Log in
Home / Publications / No. 043
You do not have an IT department and you are not going to build one. Here are six measures, ranked by what they actually prevent for a business of your size.
Position as at August 2026
Email is the target, because email is where money gets redirected.
An attacker in your mailbox reads how you do business, then sends a request that looks entirely normal. Usually a change of bank details.
Two-factor authentication stops most of it, and it is free.
Turn it on for every account, and for your accounting system while you are there.
Not technically a security measure. It is the single most effective control against the attack most likely to cost you money.
Any change to a supplier's bank details gets verified by phone, on a number you already held. Not the number in the email.
Write it down as a rule so it does not depend on who is at the desk.
Most businesses have backups. Far fewer have restored one.
Pick a date three months ago and ask someone to restore your accounting data as it stood then. Time it. Check it is complete.
That test tells you more than any policy. Common failures: the backup did not include the accounting database, it was to a drive attached to the same machine, or it is a sync rather than a backup and faithfully copied the encryption.
On the day, not the month after.
Email, accounting system, shared drives, banking, and any subscription in their name.
Keep a list of every system and who has access. Most small businesses cannot produce one, and the exercise of trying is worth the afternoon.
Attacks mostly use known problems that were fixed months ago and never applied.
Turn on automatic updates for operating systems, browsers and anything internet facing. Boring, effective.
If a system cannot be updated because something depends on the old version, that is a risk you should know you are carrying.
Day to day work in a standard account limits what any single mistake can do.
Low effort, and it reduces the impact of everything else on this list.
Expensive monitoring tools nobody reads.
Security policies written to look complete rather than to be followed.
Awareness training that is a slide deck once a year. One clear rule about bank detail changes beats an hour of general advice.
Speed matters. Call the bank immediately if money has moved, and ask about recall. Hours count.
Assume the mailbox is still compromised. Check for forwarding rules quietly set on mailboxes, which is how attackers keep reading after a password change.
Report it. Preserve rather than tidy.
Two-factor authentication, phone verification of bank changes, and a tested backup cover most of what will actually happen to a business your size.
Do those three before anything else on any list.
We hold client accounting data and we get asked about our own arrangements, which is a fair question to ask any firm handling your books.
Have a question on this?
AskCALX searches the official corpus and answers with the article quoted, word for word.
Newsletter
Latest in UAE business, tax and technology, once a month.
Thank you, you are on the list.
Office 1316, Aspin Commercial Tower
Sheikh Zayed Road, P.O. Box 10415, Dubai
Open in Google Maps →