Risk
Cybersecurity Risk
Attackers don't choose targets. Bots do, and bots pick the unprotected. The basics (MFA, updates, backups, training) are cheap, boring, and defeat most of what actually arrives.
- Beginner
- 6 min total
- 10 chapters
What decision this helps you make: Which of the five basics your business is missing, and which one to turn on this week.
- Related calculator: Cash Runway Calculator
What this topic is
Cybersecurity risk is the exposure of your systems, credentials, money, and customer data to digital attack: phishing, email compromise, ransomware, stolen passwords, and breaches. For small businesses the defining fact is automation: attacks are run by software that scans for the unprotected, regardless of company size.
Why it matters
A successful attack can freeze operations (ransomware), redirect money (email compromise), and leak customer data (breach), with recovery costs, downtime, and trust damage landing on a small business's thin margins. Yet most successful attacks exploit missing basics, not genius: the defense is configuration, not a security department.
Who should learn it
Every owner with an email account, a bank login, and customer data, which is every owner.
What you will understand
- Drop the "too small to target" myth: automation targets everyone unprotected
- Learn the big five: MFA, updates, backups, training, least privilege
- See why credentials are the crown jewels, and reuse is the master key
- Plan for the bad day: offline backups and an incident plan decide the damage
Prerequisites
Common misconception
"Hackers target big companies. We're not worth attacking." Attacks are automated: bots scan every reachable system and phish every findable inbox, and they select for weakness, not size. Small businesses get hit constantly precisely because the basics are missing: you don't need to be worth targeting; you need only be easy. The inverse is the good news: basic hygiene removes you from the pool the automation feeds on.