To protect your business, secure its data (multi-factor authentication, updates, backups, encryption and shredding), train staff to spot phishing and payment fraud, give employees the protective equipment and training that safety rules require, secure the premises, and keep a written plan for breaches, accidents and emergencies. Insurance then covers what prevention cannot.
Key Takeaways
- Business protection has three layers: data and cyber security, workplace health and safety, and physical security of the premises.
- Cybercrime is the fastest-growing threat: the FBI’s 2025 Internet Crime Report recorded 1,008,597 complaints and about $20.9 billion in reported losses, with business email compromise alone at about $3.05 billion.
- The basics stop most attacks: multi-factor authentication, prompt software updates, a password manager, offline backups and phishing training.
- In the US, OSHA’s personal protective equipment (PPE) standard requires a written hazard assessment, employee training and, with limited exceptions, PPE provided at no cost to workers.
- A written incident response plan, dated training records and the right insurance turn a potential disaster into a manageable event.
There are many ways in which you can protect your business and your employees while keeping them safe from either physical harm or harm via fraud or theft. There are still many businesses that do not take the safety of the data they hold or their employees seriously and are, therefore, leaving themselves open for the inevitable to happen.

Protecting all data
It is important that you protect all data on your site. This is not just customer data, which is very important but also employee data, product data, and any suppliers data which you may have. Any paper waste should be disposed of safely by shredding.
This is because thieves are still interested in your old paperwork, and it has been known for over a decade that it could aid them in identity fraud.
Due to the use of computers within the world today, people overload storage facilities with so much valuable information that you really do have to take special care in protecting it from unwelcome attention.
So, when you are looking at the information you hold on your cloud storage, you need to treat it a bit differently from how you treat your paper information.
Cloud security
There are many Cloud Security Issues that can arise should you not have adequate protection, and you need to protect your business from these.
If someone wanted to gain access to your paper information, they would physically have to be there, whereas to gain access to the information you hold on your cloud storage, they do not even have to be in the same country. This opens up your business to a whole new world of thieves and tricksters just looking for a weak link or a way in.
When you think of all the personal information you hold on your cloud storage facility for your employees, customers, suppliers, and of course all the information your business holds as regards products, bank accounts, and payroll details, just to name a few, it could be really daunting if a cybercriminal managed to hack in and steal it, and as far as any cybercriminal is concerned the information is worth a fortune to them.
Protecting your business against safety issues
When you run a business and have employees, it is important that you follow all safety guidelines given to you and that your employees understand the risks and reasons why these guidelines have been put in place.
Making sure that all your employees have the correct safety wear, such as a pair of safety glasses prescription spec, overalls and a hard hat if they work with heavy materials. Giving your employees all the correct protective wear and tools to carry out their jobs will not only protect them should there be any accidents but will also help show that your business met its legal duty of care if a claim or inspection ever follows.
If you happen to have a warehouse, then those employees working in that warehouse and any employees visiting the warehouse should be supplied with a high-visibility (hi-vis) jacket, vest or coat so that they will be easily seen either by other employees operating forklifts or other machinery or by delivery drivers in the yard.
They should have enclosed safety shoes on their feet, preferably with steel toe caps. This is to ensure that should anything be dropped on their feet that they are protected as much as they can be, and you reduce the risk of regulatory penalties or a lawsuit over an unsafe working environment.
It is important that if your business deals with chemicals, that you should supply your employees with the correct personal protective equipment in order for them to carry out their job roles safely and securely.
Otherwise, you could be opening yourself up for a lot of trouble if somebody should get hurt. It is a good idea to get your employees to sign to say that they have received training in how to conduct themselves as well as how to use the equipment correctly and that this is dated so that if an incident does arise, you have proof that full training was given and when.
Ensuring that your business premises are safe
It is important for the safety of your employees that your workplace is a safe place to be. There are lots of reasons why a place of work may not be seen as safe to an employee, including bullying, anti-social behavior, harassment, sexism, racism, homophobia, violence, whether it is physical or verbal, and then there is the actual security of the premises themselves.
Any problem which involves two employees or more such as bullying, harassment, or violence, should be sorted out as soon as possible.
