Most of India's small and medium businesses have no security team, no security budget, and no realistic prospect of either. They also have GST filings, customer phone numbers, a current account with net banking, a WhatsApp group where approvals happen, and — since the DPDP Act — statutory duties toward the personal data they hold. The advice written for enterprises does not scale down to this. What follows does.
The order matters more than the list. Each of these removes a category of attack that actually reaches Indian small businesses, and each is achievable in an afternoon by whoever currently handles the computers.
1. Turn on two-factor authentication where the money and the mail are
Not everywhere — everywhere is how these projects stall. Two places first: the business email account, and the bank. Email is the target because it is the recovery channel for everything else and because it is where the invoices live; the fraud that has cost Indian firms most reliably is not ransomware but the redirected payment, in which someone reads a genuine invoice thread and sends a polite correction to the account number. Ubiquiti told the SEC in August 2014 that impersonated executives had moved $46.7 million; the same technique now arrives at businesses with twelve employees, because it costs the sender nothing. Use an authenticator app rather than SMS where the service allows it.
2. Get the money process off the messaging app
Approvals over WhatsApp are convenient and unverifiable. The rule that stops nearly all payment fraud fits in one line, and it must be a rule rather than a habit: a change of bank account, or a payment above a set figure, is confirmed by a phone call to a number already on file — never a number supplied in the message asking for the payment. Write it down, tell the vendor you will be doing it, and make it stick when the person asking claims to be the managing director and says it is urgent. Urgency is the technique.
3. Back up so that one compromised login cannot delete everything
A Tally file copied to a pen drive left in the same drawer is not a backup, and a cloud folder that syncs deletions is not one either. What is needed is one copy the everyday administrator account cannot reach — an offline disk rotated weekly, or a cloud backup with its own separate credentials and versioning switched on. Then restore something from it, once, before you need to. The full argument is in this desk's companion piece, but the small-business version is short: the copy you cannot delete is the one that saves you.
4. Know your six-hour clock before you need it
CERT-In's direction requires certain incidents to be reported within six hours of noticing them, and it applies to companies far smaller than most owners assume — the obligation follows the incident, not the headcount. Six hours is not enough time to work out who to call, so decide now: who declares an incident, who writes the report, where the logs are, and who tells the bank. Our explainer on the six-hour rule sets out which categories are covered and what the 180-day log mandate means for a business with one server. Meanwhile the DPDP Act adds its own duty to notify affected people and the Data Protection Board — two clocks, one incident, and no relief for being small.
5. Decide what you are allowed to lose
Security spending goes wrong when it is spread evenly. List what would actually stop the business: the customer ledger, the GST credentials, the design files, the machine that runs the one licensed application nobody can reinstall. Protect those four properly and accept ordinary risk on the rest. A small business that can name its crown jewels and has them backed up, access-controlled and rehearsed is in better shape than one that bought an appliance it never configured.
Two habits close the list, and both are free. Keep an asset list, even in a spreadsheet, because you cannot protect what nobody remembers exists. And when an employee leaves, remove their access the same day — the most common way a small Indian business loses its data is not a foreign intruder but a former employee whose login still works, and the fix is a checklist rather than a product.