I think this is something many sole traders and small business owners quietly assume. Why would anyone target us when there are much bigger companies out there?

The reality is that very small businesses can be particularly exposed because one person may manage almost everything, including the website, business email, customer enquiries, invoices, bookings, social media and banking. Several important parts of the business may ultimately lead back to the same computer, phone and email account.

That is something I am very conscious of when running Basic Computing. It is also something I regularly discuss with people who are unsure whether an email, message or website can be trusted.

One of the biggest changes I have noticed is just how professional scams can now look. They may use the correct branding, convincing language and realistic sign-in pages. They may mention a delivery, invoice, payment or account problem at exactly the kind of moment when someone is already dealing with those things.

That does not mean the person receiving the message lacks common sense. It means the scam has been deliberately designed to fit into an ordinary working day and create pressure before the person has time to assess it properly.

For a sole trader, losing access to an email account could mean losing customer conversations, invoices, password-reset links and access to other business services. Your business email password is not simply another password. It can become the master key to almost everything you operate.

Some of the strongest protections are also relatively simple:

  • Turn on two-step verification.
  • Use a different password for your email than you use elsewhere.
  • Keep your computer and phone updated.
  • Back up important business documents.
  • Never approve an unexpected payment or change of bank details without checking independently.
  • Open important websites yourself rather than signing in through links contained in emails.

I have also seen how embarrassed people can feel when they believe they have clicked something they should not have. That embarrassment can make the situation worse because people delay asking for help.

Cyber security should not be about blaming someone for being fooled by a convincing message. It should be about creating good habits, slowing things down and making it easy to ask for help when something does not feel right.

At Basic Computing, I want to help people understand not only which buttons to press, but how to recognise when something deserves a second look. Small businesses may not have dedicated IT teams, but they can still build strong habits and make themselves much harder to deceive.