Security of a building needs to be taken into full consideration, the installation of floodlighting over your parking lot to make employees feel safer in the dark, and making sure that there is no lone working on-site nor any one person leaving the premises on their own is another way you can make your employees feel safe and secure.
What Are the Biggest Threats to a Business Today?
The biggest threats to a business are cybercrime, fraud, workplace accidents and physical theft or damage. Official data shows cyber-enabled crime is growing fastest, and small firms are targeted because their defenses are usually thinner.
According to the FBI’s Internet Crime Complaint Center (IC3) 2025 Annual Report, published in 2026, the IC3 received 1,008,597 complaints in 2025 with reported losses of about $20.88 billion, a 26% rise in losses on 2024. Business email compromise (BEC) caused about $3.05 billion of those losses, and tech support scams about $2.13 billion. The IC3 also received more than 3,600 ransomware complaints.
Verizon’s 2026 Data Breach Investigations Report found that ransomware was involved in 48% of breaches and that software vulnerabilities (31% of breaches) have overtaken stolen passwords as the most common way attackers get in. IBM’s Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million, a 12% increase on the previous year and a record high. These figures are as of September 2026 and change with each annual report.
| Threat | What it looks like | First line of defense |
|---|---|---|
| Phishing | Emails, texts or calls that trick staff into clicking a link, opening an attachment or sharing a login | Staff training, email filtering, multi-factor authentication |
| Business email compromise | A fake or hijacked supplier, executive or lawyer email asking for a payment or changed bank details | Call-back verification of every new or changed payment instruction on a known number |
| Ransomware | Malware that encrypts files and demands payment, often after stealing data | Prompt patching, offline backups, least-privilege access |
| Paper and insider theft | Stolen documents, discarded records, misuse of access by current or former staff | Shredding, locked storage, removing access the day someone leaves |
| Workplace injury | Falls, struck-by incidents, chemical exposure, forklift accidents | Hazard assessment, PPE, training, housekeeping |
| Physical crime | Break-ins, vandalism, violence in parking areas | Lighting, access control, CCTV, lone-working procedures |
How Do You Protect Business Data From Cyber Attacks?
Business data is protected by a small set of controls applied consistently. The US Cybersecurity and Infrastructure Security Agency (CISA), through its Secure Our World program, recommends four core steps: recognize and report phishing, use strong passwords and a password manager, turn on multi-factor authentication (MFA), and update software without delay.
- Turn on multi-factor authentication for email, cloud storage, banking, payroll and admin accounts first. MFA means a stolen password alone is not enough to log in.
- Use a password manager and long, unique passwords. The US Federal Trade Commission (FTC) advises passwords of at least 12 characters, ideally passphrases. A secure password generator can create them.
- Patch quickly. Turn on automatic updates for operating systems, browsers, routers and business software, and replace devices that no longer receive security updates.
- Back up and test restores. Keep at least one backup copy separate from the main network so ransomware cannot reach it. Read more on why cloud backup and recovery matter.
- Encrypt laptops, phones and sensitive files, and use WPA2 or WPA3 encryption on Wi-Fi, as the FTC recommends.
- Limit access. Give each person only the accounts and data their role needs, and remove access on the day an employee or contractor leaves.
- Train staff regularly to recognize phishing, fake invoices and urgent payment requests. See this guide on protecting employees from spear phishing.
For a structured approach, the FTC points small businesses to the NIST Cybersecurity Framework, whose current version organizes security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. For the network side, read what you should know about network security.
How Do You Secure Cloud Storage?
Cloud storage is secured mainly through account security, because most cloud breaches start with a stolen or reused login rather than a flaw in the provider’s own systems. Enforce MFA for every user, review who has access and which files are shared publicly by link, turn on login alerts, and keep an independent backup of critical data. Check that the provider encrypts data at rest and in transit, and read which security tasks the contract leaves to you.
How Do You Stop Payment Fraud?
Payment fraud, especially business email compromise, is stopped by process rather than technology. Require a call-back to a known phone number (never one in the email) before paying a new supplier or changing any bank details, require two people to approve large transfers, and treat urgency and secrecy in a payment request as red flags. If money is sent to a fraudster, contact your bank immediately and, in the US, report it to the FBI’s IC3; speed matters because banks can sometimes freeze funds.
