<?xml version='1.0' encoding='utf-8' ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<title>Dr. Justin K Joshuva | Updates</title>
<description>Dr. Justin K Joshuva | Updates</description>
<dc:creator>Dr. Justin K Joshuva</dc:creator>
<pubDate>Sat, 19 Sep 2026 10:45:56 +0000</pubDate>
<lastBuildDate>Sat, 19 Sep 2026 10:45:56 +0000</lastBuildDate>
<link>https://justinkjoshuva.com</link>
<atom:link href="/feed.xml" rel="self" type="application/rss+xml"></atom:link>
<language>en</language>
<item>
<title>5 Cybersecurity Mistakes Small Business Owners Make—and How to Avoid Them.</title>
<link>https://justinkjoshuva.com/blog/5-cybersecurity-mistakes-small-business-owners-make-and-how-to-avoid-them</link>
<dc:creator>Dr. Justin K Joshuva</dc:creator>
<guid isPermaLink="false">https://justinkjoshuva.com/blog/5-cybersecurity-mistakes-small-business-owners-make-and-how-to-avoid-them</guid>
<category>Blog</category>
<pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate>
<description>Blog post.</description>
<content:encoded>&lt;![CDATA[ &lt;p&gt;Running a small business means balancing customers, employees, invoices, and countless daily decisions. Cybersecurity can easily become something you plan to handle “when things slow down.”&lt;/p&gt;&lt;p&gt;But everyday habits—how you sign in, approve payments, and save files—can leave your business exposed.&lt;/p&gt;&lt;p&gt;You do not need to solve everything at once. Start by addressing these five common mistakes.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;1. Reusing the Same Password&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Using one password for your email, accounting software, and online store may feel convenient. The problem is that a breach at one service can put your other accounts at risk. Criminals can try stolen usernames and passwords on additional websites.&lt;/p&gt;&lt;p&gt;A slightly modified password is not a reliable solution either. Changing “Business2026!” to “Business2027!” creates a predictable pattern.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What to do instead:&lt;/strong&gt; Use a unique, long password for every account. A password manager can generate and store passwords so you do not have to memorize them all. Protect the password manager itself with a strong master password and multifactor authentication.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Start today:&lt;/strong&gt; Replace any reused password on your business email account. Email often controls password resets for your other services.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;2. Skipping Multifactor Authentication&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;A password alone provides only one barrier between an attacker and your account. If it is stolen through a scam or exposed in a breach, someone else may be able to sign in.&lt;/p&gt;&lt;p&gt;Multifactor authentication, or MFA, adds another verification step. Depending on the service, this might involve an authenticator app or a security key.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What to do instead:&lt;/strong&gt; Enable MFA on your email, financial services, cloud storage, and administrator accounts. When available, choose phishing-resistant options such as security keys or appropriately configured passkeys. Store recovery codes somewhere secure.&lt;/p&gt;&lt;p&gt;Never approve a sign-in request you did not initiate.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Start today:&lt;/strong&gt; Open your email account’s security settings and check whether MFA is enabled.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;3. Trusting Urgent Payment Requests&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;An email arrives from someone who appears to be your supplier: “Our bank details have changed. Please send today’s payment to this account.”&lt;/p&gt;&lt;p&gt;The message looks professional. It may even appear in a familiar conversation. That does not prove the request is legitimate—an account could have been compromised.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What to do instead:&lt;/strong&gt; Verify new payment instructions through a separate, trusted channel. Call the supplier using a number already in your records, rather than a number supplied in the suspicious message.&lt;/p&gt;&lt;p&gt;Establish a clear rule: changes to bank details require independent verification. For larger payments, consider requiring a second person’s approval.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Start today:&lt;/strong&gt; Tell everyone who handles payments that urgency never removes the need to verify.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;4. Delaying Software Updates&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;It is tempting to dismiss an update notification when you are busy. However, updates often fix security weaknesses as well as improve features.&lt;/p&gt;&lt;p&gt;Leaving software outdated can leave known weaknesses available for attackers to exploit.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What to do instead:&lt;/strong&gt; Enable automatic updates where practical. Schedule updates that require downtime, and remember devices beyond your main computer: phones, routers, and other connected equipment also need attention.&lt;/p&gt;&lt;p&gt;If a product no longer receives security updates, plan to replace it or move to supported software.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Start today:&lt;/strong&gt; Check your operating system and web browser for pending updates.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;5. Keeping Backups Without Testing Them&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Having files in cloud storage does not automatically mean you have a recovery plan. Synchronization can copy unwanted changes or deletions, and a backup accessible through a compromised account may also be vulnerable.&lt;/p&gt;&lt;p&gt;A backup is useful only if you can restore the information you need.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What to do instead:&lt;/strong&gt; Keep separate backups of essential business data. Include an offline copy or a backup protected against alteration, and secure backup access separately where possible.&lt;/p&gt;&lt;p&gt;Test recovery periodically. Restore a sample file to a separate location, open it, and confirm that it contains the expected information. Also consider how you would recover your business applications—not just individual documents.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Start today:&lt;/strong&gt; Choose one important file and verify that you can recover it from a backup.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Make One Improvement Today&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Choose one action from this article and complete it before the day ends. Then assign someone responsibility for the next step.&lt;/p&gt;&lt;p&gt;Consistent habits can reduce avoidable risks and make recovery easier when something goes wrong. The goal is steady progress supported by clear procedures your team can follow.&lt;/p&gt;&lt;p&gt;For more practical guidance, explore my book, &lt;em&gt;Outsmart the Cybercriminals: The Small Business Owner’s Practical Guide to Preventing Scams, Ransomware, and AI-Powered Fraud… Without an IT Department.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://a.co/d/0bHYFnax&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;strong&gt;Buy on Amazon&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Subscribe to my newsletter for practical cybersecurity tips and updates on my writing.&lt;/p&gt; ]]&gt;</content:encoded>
<media:content height="400" medium="image" url="https://res.cloudinary.com/wellfleet/image/upload/5e64irs4fyhr4l7i6t45kvizxt4e.png" width="600"></media:content>
</item>
</channel>
</rss>
