Last month, an Albertan contractor lost $47,000 when someone gained access to their business email and rerouted client payments. The business had antivirus software. They had a firewall. But they missed three basic security practices that would have stopped the theft completely.
Small business owners face a peculiar challenge with IT security. You need protection strong enough to stop real threats, but you can’t dedicate full-time staff to managing it. The question isn’t whether you’ll face security risks, it’s whether you’ll have the right systems in place when they arrive.
The Real Threats (And Where They Actually Come From)
Cyberattacks on small businesses increased by 150% between 2020 and 2023, but most breaches don’t come from sophisticated hackers. They come from employees clicking links in fake emails, using weak passwords, or accessing business systems on unsecured networks.
Think of IT security like locking your office doors. You wouldn’t leave your building unlocked overnight, but many businesses leave their digital doors wide open. The difference is that physical break-ins are obvious. Digital ones can go unnoticed for months.
The Three Systems That Matter Most
- Password Management
Every employee needs a password manager. Not suggestions about creating better passwords, an actual tool like 1Password or Bitwarden that generates and stores complex passwords automatically. 81% of data breaches involve weak or stolen passwords, making this single change one of the most effective security measures you can implement.
When passwords are hard to manage, people reuse them. When someone reuses their Facebook password for your accounting software, you’ve handed attackers a direct route into your financial systems. A password manager costs less than $10 per employee per month and removes the friction that leads to weak security habits.
2. Multi-Factor Authentication (MFA)
This is the second lock on your door. Even if someone steals a password, MFA requires a second form of verification (usually a code sent to a phone or generated by an app). MFA blocks 99.9% of automated attacks.
Set it up on every system that handles money or sensitive data: your banking, accounting software, email, and payroll systems. The extra ten seconds to log in becomes irrelevant the first time it stops an unauthorized access attempt.
3. Regular Software Updates
Outdated software is like a door with a known broken lock that you haven’t fixed yet. Attackers scan for these vulnerabilities systematically. When you delay updates, you’re gambling that your business won’t be the next target.
Set systems to update automatically when possible. For critical business software, schedule updates during slow periods and test them first on a single machine. The brief inconvenience of updating prevents the major disruption of a breach.
What This Means for Your Financial Records
As accountants, we see the aftermath of security breaches regularly. Clients face not just the immediate theft, but months of work reconstructing financial records, notifying affected parties, and managing regulatory requirements.
Good bookkeeping practices matter here. When your financial data is organized and backed up, you can recover from a breach faster. When it’s scattered across multiple systems with unclear access controls, a breach becomes a catastrophe.
Consider how your current setup handles these questions:
- Who has access to your financial software, and does each person need it?
- When someone leaves your company, do you have a system for immediately removing their access?
- Are your financial records backed up automatically, and have you tested restoring from those backups?
These aren’t IT questions, they’re business continuity questions. Strategic financial planning includes preparing for digital disruptions just as you would prepare for equipment failures or supply chain issues.
Starting Today
Pick one system to implement this week. If you already use password managers, add MFA to your most sensitive accounts. If you have both, audit who has access to what and remove unnecessary permissions.
Security isn’t about perfection. It’s about making your business harder to breach than the next target. Most attacks succeed because they find the easiest path, the business that hasn’t implemented basic protections.
The contractor who lost $47,000 had strong security in some areas but gaps in others. The attackers found the gaps. Your goal is to close enough gaps that attackers move on to easier targets.
Need help reviewing your financial systems and access controls? Our business consulting services include practical guidance on protecting your financial data and building systems that support both growth and security.
McNabb Lucuk LLP – Chartered Professional Accountants
201 – 10712 100 Street, Grande Prairie, AB T8V 3X8
780-539-3400 | [email protected]

