Skip to main content
Security & ComplianceFree ForeverNew York SHIELD Act

Security for Small Business What You Actually Need to Do

You do not need an IT department. You need to close the doors attackers actually walk through, and know what New York law requires of you if something goes wrong.

Free cybersecurity basics that every business must do, in plain language. No product to sell you.

Security for Small Business

Most small business owners think security is something big companies worry about. Then a phishing email costs them twelve thousand dollars, or a laptop gets stolen with customer records on it, and they find out New York law had requirements they never knew existed.

This guide covers both halves: the practical steps that prevent most attacks, and the legal obligations you already have under New York law. You can act on the first half this week. The second half you need to understand before something goes wrong, not after.

The Practical Basics

You do not need an IT department. In order of impact, here is what actually closes the doors attackers walk through.

Turn on multi-factor authentication everywhere

This is the single highest-value thing you can do, and it is free. Even if someone steals your password, they still cannot get in without a code from your phone. Start with email, since it is the master key to everything else you own. Then do banking, your payment processor, and your point of sale system.

Use a password manager

Reusing the same password across accounts is how one breach becomes five. A password manager generates a different strong password for every account. It also solves what happens when an employee leaves: you revoke their access and move on, instead of changing one shared login for everyone.

Back up your data, and test the backup

Ransomware locks your files and demands payment. A working backup turns that into a bad afternoon instead of a business-ending event. Keep at least one backup that is not connected to your main system, and actually test it by restoring a file. A backup you have never tested is a guess.

Keep software updated

Updates close security holes attackers already know about. Turn on automatic updates for your operating systems, browsers, point of sale system, and website platform.

Limit who can access what

Give each person only the access their job requires. Remove access the same day someone leaves. This one habit prevents a large share of incidents, most of which are careless rather than malicious.

Passwords and Access

Use an authenticator app rather than text messages where you have the choice. Text messages can be intercepted through a technique called SIM swapping. An app is stronger and takes the same two seconds. Pair this with a password manager so every account has its own strong password, and you have closed the two most common doors attackers use.

A true story: when someone leaves

Carol managed the office of a small building firm for nine years, and everybody loved her. When she retired, nobody changed a thing. Her email stayed open. Her login to the accounting system stayed active. The safe word the team used for emergencies about money stayed exactly as it was, because Carol was Carol. Seven months later, on an ordinary Wednesday, that untouched access became the way someone else got in. The lesson is not about Carol, who did nothing wrong. It is that the day a person leaves is a security moment, every single time, no matter how much you trusted them.

Spotting Phishing

Most successful attacks on small businesses are not sophisticated. Someone sends an email that looks like it is from your bank, your vendor, or you, and an employee clicks it or wires money.

The pattern to teach your team: urgency plus a request to change payment details is almost always fraud. If a vendor emails saying their bank account changed, call them at the number you already have on file, never the number in the email.

A true story: the letter that frightens you

Hakim owns two small grocery shops and has never been in trouble with anyone. An email arrived using his real business name and a case number, claiming a discrepancy in his filings and threatening enforcement within seventy two hours. He did not sleep that night. He did not tell his wife, and he did not call his accountant, because he was embarrassed and wanted to make it disappear quietly. He called the number in the email. A polite man confirmed the case number back to him and offered to settle it immediately for eight thousand two hundred dollars. Relieved, Hakim paid.

Nobody borrowed his trust in that attack. They borrowed his fear, and fear does something trust never does: it makes people act quickly and completely alone. The single most useful habit you can build is this: whenever an official letter or call makes you afraid, stop, and tell one other person before you do anything else. Fear that is spoken out loud loses most of its power immediately.

What New York Law Requires of You

New York's SHIELD Act gives small businesses a lighter security standard, but there is no small business exemption from breach notification at all. If you have a breach, you must notify people, regardless of your size.

Does it apply to you?

Yes, if you hold computerized private information on New York residents. You do not need to be located in New York or do business here.

Are you a small business under this law?

Yes if you have fewer than 50 employees, under 3 million dollars in gross annual revenue for three years, or under 5 million dollars in total assets.

What counts as private information?

Social Security numbers, driver license numbers, financial and card numbers, biometrics, and a username or email paired with a password. Since March 2025 this also includes medical and health insurance information.

Your security duty

Reasonable safeguards, scaled to your size and the sensitivity of what you hold. The practical basics above count toward this.

If You Have a Breach: The First Hour

Almost anything can be fixed in the first hour, and almost nothing in the first week. The difference between a scare and a true disaster is rarely whether something bad happened. It is what you do in the sixty minutes right after you realize it.

1

Say it out loud, immediately. The instinct in that first moment is panic and shame, and both push toward silence. Do the opposite. Tell the people who need to know without wasting a minute on how embarrassing it feels. Speed beats shame.

2

Stop the bleeding first. If money is moving, your very first call is to your bank, on their real number, to flag a fraudulent payment and ask them to stop or reverse it. A payment caught in the first hour can often be pulled back. The same payment on the second day is very often gone for good.

3

Close the door that was used. If a password was compromised, change it immediately, everywhere you used it. If a password manager kept you to one unique password per account, this step just became far smaller than it would have been otherwise.

Beyond the first hour, the law adds specific duties. You must notify affected New York residents within 30 days of discovering the breach, plus the Attorney General. The law triggers on unauthorized access, not just theft, which is a lower bar than most owners assume.

Penalties can run up to 5,000 dollars per violation, but individuals cannot sue you directly under this law. This explanation is not legal advice. If you hold medical or financial data, spend an hour with a data privacy lawyer before you need one.

Do This Week

  • Turn on multi-factor authentication for email, banking, and payments.
  • Set up a password manager and stop reusing passwords.
  • Confirm you have a backup that is not always connected, and test it.
  • Turn on automatic updates everywhere.
  • Review who has access to what, and remove access for anyone who has left.
  • Write down what private information you collect, where it is stored, and who can reach it.

Free Business Help in NYC

NYC Small Business Services offers free expert help: business planning, legal advice, permit assistance, and more. No cost, no catch.

Security Q&A

Common questions from small business owners about security and New York law.

💬 Quick Q&A
CL
Authored by Christian Lawson | Based on real case studies and industry research
Last Updated: May 2026