Signs your office is more exposed than you think
Small offices rarely get singled out. They get caught by the same automated scams that hit everybody, and the ones that get hurt left a door open. These are the open doors we find most often:
- Email accounts protected by a password and nothing else.
- The same password used for email, the bank and the accounting software.
- Passwords kept in a spreadsheet, a notebook or a sticky note under the keyboard.
- The router your internet provider installed is the only thing between the office and the internet, still on its original settings.
- There's a backup drive, but nobody has ever tried to get a file back from it.
- Staff get fake invoices and "your mailbox is full" messages weekly and have no instructions for what to do with them.
- Everyone signs in to their computer as an administrator.
If you think something has already happened, such as money sent to a fake vendor, a mailbox sending spam or a scammer who got remote access to a computer, go to our virus and scam removal page and call us. This page is about closing the doors beforehand.
Seven layers that fit a small office
No single product protects an office. Security works in layers, so that when one fails (and one will) the next one catches the problem. None of the seven below needs an enterprise budget or a full-time IT person.
1. A business firewall
A firewall sits between your office network and the internet and decides what's allowed through. The modem and router combination from an internet provider does a basic version of this. A business firewall does more: it blocks known bad destinations, lets you put guest Wi-Fi and card readers on their own separate networks, and keeps a log you can go back to when something looks wrong. We install it, configure it and keep its software current.
2. Protection on each computer
Every PC and Mac needs protection software that's turned on, up to date and watched by someone. The watching is the part that gets missed. A warning that pops up on one employee's screen and gets closed has protected nobody. We set it up so alerts go to a person whose job is to read them. We also turn on disk encryption, which is built into both Windows and macOS, so a stolen laptop is a lost laptop and not a lost client list.
3. Multi-factor authentication
Multi-factor authentication (MFA) means a password alone isn't enough to sign in. You also approve the sign-in on your phone or type a short code. If we could do only one thing on this list for an office, it would be this, starting with email. Email is the account every other password reset goes through. We turn it on for each person, sit with them while they set it up, and store backup codes somewhere safe so a lost phone doesn't lock anyone out.
4. A password manager
People reuse passwords because nobody can remember a hundred different ones. A password manager remembers them, creates long random ones, and fills them in only on the real website, which also helps against fake login pages. For an office, the bigger benefit is shared access. The login for the bank, the utility account and the supplier portal lives in a shared vault, and when someone leaves, you remove their access without changing every password by hand.
5. Email filtering
A lot of small office break-ins start with an email: a fake invoice, a link to a fake sign-in page, a message that looks like it came from the owner asking for a wire transfer. Microsoft 365 and Google Workspace both include filtering that's stronger than most offices realize, once it's switched on and tuned. We also set up the domain records (SPF, DKIM and DMARC) that make it harder for someone to send mail pretending to be you. If your email itself needs moving or cleaning up, that's on our Microsoft 365 and email page.
6. Backups with tested restores
A backup you haven't restored from is a hope. We set up backups using the old rule of three copies, on two kinds of storage, with one copy off-site. For most offices that means the working files, a local copy for quick recovery and a cloud copy in case of fire, theft or ransomware. Desert summers are hard on drives and power, so the off-site copy matters here; our desert computer guide on pdgeeks.com explains why.
People are often surprised that files in Microsoft 365 or Google Workspace aren't backed up the way they assume. Those services keep deleted items for a limited time, which isn't the same as a backup you control. Then comes the step that gives this layer its name: on a schedule, we pick real files, restore them and confirm they open. If the backup is ever all you have left, that's the wrong day to find out it wasn't working. Recovering files from a drive that has already failed is a different job, covered on our data recovery page.
7. Staff awareness
Your staff see the scams before any software does. They need a few habits, and none of them takes a training course to learn. Check the sender's actual address. Don't sign in from a link in an email. Any request to change bank details or send money gets confirmed by calling a phone number you already had. And they need to know that reporting a mistake quickly is welcome, since an employee who clicked something and says so within minutes has done you a favor. We'll walk your team through this in plain language and leave a one-page reference behind.
How the work goes
We start by looking at what you have, and you get a written list sorted by risk. Then we go in order, starting with the steps that do the most for the least effort.
- Turn on MFA for email and banking, and remove accounts that belong to people who've left.
- Get a working backup in place and prove it with a restore.
- Put protection on every computer and bring updates current.
- Roll out the password manager and retire the spreadsheet.
- Tighten email filtering and set up the domain records.
- Replace or reconfigure the firewall and separate guest Wi-Fi from office machines.
- Walk the staff through what to watch for.
Each step is quoted before it starts, and you can stop after any one of them and still be better off than before. Keeping it all patched and watched afterward is ongoing work, which is what a managed IT plan is for. The network side of the job, including guest Wi-Fi, is covered under office networks and Wi-Fi.
Medical and regulated offices
If you handle patient records, client financial data or anything else covered by privacy rules, the same seven layers apply, with more attention to who can see what and to writing things down. Our work with these offices is HIPAA-aware. We can assess your current security, point out the gaps and fix the technical ones, and we help you prepare for a formal review or audit.
We don't certify compliance, and we won't tell you that buying a product makes you compliant. That determination belongs to your compliance officer, your attorney or an auditor. What we can do is make sure the technical side holds up when they look at it. Practices in the medical corridors we describe in the Rancho Mirage guide deal with this regularly.
When simpler is enough
A two-person office with cloud email doesn't need all seven layers on day one, and the paid versions of several can wait. The short list covers most of the risk:
- MFA on email and banking.
- Automatic updates left on.
- The protection built into Windows or macOS, left on.
- A password manager.
- One cloud backup you've restored a file from at least once.
If you're comfortable in settings menus, you can do most of that yourself in an afternoon. If you'd like someone to check your work or do it for you, that's a small job and we're glad to take it. A business firewall and tuned email filtering start to earn their keep once you have several people, guest Wi-Fi, card payments on the network or regulated data.