The Cybersecurity Buying Guide I Give Every Small Business

Aug 17, 2026

What I Look at Before Recommending Anything

Every business that asks me about cybersecurity thinks it needs the biggest, priciest package on the market. It usually doesn't. A five-person accountancy firm has completely different risks to a warehouse team handling stock for a national retailer, and a two-person design studio working entirely from laptops has different risks again. The first thing I do with any business is work out what data it actually holds, who might want it, and what would genuinely hurt if it went missing. Get that right and the rest of the buying decision gets a lot simpler, because a good chunk of what gets sold to small businesses is priced for problems they don't actually have. I've sat through enough sales calls on behalf of clients to know the pattern: the pitch starts with the worst-case headline, not with a single question about what the business actually does, and by the time the quote lands it bears almost no relationship to the risk in front of you.

This matters more the smaller the business is, not less. A larger company usually has someone whose job it is to push back on an oversized quote or spot a contract clause that doesn't add up. A five-person team rarely has that person, which is exactly why so many small businesses end up either badly underprotected or paying for a package built for a company ten times their size.

The Non-Negotiables, Whatever Your Budget

Some things aren't optional, no matter how small the business is. A proper firewall, endpoint protection that actually updates itself rather than sitting untouched after installation, and backups that are tested, not just switched on and forgotten about. I've seen businesses pay for expensive software and never once check whether their backup would actually restore anything if it had to. Set a calendar reminder and test it, it takes twenty minutes and can save you a very bad week. I've written before about protecting small businesses if you want the fuller version of this advice, covering the basics without the jargon or the price tag some providers attach to them.

Two Tools Worth Paying For

Beyond the basics, the two upgrades I recommend most often are a proper password manager and a VPN for anyone working off site or on public wifi. If a team is still sharing logins on a spreadsheet, a tool like NordPass sorts that out in an afternoon, generating and storing a unique password for every account rather than the same one reused across a dozen logins by whoever set it up first. NordVPN is worth having too if anyone on the team works from cafes, client sites, or home broadband nobody's vetted, since public wifi is exactly the kind of connection a strong password alone won't protect you on. Neither costs much measured against what a breach would.

Red Flags When You're Being Sold To

Watch out for fear-based sales pitches, generic package deals that ignore what you actually told them about your business, and contracts that lock you in for years with no way out if the service turns out to be wrong for you. A good provider asks questions before they pitch anything, and if they can't explain in plain terms what a piece of software actually does for your specific setup, that's worth noticing. If a salesperson's first move is frightening you with ransomware headlines before they've asked a single question about how your business actually operates, that's a sign they're selling fear, not a solution built for you.

The Mistake I See Most Often

The single most common mistake isn't a missing piece of software at all, it's a business that bought the right tools and then never revisited the setup again. A password manager rolled out two years ago is only useful if new starters are actually added to it and leavers are actually removed, and I've walked into more than one business where a former employee's login still worked months after they'd left. The same goes for backup and endpoint software installed once during a rushed onboarding and never checked since. Cybersecurity isn't a one-off purchase you tick off a list, it's a handful of habits that need someone to actually own them, even if that's just fifteen minutes a quarter to check what's still active and who still has access to what.

What This Actually Costs

Business owners usually assume proper cybersecurity is going to be a huge line item, and that assumption alone stops a lot of sensible spending from ever happening. In reality, the non-negotiables I mentioned earlier, decent endpoint protection, tested backups, and a password manager across the whole team, usually cost less per month than a single client lunch. The expensive mistakes come from one of two directions: doing nothing until something goes wrong, or overspending on an enterprise-grade package sold to a five-person team that will never use half of what it includes. I'd rather see a small business spend modestly on the right things consistently than sign an eye-watering annual contract for coverage it doesn't actually need.

Getting Started

If you want a second opinion before you sign anything, my Safety Toolkit page lists the tools I actually use and recommend myself, and you're always welcome to get in touch. I'll give you my honest take, free of charge, no obligation, and if the answer turns out to be that you don't need anything beyond what you've already got, I'll tell you that too rather than talk you into a package you don't need.