Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

The 30-Day Small Business Security Hardening Playbook

In short

A four-week plan that takes your business from exposed to genuinely resilient, no IT degree required. Each week has a short, do-able task list: switch on multi-factor authentication, sort your backups, protect your email domain, roll out a password manager, get updates under control, and train your team. Follow it in order and you will close the gaps attackers use most.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Why 30 days, and why in this order

Most small businesses are not breached by genius hackers. They are breached by automated attacks that hunt for the easy stuff: a password reused across sites, an email account with no second layer of protection, a backup that quietly stopped working months ago. The good news is that the fixes are ordinary and cheap. The hard part is doing them in a sensible order without getting overwhelmed.

This playbook spreads the work across four weeks. Each week builds on the last, and each task is small enough to finish in a coffee break or two. You do not need a bigger budget to be far harder to attack. You need to do a handful of ordinary things properly, in the right order, and then keep doing them.

Print this page, or keep it open, and tick off each item as you go.

Week 1: Lock the front door (MFA and accounts)

The fastest, cheapest win in security is multi-factor authentication (MFA), sometimes called two-step verification. It means that even if a criminal steals your password, they still cannot get in without a code from your phone.

  • Day 1 – Turn on MFA for your email. Email is the master key to your business; password resets for everything else land there. Switch on MFA in Microsoft 365 or Google Workspace first. Use an authenticator app rather than text messages where you can.
  • Day 2 – Turn on MFA for your other important accounts. Online banking, accounting software, your website host, your domain registrar, and any system holding customer data.
  • Day 3 – Make a list of every account that matters. A simple spreadsheet: what it is, who has access, and whether MFA is on. This becomes your master inventory.
  • Day 4 – Remove access nobody needs. Old staff, former contractors, that shared login three people use. Every extra door is a risk.
  • Day 5 – Check who has admin rights. Admin (or owner) accounts can change everything. Keep the number tiny, and never use an admin account for day-to-day email and browsing.

By the end of Week 1 you have closed the door that attackers walk through most often.

Week 2: Make sure you can recover (backups)

Ransomware, a stolen laptop, a deleted folder, a flood in the office. The question is not whether something will go wrong, but whether you can recover when it does. A backup you have never tested is just a hope.

  • Day 8 – Confirm what is actually being backed up. Email, shared files, accounting data, your website. Write down where each one lives.
  • Day 9 – Follow the 3-2-1 rule. Keep three copies of important data, on two different types of storage, with one copy off-site or in the cloud. Cloud services like Microsoft 365 hold your live data, but they are not a full backup on their own.
  • Day 10 – Set up a proper backup for your cloud data. Many owners wrongly assume Microsoft or Google keep permanent copies. They do not; if a file is deleted or encrypted, it can be gone. A dedicated backup fixes this.
  • Day 11 – Do a test restore. Pick a file and actually recover it. This is the step everyone skips and the one that matters most.
  • Day 12 – Write down your recovery plan. One page: what to do, who to call, and where the backups are, if the worst happens.

Week 3: Protect your email and passwords

Email is where most attacks begin, through phishing or by criminals pretending to be you. This week you make your email harder to fake and your passwords far harder to crack.

  • Day 15 – Roll out a password manager. Stop reusing passwords and writing them on sticky notes. A password manager creates and remembers a strong, unique password for every account. Proton Pass is a straightforward, privacy-focused option, and Proton is the same email provider we use ourselves at Dacros, so it is a genuine recommendation rather than a name pulled from a list.
  • Day 16 – Change your weakest, most reused passwords first. The password manager will flag them. Prioritise email, banking and anything holding customer data.
  • Day 17 – Set up SPF, DKIM and DMARC for your domain. These are settings that stop criminals sending emails that look like they came from your business. They are technical, so this is a fair one to hand to your IT provider. They protect your reputation and your customers.
  • Day 18 – Learn to spot a phishing email as a team. Unexpected urgency, a request to pay or change bank details, a link that does not match the sender. When in doubt, phone the person on a number you already have.
  • Day 19 – Agree a rule for money and bank-detail changes. Any request to change payment details must be verified by phone. This one habit stops invoice fraud, which costs UK businesses in the hundreds of millions of pounds a year (per UK Finance’s Annual Fraud Report).

Week 4: Keep it that way (updates, devices and people)

Security is not a one-off project. Week 4 turns what you have done into habits that keep working.

  • Day 22 – Turn on automatic updates everywhere. Laptops, phones, and key software. Most breaches exploit flaws that were already fixed, in updates people had not installed.
  • Day 23 – Check every device has protection. Built-in tools like Windows Defender are fine for many small businesses, as long as they are switched on and updating.
  • Day 24 – Secure your Wi-Fi and router. Change any default admin password, and set up a separate guest network so visitors are not on the same network as your business data.
  • Day 25 – Sort out mobile phones. If staff read work email on personal phones, make sure those phones have a screen lock and can be wiped remotely if lost.
  • Day 26 – Run a short team briefing. Fifteen minutes: the phishing rule, the payment-verification rule, and how to report anything suspicious without fear of blame.
  • Day 29 – Book your next review. Put a recurring monthly reminder in the calendar to check backups and updates, and a quarterly one to review who has access.

What to do after Day 30

You have now closed the gaps that most attacks rely on. To keep the momentum:

  • Keep the monthly backup and update checks going. They take minutes and save days.
  • Review access whenever someone joins or leaves.
  • Consider Cyber Essentials, the UK government-backed scheme that certifies you have the basics in place. It reassures clients and insurers, and increasingly it is required to win contracts.

If any step in this playbook feels daunting, that is completely normal, and it is exactly what a good IT partner is for. Our managed IT services and cyber-security support are built for small businesses that want this handled without the jargon.

Want a second pair of eyes? Book a free IT and security review and we will walk through your setup, tell you honestly what is solid and what needs attention, and help you finish anything on this list. See our straightforward pricing if you would like to know where you stand first.

Frequently asked questions

Do I need to be technical to follow this playbook?

No. Every step is written for a non-technical owner and uses settings built into tools you already have, like Microsoft 365 or Google Workspace. Where a step is fiddly, we say so, and you can ask an IT provider to do that one part for you.

How much will the 30-day plan cost?

Most steps are free or already included in software you pay for. A password manager and a proper backup may add a small monthly cost per user. The biggest investment is a few hours of your time spread across the month.

What is the single most important step?

Turning on multi-factor authentication (MFA) on email and your key accounts. It blocks the vast majority of account takeovers even if a password is stolen, which is why it is Week 1, Day 1.

What happens after the 30 days?

You keep the habits: monthly backup checks, prompt updates, and reviewing who has access when staff join or leave. Many owners then pursue Cyber Essentials certification to prove their security to clients and insurers.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.