What Does OSHA Require for Personal Protective Equipment?
In the US, OSHA’s general industry PPE standard (29 CFR 1910.132) requires employers to assess workplace hazards, select suitable PPE, train employees to use it, and verify the hazard assessment with a written certification that names the workplace, the person certifying and the date.
- Who pays: OSHA requires employers to provide required PPE at no cost to employees, with limited exceptions. Employers do not have to pay for non-specialty safety-toe footwear (including steel-toe boots) or non-specialty prescription safety eyewear, provided the employer lets workers wear them off the job site.
- Training: employees must be trained on when PPE is necessary, which PPE is needed, how to put it on and take it off, its limitations and its care, and must show they understand before working with it.
- Penalties: as of September 2026, OSHA’s penalty page lists maximum civil penalties of $16,550 per serious violation and $165,514 per willful or repeated violation.
Rules differ outside the US: in the UK the Health and Safety Executive (HSE) enforces workplace safety law, and other countries have their own regulators. Check the rules that apply where the business operates, and take professional advice for hazardous work.
How Do You Make Business Premises More Secure?
Premises security combines deterrence, access control and procedures. Good lighting in parking lots and entrances, locked doors with controlled keys or access cards, visitor sign-in, alarm systems and CCTV used in line with local privacy law all reduce theft and help staff feel safer.
- Keep a register of who holds keys or access cards, and recover them when people leave.
- Store paper records, cash and devices in locked rooms or cabinets, and shred documents with personal or financial details.
- Write a lone-working policy with check-in times for anyone who opens up, closes up or works alone.
- Train staff on fire evacuation, first aid and how to report a safety or security concern.
What Should a Business Do After a Data Breach or Incident?
After a data breach or serious incident, a business should contain the damage, preserve evidence, notify the right people and fix the cause. A written incident response plan, prepared in advance, makes each step faster.
- Contain: disconnect affected devices, reset compromised passwords and revoke suspicious access.
- Get help: contact your IT provider, your cyber insurer’s response line if you have one, and your bank for any payment fraud.
- Report: in the US, report cybercrime to the FBI’s IC3; in the UK, personal data breaches that pose a risk to individuals must generally be reported to the Information Commissioner’s Office within 72 hours under UK GDPR.
- Notify: every US state has a data breach notification law, and deadlines and triggers vary by state, so take legal advice on who must be told and when.
- Learn: record what happened, close the gap and update training and procedures.
Workplace injuries follow a parallel path: give first aid, secure the area, record the incident and, in the US, report severe injuries to OSHA within the required deadlines.
Common Mistakes That Leave a Business Exposed
- Assuming the business is too small to be a target.
- Leaving email and cloud accounts protected by a password alone.
- Keeping backups connected to the network, where ransomware can encrypt them too.
- Paying changed bank details without a call-back check.
- Handing out PPE without training, or training without dated records.
- Forgetting to remove access and keys when staff leave.
For a deeper look at information security trends, see the future of data security for business information.
Frequently Asked Questions
What is the first step to protect a small business from cyber attacks?
The first step is turning on multi-factor authentication for email, cloud storage and financial accounts. CISA lists MFA among its four core steps, alongside strong passwords with a password manager, prompt software updates and recognizing phishing.
Do small businesses really get hacked?
Yes. Small businesses are regularly hit by phishing, business email compromise and ransomware because they often lack dedicated security staff. The FBI’s IC3 recorded more than one million cybercrime complaints in 2025.
Does an employer have to pay for safety glasses and steel-toe boots?
In the US, OSHA generally requires employers to provide required PPE at no cost. The exceptions are non-specialty prescription safety eyewear and non-specialty safety-toe footwear, provided the employer allows workers to wear them off the job site.
What insurance protects a business?
Common policies include general liability, property, workers’ compensation where required, and cyber insurance. The FTC notes that cyber insurance can include first-party coverage for your own losses and third-party coverage for claims against you; read exclusions carefully.
How often should staff receive security and safety training?
Training should happen at hiring, whenever duties, equipment or threats change, and at regular intervals, with dated records kept. The FTC recommends ongoing cybersecurity training rather than a single session.