Most business owners think security is complicated, expensive, and something you deal with after something goes wrong. It is none of those things. The handful of steps that actually stop the scams and account takeovers we see every week are simple settings and habits you can handle yourself. Set a timer for fifteen minutes this weekend, work down this list, and you will close the doors attackers rely on being left open.

We built this from the real incidents that land on our desk: malware, hijacked listings, phishing, and account takeovers. Each step below links to the deeper guide if you want the full story, but you can do every one of them without reading further.

Security is not a product you buy. It is five doors you lock. The businesses that get hit are almost always the ones that left one of these open.
15
minutes total to work the whole list
5
doors that stop the most common attacks
$0
it costs to do every step yourself
1
3 minutes

Turn on two-factor authentication

Do this for every account that matters: email first, then banking, Google, Microsoft, your website host, and your social accounts. Two-factor means that even if someone steals your password, they still cannot get in. It is the single highest-impact thing on this list, and it is the same lock that would have stopped most of the account takeovers behind our website malware incident. Start with email, because whoever controls your email can reset everything else.

2
4 minutes

Audit who has access

Open your key accounts and look at who else can get in. Check the manager list on your Google Business Profile, the users on your website and hosting, and the connected apps and access tokens on your Google and Microsoft accounts. Remove anyone you do not recognize, plus old agencies and former employees. Stale access is exactly how listings and sites get hijacked.

3
2 minutes

Set the verify-on-a-second-channel rule

Make it a standing rule for yourself and your team: any request involving money, bank details, or a login gets confirmed by voice on a number you already have, never the one in the message. This one habit defeats nearly every AI-powered phishing scam, even the flawless ones, because the whole trick depends on rushing you into acting without checking.

4
3 minutes

Check your live site and backup

Open your website in a browser and make sure it looks right, with no strange pop-ups or content you did not add. If you can, view the page source and confirm nothing extra was slipped in near the bottom. Then confirm you have a recent backup stored somewhere separate, and that you actually know how to restore it. A good backup turns a scary incident into a routine cleanup.

5
3 minutes

Brief your team and your customers

Tell your team the two rules that matter: never read a verification code back to a caller, and pausing to verify a request is always encouraged, never punished. Then give your customers one line too, ideally on your site or in your emails: we will never ask you to pay or log in through a link we text you, and a real verification step never asks you to run commands. Clear expectations make a fake obvious.

One Bonus Step If You Have Ten More Minutes

If you want to go one level deeper, set up email authentication for your domain, the SPF, DKIM, and DMARC records. This stops scammers from easily sending email that looks like it came from your business, which protects both your team and your customers from impersonation. It is a bit more technical than the rest, so it is the one item where a quick hand from a web partner is worth it.

That is the whole list. Two-factor on, access cleaned up, a verify rule in place, your site and backup checked, and your people briefed. Fifteen minutes buys you protection against the attacks that actually take businesses down.

Want the Full Story on Any of These?

Each step above is drawn from a deeper guide. If one hit close to home, read the full breakdown:

You will never regret the fifteen minutes. Plenty of business owners have regretted skipping it.

Print This. Check the Boxes.

Done in one sitting, or one item a day for a week. Either way, get them all.

  • Two-factor authentication is on for email, banking, Google, and website tools.
  • I have removed any account or profile access I do not recognize.
  • My team knows to verify money and login requests on a second channel.
  • My site looks right and I have a recent, restorable backup.
  • My team and customers know how I will and will not contact them.

Want us to run this check for you and lock it all down? Get a free audit →