When small business owners in Orange think about online security, they picture viruses and hackers breaking through a firewall. So they buy antivirus, feel covered, and move on. But that's not how most small businesses actually get compromised.
The single biggest gap we see isn't a missing piece of software. It's weak account security: specifically, no two-factor authentication and reused passwords. That's how the overwhelming majority of small business break-ins actually happen: not by hacking your computer, but by simply logging into your accounts.
Why passwords alone aren't enough
Here's the uncomfortable reality: if someone gets your email password, they don't need to hack anything. They just log in, and from your email, they can reset the password on almost every other account you own, because that's where the reset links go.
And getting that password is easier than most people think. Data breaches leak millions of email-and-password combinations. If you've reused a password anywhere, and it's since leaked from some unrelated website, attackers try that same combination on your email, your banking, your business accounts. This is automated and happens at massive scale. It has nothing to do with how careful you are day to day.
The fix: two-factor authentication
Two-factor authentication (2FA, sometimes called MFA or "two-step verification") means that even with your password, someone can't get in without a second thing, usually a code from your phone. It is the single most effective security step a small business can take, and for the accounts that matter most it's free.
Even if your password leaks tomorrow, 2FA stops the login cold. That's the whole point: it protects you from the exact attack that hits small businesses most.
Turn it on for these first, in this order
- Your email. This is the master key: every password reset flows through it. Secure this before anything else.
- Your banking and accounting (bank, Xero, MYOB, PayPal, etc.).
- Anywhere customer data lives, like your booking system, CRM, or online store.
- Your social media and Google Business Profile, since a hijacked profile can do real reputational damage.
Use an authenticator app (like Microsoft Authenticator or Google Authenticator) rather than SMS codes where you can. App-based codes are more secure than text messages, which can be intercepted. But SMS 2FA is still far better than none, so don't let "perfect" stop you turning something on.
The second half: stop reusing passwords
2FA is the priority, but reused passwords are what create the exposure in the first place. The realistic fix isn't memorising dozens of unique passwords; it's a password manager. It generates and remembers a strong, unique password for every account, and you only remember one master password. It removes the temptation to reuse, which is what most people do simply because remembering is hard.
What about antivirus and firewalls?
They still matter, so keep them. But think of them as locks on your doors. Account security is making sure you haven't left a key under the mat with your address on it. Most small business incidents we see aren't someone smashing through the front door; they're someone walking in with credentials that leaked somewhere else. Antivirus can't stop a correct password being used.
A practical afternoon's work
You don't need a big budget or an IT department. In an afternoon you can: turn on 2FA for your email, banking, and customer systems; set up a password manager; and change any passwords you know you've reused. That combination closes the gap that causes most small business compromises, and it costs little to nothing.
If you'd rather have someone set it up properly across your business, and make sure nothing important is missed, that's exactly the kind of job worth getting done once, correctly.