Cybersecurity Basics for a One-Person Business: Ten Habits and Why Layers Work
Ten practical security habits for freelancers and solo operators, based on CISA and FTC guidance, with a model showing why layered defenses add up.

A one-person business has no IT department, and attackers know it. Small operators hold valuable things: bank access, client files, customer data and an email account that can reset almost every other password. Protecting them does not require expensive tools. It requires a short list of habits, done consistently.
Key takeaways
- CISA's "Secure Our World" program boils personal and small-business protection down to four steps: strong unique passwords with a password manager, multi-factor authentication, software updates, and recognizing and reporting phishing.
- Your email account is the master key, since password resets go there. Protect it first.
- Layers add up. No single control stops everything, but each one removes a share of attacks that would otherwise succeed.
- Backups turn ransomware and hardware loss from a disaster into an inconvenience.
- If a client's data is involved, you may have contractual and legal duties to protect it and to report an incident. Read your contracts.
What "basic cybersecurity" means
The practices that protect your accounts, devices, data and money from theft, damage or misuse by other people, and that let you recover if something goes wrong.
It is less about exotic hacking and more about ordinary failures: a reused password, a rushed click on a fake invoice, an out-of-date laptop, a lost phone with no lock.
The problem: small targets, few defenses
Attackers do not need to know who you are. Automated tools scan for weak passwords, exposed accounts and unpatched software at scale, and phishing emails go to thousands of addresses at once. A freelancer is a good target for a simple reason: valuable access with little monitoring.
The challenge: nobody is watching but you
In a company, someone runs updates, enforces multi-factor authentication and investigates suspicious emails. Solo, all of that is you, on top of billable work. Security therefore has to be cheap in time, done once where possible and automatic thereafter.
The gap: knowing what matters most
Security advice is often a long list with no order. What helps most is knowing which controls protect against the most common ways in. The FTC's small-business guidance and CISA's programs point to the same basics, in roughly this order of value:
| Habit | What it stops | Effort |
|---|---|---|
| Multi-factor authentication on email, banking and key tools | Stolen or guessed passwords being enough on their own | One-time setup, seconds per login |
| Password manager with unique passwords | Credential stuffing after a breach elsewhere | Hours to set up, then saves time |
| Automatic updates | Attacks on known, already-fixed flaws | Turn on once |
| Phishing awareness | Fake invoices, fake logins, urgent requests | Ongoing habit |
| Backups (3-2-1) | Ransomware, theft, hardware failure | Set up, test quarterly |
| Device lock and disk encryption | Lost or stolen laptops and phones | One-time setup |
| Least access | One compromised account exposing everything | Reviews now and then |
The plot: why layers work
Suppose an attacker's attempt succeeds against a device with no defenses, and each additional independent control stops a share of attempts. If each stops half, the chance that an attempt gets through falls like this:
Illustrative model, not a measurement. It assumes each control independently stops 50% of attempts. Real controls differ in strength and often overlap, so the true numbers vary. The shape of the curve, not the exact figures, is the point.
The lesson: four modest habits do far more than one perfect one. The model also flags a limit. Controls only add up when they fail independently, so two controls that rely on the same weak point, such as the same email account, count closer to one.
Strategy: ten habits, in priority order
- Turn on multi-factor authentication for email, banking, payment tools, domain registrar, cloud storage and client systems.
- Use a password manager and unique long passwords. See our guide to password managers for freelancers.
- Update automatically: operating system, browser, apps, router and phone.
- Back up to the 3-2-1 rule and test a restore. See cloud backup for freelancers.
- Learn the signs of phishing: urgency, unexpected attachments, mismatched sender addresses, requests to change bank details.
- Verify money changes out of band. If a client "changes their bank account", confirm by phone using a number you already had.
- Lock and encrypt devices with a screen lock, full-disk encryption and remote wipe.
- Separate work and personal browsers, profiles or accounts where practical, and keep shared family devices away from client files.
- Limit access: give contractors and clients only what they need, remove them afterwards, and do not share passwords.
- Plan for a bad day: know who to call (bank, clients, insurer), how to reset accounts, and where your recovery codes are.
Step-by-step: a two-hour setup
- Hour one, accounts. Secure your primary email first: change to a long unique password, turn on multi-factor authentication, save recovery codes offline. Repeat for bank, payments, cloud storage and domain.
- Install a password manager and let it capture logins as you go.
- Hour two, devices. Turn on automatic updates, disk encryption and a screen lock on laptop and phone. Check that "find my device" or equivalent is on.
- Start a backup using the 3-2-1 rule.
- Write a one-page incident sheet: numbers for your bank and card issuers, where recovery codes are, steps to change key passwords, and which clients to notify.
- Put a quarterly reminder in your calendar to review access and test a restore.
If something goes wrong
- Disconnect the affected device from the network, but do not wipe it yet if you may need evidence.
- Change passwords from a clean device, starting with email, and revoke unknown sessions.
- Tell your bank if money or card details may be exposed.
- Report it. The FTC's IdentityTheft.gov and the FBI's Internet Crime Complaint Center (IC3) take reports from US victims.
- Tell affected clients promptly. Contracts and laws may require notice, and honesty protects the relationship.
Common mistakes
- Protecting bank accounts but not the email address that resets them
- Reusing the same password for "unimportant" accounts
- Postponing updates for weeks
- Assuming small businesses are not targeted
- Paying an unexpected invoice or changing bank details without checking
- Keeping the only backup connected to the computer
Frequently asked questions
Do small businesses really get targeted?
Yes. Attacks are often automated and do not select victims by size. Small operators tend to have fewer defenses, which can make them easier to attack. CISA and the FTC both publish security guidance aimed at small businesses.
What is the single most useful thing I can do?
Turn on multi-factor authentication on your email and banking, and use unique passwords through a password manager. Those two steps address the most common ways accounts are taken over.
Do I need antivirus software?
Modern operating systems include built-in protection. Keep it on and updated, avoid pirated software and unknown attachments, and add further tools only if you understand what they cover.
How do I spot a phishing email?
Watch for urgency, unexpected attachments or links, sender addresses that look almost right, and requests to change payment details or reveal a code. When unsure, contact the sender by a separate route.
Should I buy cyber insurance?
It may be worth pricing, especially if you handle sensitive client data, but it does not replace security habits. Read what a policy excludes and what it requires of you. See also our guide to [liability insurance for freelancers](/blog/business-liability-insurance-freelancers).
Sources and further reading
- CISA: Secure Our World — Four core steps: strong passwords, multi-factor authentication, updates, phishing
- CISA: Turn On MFA
- CISA: Recognize and Report Phishing
- FTC: Cybersecurity for Small Business — Small-business guidance and checklists
- FBI Internet Crime Complaint Center (IC3) — Where to report internet crime
Educational content, not professional security or legal advice. Follow your clients' security requirements and seek qualified help after any serious incident.


