Cybersecurity advice can feel aimed at large companies with dedicated teams. Small businesses in Port Elizabeth and Gqeberha face the same threats — phishing, stolen passwords, ransomware, invoice fraud — often with fewer people to watch systems. The good news is that a short list of consistent practices closes many gaps without enterprise complexity.
Take email fraud seriously
Business email compromise remains one of the most costly attacks on SMEs. Attackers impersonate a director or supplier and ask for an urgent payment or bank detail change. Train staff to verify unusual requests through a second channel — a known phone number, not a number in the same email.
Use professional email on your own domain with sensible authentication (SPF, DKIM, DMARC where your host supports them). Consumer addresses on invoices look unprofessional and make impersonation easier.
Passwords and multi-factor authentication
Reused passwords are a domino effect: one leaked website credential unlocks your accounting or Microsoft 365 account. Require unique passwords and enable multi-factor authentication (MFA) on email, cloud storage, and banking portals that support it.
A password manager helps staff generate and store strong credentials without sticky notes under keyboards. MFA is not perfect, but it blocks a large share of automated break-in attempts.
Keep systems updated
Unpatched Windows, macOS, routers, and line-of-business software are open doors. Enable automatic updates where safe, and schedule maintenance windows for servers or specialised apps that need testing first. End-of-life operating systems should be replaced or isolated — they will not receive fixes for new vulnerabilities.
Control who can access what
Not every employee needs administrator rights on their PC or full access to every shared folder. Use role-based access: accounts payable does not need engineering drawings; temp staff should not retain access after they leave.
Review accounts when people join, move roles, or depart. Forgotten VPN or cloud accounts are a common oversight.
Secure your Wi‑Fi and guest access
Separate guest Wi‑Fi from internal systems. Change default router passwords. Use WPA2 or WPA3 with a strong passphrase. If customers only need internet, they should not be able to reach printers, NAS devices, or desktop shares.
Backups are part of security
Ransomware recovery depends on backups that attackers cannot encrypt along with live files. Offline or versioned off-site copies turn extortion from a company-ending event into a difficult but survivable restore. See our guide on how small businesses should back up data for practical detail.
Physical security still matters
Unlocked offices, visible passwords, and laptops left in vehicles expose data without any “hacking.” Screen locks, disk encryption on portable machines, and sensible clean-desk habits cost little and complement technical controls.
Know what you have connected
Inventory internet-facing services: remote desktop, CCTV portals, old FTP servers, vendor VPNs. Disable what you no longer use. Each exposed service is another place to patch and monitor.
Respond calmly if something goes wrong
If you suspect compromise, isolate affected machines from the network, change passwords from a clean device, and preserve logs before rebooting everything. Report incidents to your bank if payments were involved. Having a one-page response checklist saves panic-driven mistakes.
Proportionate local support
RedLeopardIT provides Cybersecurity Protection guidance for businesses in Nelson Mandela Bay — practical steps matched to how you actually work, not checkbox compliance for its own sake. Explore our IT services hub or contact us if you want help reviewing your current setup.