You don't need an IT department or a big budget to be a hard target. Most small-business breaches come down to a handful of gaps, and closing them is mostly free. Here is the checklist, in order of impact, in plain language for the owner or office manager who has an hour and wants to spend it well.
The highest-impact small-business email security steps are free or nearly so: turn on multi-factor authentication everywhere, adopt a written rule that any payment or bank-detail change is verified by phone, publish SPF/DKIM/DMARC for your domain, and give staff a short, plain briefing on phishing and wire fraud. Most breaches begin with one stolen password or one unverified payment request — these steps close both doors. Paid tools are useful layers on top, not the foundation.
With the foundation in place, paid layers add real value: advanced phishing protection (Safe Links, sandboxing), endpoint protection on your computers, and email monitoring that reads the intent of messages your filter waves through. These are worth money — but only after the free basics above, which do most of the work.
Sources & further reading: CISA small-business cyber guidance · FTC Cybersecurity for Small Business · FBI IC3 (ic3.gov) · Verizon 2025 Data Breach Investigations Report. Educational only; not a substitute for advice tailored to your business.
Turn on multi-factor authentication for every account, starting with email. Most breaches of small businesses begin with one stolen or reused password, and MFA blocks nearly all of those attempts. It is free with every major email provider and takes minutes per account.
Less than most owners expect. The highest-impact steps — multi-factor authentication, a written payment-verification rule, publishing SPF/DKIM/DMARC, and staff awareness — are free or included with the email service you already pay for. Paid add-ons like advanced phishing protection or monitoring are optional layers on top, not the foundation.
Yes, and often precisely because attackers expect weaker defenses than at a large company. Small businesses are hit hard by business email compromise, invoice fraud, and account takeover. The attacker does not need you to be famous — they need you to move money and to lack a verification habit, which describes most small firms.
Spend it turning on multi-factor authentication for every account, and writing one rule everyone follows: no new or changed bank detail is paid without a phone call to a number you already had on file. Those two actions, done in an hour, remove a large share of the real-world risk.
You don't need a paid platform. Hold a 20-minute talk with real examples: show the scams aimed at your business (fake invoices, a “CEO” gift-card request, a bank-detail change), state your payment-verification rule out loud, and make clear that anyone who pauses to verify will be thanked, never blamed. Give people a simple way to report a suspicious message and repeat the briefing a couple of times a year. The FTC publishes free small-business phishing materials you can hand out.
It handles the obvious junk and known malware, but the costliest small-business email fraud carries no link and no attachment — a plain request to change a bank account or wire a payment. A spam filter has nothing technical to catch there. That is why the free process controls on this list, especially the payment-verification rule, matter more than any filter, and why an intent-aware layer is a useful addition on top.
Once the basics are in place, Family Sentinel's Org Guard adds the piece filters miss — it reads what a message is actually asking for, watches for wire and new-payee language and lookalike domains, and alerts a person you choose before the money moves. Read-only by design.