The UK Small Business
Email Deliverability Experts

Email Security for Small Businesses: The Basics That Stop Most Attacks

Padlock icon: email security
This guide walks through the settings and habits that protect a small business's email, in order of how much difference they make.

Most attacks on small businesses start with email: a stolen password, or a convincing fake invoice. You do not need expensive security products to stop them. A handful of settings and a few habits block the great majority, and most take minutes to put in place.

Why small businesses are targeted

Criminals do not pick victims by size. They send millions of emails and work on whoever responds. A small business pays invoices, holds customer details and rarely has anyone watching its email settings.

A break-in usually ends one of two ways. Either a customer is sent a fake invoice with new bank details, or your mailbox is used to send thousands of scam emails and your domain’s reputation suffers.

 

1. Turn on two-step verification for every mailbox

This is the single most effective step. With two-step verification, a stolen password is not enough to get in. The attacker also needs your phone or security key.

  • Microsoft 365: turn on ‘security defaults’, or ask whoever manages your account to confirm it is on.
  • Google Workspace: in the Admin console, go to Security, then Authentication, then ‘2-step verification’, and enforce it for everyone.

Use an authenticator app or a passkey where you can. Codes by text message are better than nothing but easier to intercept. Cover every account, including the administrator account and any shared mailbox.

 

2. One person, one login, one strong password

Give each person their own mailbox and password. When two people need the same inbox, such as info@ or accounts@, use a shared mailbox or delegated access. Do not hand round one password.

Make each password long and unique. Three random words is the approach the National Cyber Security Centre recommends. A password manager removes the need to remember them.

Never reuse your email password anywhere else. Email is where every other account sends its ‘reset your password’ link, so whoever controls your email controls the rest.

 

3. Keep the administrator account separate

The administrator account can reset any password and read any mailbox. Do not use it for everyday email. Keep it as a separate login, used only for changes, with two-step verification on.

 

4. Check for forwarding rules you did not create

An attacker who gets into a mailbox often adds a rule that quietly forwards copies of your email, or hides replies from your bank. The rule keeps working after you change the password.

Once a month, look in each mailbox’s settings for forwarding addresses and inbox rules, and remove anything nobody recognises. Check the list of connected apps and signed-in devices at the same time.

 

5. Stop other people sending as your domain

Without the right DNS records, anyone can send an email that appears to come from your address. SPF, DKIM and a DMARC policy of quarantine or reject close that gap.

Start with What is SPF, DKIM and DMARC?, then use What DMARC reports tell you to tighten the policy safely.

 

6. Never change bank details on the strength of an email

Invoice fraud is the costliest email scam for small businesses. An email arrives, apparently from a supplier, saying their bank details have changed. Sometimes it comes from the supplier’s real mailbox, because that has been broken into.

Make one rule and keep to it. Any new or changed bank details are confirmed by phone, using a number you already hold and not one in the email. Tell your own customers that you will never change your bank details by email.

If money has been sent to the wrong account, phone your bank straight away. Calling 159 connects you to most UK banks’ fraud teams.

 

7. Teach everyone the signs of a fake email

Most phishing emails share the same marks:

  • pressure to act now
  • a link to a login page you were not expecting
  • a sender address that does not match the name shown
  • a ‘shared document’ or ‘voicemail’ from someone you do not know
  • a QR code to scan instead of a link

Make it normal to ask before clicking, and make sure nobody is blamed for reporting a mistake quickly. Forward suspicious emails to report@phishing.gov.uk, the National Cyber Security Centre’s reporting address.

 

8. Keep devices and email apps up to date

Install updates on computers and phones when they are offered, and set a screen lock on every device that holds work email.

Use a current email app that signs in through your provider’s own login page. Old apps that need a special ‘app password’ bypass two-step verification and should be replaced.

 

9. Close accounts when people leave

On someone’s last day, block their sign-in, change any password they knew, and remove their phone from the account. Then turn their mailbox into a shared mailbox, or forward it to a colleague, so customer emails are not lost.

Old, forgotten accounts with weak passwords are a common way in.

 

10. Keep your own backup

Microsoft and Google keep their services running, but that is different from keeping your data. Email that is deleted, by mistake or by an attacker, can usually only be recovered for a few weeks.

A separate backup service for your mailboxes costs a few pounds a month per user.

 

If something does go wrong

Act in this order:

  1. Change the password and sign out of all devices. Our guide Business email hacked? covers the full steps.
  2. Phone your bank if any payment could be affected.
  3. Report it. In England, Wales and Northern Ireland, use Report Fraud at reportfraud.police.uk or 0300 123 2040. In Scotland, call Police Scotland on 101.
  4. If personal information about customers or staff may have been exposed, you may need to tell the Information Commissioner’s Office within 72 hours.

 

A 30-minute check

  • Two-step verification is on for every mailbox, including the administrator.
  • No two people share a password.
  • No mailbox has a forwarding rule you did not set.
  • Your domain has SPF, DKIM and DMARC records.
  • Everyone knows the rule about bank details.
  • You know where your backup is.

 

Need help fixing this?

We provide:
  • Free initial assessment
  • Clear explanation of the issue
  • Fixed-price solutions
  • UK-based support

If you would like a second pair of eyes on your email security, tell us which provider you use and we’ll check the essentials for you.

Get in touch
Online now: Amanda, our supportive AI Agent, 24/7
Pop in your details below and we'll bring you straight into the conversation.
We never phone. We'll only text you the link to your private ticket chat, so you can still reach us if your email stops working.
Please fill in the required fields.
Emails going to spam
Website not sending emails
Not sure what's wrong
Set up business email