A lot of small business owners assume hackers go after big companies with something worth stealing. It is actually the opposite. Small businesses get targeted precisely because the defenses tend to be weaker. Verizon's 2025 Data Breach Investigations Report found that ransomware was involved in 88% of breaches at small and mid-sized businesses, more than double the 39% rate at large organizations. You do not need an in-house IT department to close most of the gap. A handful of basics cover most of the real risk.

Password Management and Multi-Factor Authentication

This is the highest-impact, lowest-cost fix available, and most businesses still are not doing it consistently. Weak or reused passwords are behind a huge share of breaches, because once one account is compromised, attackers try the same password everywhere else.

A password manager (1Password and Bitwarden are both solid options) lets your team use a unique, strong password for every account without having to memorize any of them. Multi-factor authentication, where logging in also requires a code from your phone or an authentication app, should be turned on for email, banking, and any accounting or payment software you use. According to CISA, turning on MFA makes you 99% less likely to be hacked, because a leaked password alone is no longer enough to get in.

Backups

Ransomware works by locking you out of your own files and demanding payment to get them back. A solid backup strategy is what makes that threat mostly irrelevant, because you can restore your systems instead of paying anyone.

The standard approach is the 3-2-1 rule: keep three copies of your data, on two different types of storage, with one copy stored somewhere off-site or in the cloud. A backup that lives on the same network as everything else can get encrypted right along with your live files in a ransomware attack, so the off-site copy matters more than people expect. Just as important, actually test that your backups restore correctly every so often. A backup nobody has tested is a backup nobody can trust.

Email Security and Phishing Awareness

Most breaches do not start with a sophisticated hack. They start with someone on your team clicking a link in an email that looked legitimate. Phishing emails have gotten harder to spot, often impersonating a vendor, a bank, or even someone else inside your own company asking for an urgent wire transfer or login credentials.

The version that catches small businesses most often looks like this: an email arrives that appears to be from your bookkeeper or a vendor you actually use, referencing a real invoice, asking you to update the bank details for payment. Nothing about it looks dramatic. The money goes out, and it is usually gone for good. Any change to payment details should be confirmed by phone, using a number you already had, not one printed in the email.

A few habits go a long way here: verify any request for payment or sensitive information through a second channel, like a phone call, before acting on it, especially if it feels urgent. Hover over links before clicking to see where they actually go. And run through basic phishing awareness with your team periodically. It does not need to be elaborate; even a short annual refresher measurably reduces how often people fall for these emails.

The New York Law That Applies to You

This is the part most Long Island small business owners have never heard of. New York's SHIELD Act, short for Stop Hacks and Improve Electronic Data Security, applies to any business holding private information about a New York resident. There is no revenue threshold and no minimum size. If you keep a customer list with names attached to account numbers, card data, driver's license numbers, or even an email address paired with a password, the law applies to your business.

Small businesses get a scaled version of the requirement rather than an exemption. If you have fewer than 50 employees, under $3 million in gross annual revenue in each of the last three fiscal years, or under $5 million in year-end assets, you satisfy the law with safeguards that are reasonable for your size, the nature of your business, and how sensitive the information you hold actually is. You are not expected to run enterprise security. You are expected to have something deliberate in place.

In practice that means naming someone responsible for security, thinking through where your data is actually exposed, training staff, and disposing of old records properly rather than letting them sit indefinitely. The New York Attorney General's own guidance points to multi-factor authentication, particularly for administrative and remote logins, and to long passwords checked against known breach databases. Those are the same two steps at the top of this article, which is convenient: the highest-value security fix is also the one the state most wants to see.

One detail worth knowing: the breach notification side of the law has no small business carve-out at all. If private information is exposed, you must notify the affected New York residents within 30 days of discovering the breach, and you also notify the Attorney General, the Department of State, and the State Police. Businesses regulated by the Department of Financial Services must notify that agency too. No minimum number of affected people triggers it. Civil penalties for failing to meet the data security requirements can run up to $5,000 per violation.

When to Bring in a Managed IT Provider

A solo business or a small team with straightforward needs can usually handle the basics above without outside help: a password manager, MFA turned on everywhere, and a cloud backup service.

It is worth bringing in a managed IT provider once you are handling sensitive customer data (health records, payment information, anything regulated), running your own servers or complex networks, or simply growing to the point where nobody on staff has time to keep security up to date. A good local provider will also handle patching software, monitoring for suspicious activity, and responding quickly if something does go wrong, which matters more than most of the preventive steps once an incident is already underway.

Common Questions

Does the SHIELD Act apply if my business is not in New York?

Yes, if you hold private information about New York residents. The law follows the data, not your address. A business anywhere in the country with New York customers on its list falls under it.

Is antivirus software enough on its own?

No. Antivirus catches malicious files, but most small business incidents start with someone entering a password on a convincing fake login page or approving a payment based on a spoofed email. No antivirus product stops that. Multi-factor authentication and a habit of verifying payment changes by phone do more.

How often should backups be tested?

Quarterly is a reasonable rhythm for most small businesses. Restore a handful of real files, not just check that the backup job reported success. Plenty of businesses discover their backup has been silently failing only when they finally need it.

What should I do first if I think we have been breached?

Preserve what happened rather than immediately wiping machines, since that evidence matters later. Change passwords on affected accounts, contact your IT provider or an incident response firm, and talk to an attorney early, because New York's notification requirements have real deadlines and specific agencies that must be told.

You can browse Long Island IT services and cybersecurity providers in our directory to compare local options.

This article is for general informational purposes only and is not a substitute for a professional security assessment. Talk with a qualified IT or cybersecurity provider about the specific risks facing your business.

© 2026 by liventures.com. All rights reserved. No part of this document may be reproduced or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, or otherwise, without prior written permission.

Editor
Author: Editor