, or trade secrets into tools where you don't know where the data ends up.
Simple rules for AI use in your business:
Choose enterprise versions of the tools. In these versions, it is standard agreement that your data is not used to train the models.
Do not enter personal data or confidential information into free versions.
Check the data processing agreement when an AI tool processes personal data. GDPR requirements apply to ChatGPT and Copilot just as they do to any other supplier.
Create a brief policy for employees, ideally just a single page, detailing what is acceptable and what is not.
Verify the output: AI can make mistakes, and you are ultimately responsible for what you publish or send out.
Summary: an IT security checklist for small businesses
Level 1 – get started (first month)
Multi-factor authentication on all key accounts
Tested backups
Overview of systems, data, and access rights
Automatic updates
Level 2 – get in control (first six months)
Simple risk assessment
Privacy policy, records, and data processing agreements in place
Breach and incident response procedures
Employee training on phishing and fraud
Guidelines for using AI
Level 3 – build further (when you are ready)
Regular supplier reviews
Annual review of risks and measures
Documentation that can be shared with clients and in tenders
Preparation for ISO 27001 if your market or clients demand it
With our Security in Small Businesses framework, your company gets a clear action plan with steps in the right order, tailored to where you are today. If you need help with technical implementation or employee training, we have partners who can manage that for you. Get in touch with us for an informal chat.
Back to Blog