---
title: "SMB Security: 3 Steps To Protect Online Businesses Against Cybercrime"
description: Learn three easy steps small businesses can take to protect against cybercrime.
image: https://blog.pcisecuritystandards.org/hubfs/2016_Blog/bike-shop.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/3-steps-to-protect-online-businesses-against-cybercrime#)

# [SMB Security: 3 Steps To Protect Online Businesses Against Cybercrime](https://blog.pcisecuritystandards.org/3-steps-to-protect-online-businesses-against-cybercrime)

 Posted by [Elizabeth Terry](https://blog.pcisecuritystandards.org/author/elizabeth-terry) on 29 Nov, 2016 in [Software Product Family](https://blog.pcisecuritystandards.org/topic/software-product-family) and [Small Business](https://blog.pcisecuritystandards.org/topic/small-business) and [Holidays](https://blog.pcisecuritystandards.org/topic/holidays) and [eCommerce](https://blog.pcisecuritystandards.org/topic/ecommerce) and [Breaches](https://blog.pcisecuritystandards.org/topic/breaches) and [Patching](https://blog.pcisecuritystandards.org/topic/patching) and [Passwords](https://blog.pcisecuritystandards.org/topic/passwords) and [Hackers](https://blog.pcisecuritystandards.org/topic/hackers) and [Phishing](https://blog.pcisecuritystandards.org/topic/phishing) and [Small Merchant Resources](https://blog.pcisecuritystandards.org/topic/small-merchant-resources) and [SMB Series](https://blog.pcisecuritystandards.org/topic/smb-series)

![bike-shop.jpg](https://blog.pcisecuritystandards.org/hs-fs/hubfs/2016_Blog/bike-shop.jpg?width=800&name=bike-shop.jpg "bike-shop.jpg")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/3-steps-to-protect-online-businesses-against-cybercrime>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/3-steps-to-protect-online-businesses-against-cybercrime>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/3-steps-to-protect-online-businesses-against-cybercrime&url=https://blog.pcisecuritystandards.org/3-steps-to-protect-online-businesses-against-cybercrime&source=tweetbutton&text=SMB%20Security:%203%20Steps%20To%20Protect%20Online%20Businesses%20Against%20Cybercrime> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/3-steps-to-protect-online-businesses-against-cybercrime](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/3-steps-to-protect-online-businesses-against-cybercrime)

 

With the holidays around the corner and with 57% of consumers shopping online (National Retail Federation), it is imperative you protect your customers while they shop on your site. And studies show that [**online attacks are increasing**-](https://www.symantec.com/security-center/threat-report) the number of web attacks doubled in 2015. Preventing a breach of your systems can also help you avoid loss of revenue, damage to customer loyalty, and possible fines – all of which can be devastating to a business.

You can make it more difficult for criminals to steal your customers’ data by making sure all the doors are locked and holes repaired in your online environment.

***Here are 3 things you can do NOW to protect your online business against data theft:***

**1. Change your passwords and make them strong!**

- 63% of confirmed breaches involved weak, default or stolen passwords.
- The best way to make it hard for criminals is to use a passphrase instead of a password. A passphrase is a phrase or sentence you use instead of a single word. For example, the phrase “I love big donuts” could be changed to 1l0v3B!GD@nut$.
- Make sure employees know this too.

Read More: **[How Quickly Can a Hacker Crack Your Password?](https://www.pcisecuritystandards.org/pdfs/its_time_to_change_your_password_infographic.pdf)**

**2. Install the updates known as “patches” that your payment service provider sends you for your payment systems.**

- Software vulnerabilities are the main reason for breaches occurring.
- The patches help fix problems found in the system and close a door criminals could use to access your system and steal customer’s data. Keep them out, install the patches.

Read More:  **[Keeping Patches Up-to-Date](https://blog.pcisecuritystandards.org/smb-security-there-is-a-patch-for-that)**

** 3. Think before you click!**

- In a phishing attack, criminals send you an email to try to trick you to click a link or open an attachment. Always verify and confirm with the sender to make sure the email is really from them if it looks suspicious.
- Be extra cautious of email attachments from unknown sources. Also, many viruses can fake the return address, so even if it looks like it’s from someone you know, be wary about opening any attachments.
- Train employees and users on email and browser security best practices.

Read More: **[Learn the Red Flags of a Phishing Attack](https://www.pcisecuritystandards.org/documents/PCI_SSC_Phishing_Resource_Guide_v05.pdf)**

Protecting your customer’s data by doing these three things will go a long way in keeping the hackers out of your systems. Keep the holidays happy – protect your customers!

[![More Small Merchant Tips](https://no-cache.hubspot.com/cta/default/281302/676c01df-473d-4734-9fe9-0e658979157d.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/676c01df-473d-4734-9fe9-0e658979157d)

 

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Elizabeth Terry](https://blog.pcisecuritystandards.org/hubfs/Headshots/Elizabeth-Terry.jpg)

[ Elizabeth Terry ](https://blog.pcisecuritystandards.org/author/elizabeth-terry)

 Ms. Terry has over 25 years’ experience in the payment card industry including over 20 years managing enterprise projects encompassing PCI Compliance, security, system design, implementation and replacement as well as standards development initiatives at PCI SSC. Her responsibilities for the Council have ranged from research and development of new standards to updates to existing standards to address market changes as well as liaising with other regulatory bodies, vendors, labs and academia. Elizabeth served as the chair for both the Mobile Working Group and Mobile Task Force as well as numerous Special Interest Groups in her seven years in the Standards group at PCI. In her current role as the Community Engagement Manger for the Council, her primary objective is to enhance the value of the PCI SSC programs for all participants. She’s also responsible for collaborating with key stakeholders internally and externally to PCI SSC as well as being the contact for stakeholder relationship management. Ms. Terry holds a Master’s in Business Administration and a Bachelor’s in Computer Science and is a current PMP, CISSP, CBSA, PCIP and CDMA.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/3-steps-to-protect-online-businesses-against-cybercrime#)