Wiki

FTC Cybersecurity for Small Business

FTC Cybersecurity for Small Business

Summary

The Federal Trade Commission (FTC) provides cybersecurity guidance that focuses on what you need to do to protect your business—and what happens if you don’t. The FTC can take legal action against businesses that fail to implement “reasonable” security measures, so their guidance is both practical and a warning.

What You Need to Know

  • You have a legal duty: The FTC enforces that businesses implement “reasonable” security. If you suffer a preventable breach because you skipped basic protections, you could face fines or legal action.
  • Start with the basics: Multi-factor authentication (MFA), regular software updates, employee training, and data backups cover most threats.
  • Minimize data collection: Only collect and retain the customer data you actually need. Less data stored = less data at risk.
  • Watch your vendors: If a third party (POS vendor, cloud provider, bookkeeper) handles your data, ask them about their security practices.
  • Have an incident response plan: Know how you’ll detect a breach, notify affected parties, and report to authorities if needed.

Take Action Today

  1. Enable MFA on everything — Email, banking, cloud storage, and admin accounts. This alone prevents most account takeovers.
  2. Update your software weekly — Enable auto-updates where possible. Outdated software is the easiest way in for attackers.
  3. Train your staff — Spend 15 minutes discussing phishing red flags (urgent requests, mismatched sender addresses, suspicious attachments).

Sources