A single data breach in India now costs a company an average of โ‚น25.5 crore, and that number has climbed every year for over a decade. For a commerce student, this isn’t just an IT statistic, it’s a business risk that touches finance, operations, and even a company’s ability to survive a bad quarter. The good news is that most breaches are not the result of some unstoppable genius hacker. They happen because a business skipped one of a handful of basic security actions. Six of these actions, in particular, form the backbone of any credible business data protection plan: firewalls, antivirus software, strong passwords, regular backups, penetration testing, and restricted access to critical data. Add employee training to the mix, and you have a security posture that covers both the technology and the people using it.

Table of Contents

Why these six actions matter more than ever

Business data today lives everywhere: on office desktops, employee laptops, mobile phones, and cloud servers. Every one of these is a potential entry point for an attacker. The Indian Computer Emergency Response Team (CERT-In), the national nodal agency for cybersecurity, regularly runs awareness campaigns precisely because most incidents trace back to gaps that were entirely preventable. The six actions covered here are not exotic enterprise tools reserved for large corporations. They are foundational controls that any business, from a college-run startup to a mid-sized firm, can and should put in place.

The six actions at a glance

Security action What it protects against
Firewalls Unauthorised network access
Antivirus software Malware, viruses, and spyware
Complex passwords Account takeover and credential theft
Regular backups Data loss from ransomware or hardware failure
Penetration testing Unknown vulnerabilities in systems
Access restriction Insider misuse and unnecessary exposure

1. Firewalls: controlling what enters and leaves the network

A firewall sits between a business’s internal network and the open internet, filtering traffic based on a set of security rules. Think of it as a checkpoint that decides which data packets are allowed in and which are turned away. According to the Federal Communications Commission’s small business cybersecurity guidance, a firewall is one of the most basic yet effective tools for preventing outsiders from reaching sensitive data stored on a private network.

Most businesses use two layers: a hardware firewall protecting the entire office network, and software firewalls installed on individual devices. This layered approach means that even if one device is compromised, the attacker cannot easily move across the rest of the network. For businesses that have shifted to hybrid work, firewall protection increasingly extends to cloud applications and remote employee connections as well, not just the physical office.

2. Antivirus software: catching what gets through

No firewall is perfect. Malicious files can slip in through email attachments, USB drives, or compromised websites. This is where antivirus software earns its keep. It scans files and programs for known malware signatures and suspicious behaviour, then removes or quarantines threats before they can spread.

The effectiveness of antivirus software depends heavily on how well it is maintained. The FCC’s guidance stresses keeping security software, browsers, and operating systems updated, since outdated antivirus definitions cannot recognise newer threats. A good habit for any business is to automate updates and schedule a full system scan after every major update, rather than relying on employees to remember to do it manually.

3. Complex passwords: the first and weakest line of defence

Passwords remain the most common way businesses authenticate users, and also the most common way attackers get in. The good news is that password guidance has actually become simpler over the past few years. The National Institute of Standards and Technology’s Digital Identity Guidelines now recommend prioritising length over complicated character combinations, allowing long passphrases that are easier for employees to remember and harder for attackers to crack through brute force. Forcing frequent password changes is no longer considered best practice either, since it tends to push people toward weaker, predictable variations of old passwords.

What actually works for a business is straightforward:

  • Length over complexity: A long passphrase beats a short password stuffed with symbols.
  • Unique passwords per account: Reused passwords mean one leaked account compromises several.
  • Password managers: These generate and store strong, unique passwords so employees don’t have to memorise dozens of them.
  • Multi-factor authentication: Even a stolen password becomes far less useful when a second verification step is required.

4. Regular backups: the insurance policy for your data

Ransomware attacks work by locking a business out of its own data until a ransom is paid. The single best defence against this is a reliable backup that lets a business restore its systems without paying anyone. The Cybersecurity and Infrastructure Security Agency (CISA) recommends what is widely known as the 3-2-1 rule: keep three copies of important data, store them on two different types of media, and keep at least one copy offsite or in the cloud.

Backups are only useful if they actually work when needed. It’s worth building in a habit of periodically testing whether a backup can actually be restored, rather than assuming it will work because the backup job ran successfully. Businesses that skip this step often discover the flaw in their backup process during an actual crisis, which is the worst possible time to find out.

5. Penetration testing: finding the cracks before attackers do

Penetration testing, often shortened to “pen testing,” involves hiring security professionals to deliberately try to break into a business’s systems, using the same techniques real attackers would. The goal is to find vulnerabilities and fix them before they can be exploited for real. The U.S. Small Business Administration recommends vulnerability scanning and resilience assessments as a routine part of any business’s cybersecurity strategy, not a one-time exercise.

In India, this practice has a specific regulatory dimension. CERT-In maintains a list of empanelled security auditing organisations that are officially authorised to carry out these assessments for businesses and government bodies. For companies in regulated sectors such as finance or IT services, working with a CERT-In empanelled auditor is often not just good practice but a compliance requirement. Even for smaller businesses outside these sectors, periodic testing helps catch misconfigurations, outdated software, and weak points that day-to-day operations tend to overlook.

6. Limiting access to critical data

Not every employee needs access to every file. The principle of least privilege means giving each person access only to the data and systems required for their specific role, nothing more. CISA’s ransomware response guidance lists restricting access according to this principle as one of the core practices that limits how far an attacker can move once inside a network, even if one account gets compromised.

Practically, this means:

  • Role-based access: Finance staff see financial records; marketing staff see marketing assets.
  • Regular access reviews: Removing permissions when employees change roles or leave the company.
  • Segmented systems: Keeping sensitive databases separate from general-use networks.

This also reduces the damage from human error. If an employee accidentally clicks a phishing link, the blast radius is limited to whatever that one account could access, rather than the entire company’s data.

The human layer: why employee training ties everything together

Even the best firewall or backup system can be undone by a single employee clicking a malicious link or reusing a weak password across accounts. This is why security awareness training is treated as a foundational practice rather than an optional add-on. CERT-In runs national awareness initiatives specifically because building security literacy among users and organisations is seen as essential to reducing incidents at the source, not just responding after they happen.

A practical training programme for a business doesn’t need to be elaborate. Covering how to spot phishing attempts, why password reuse is risky, and what to do if a device is lost or a suspicious email is received goes a long way. Running periodic phishing simulations also helps employees build the instinct to pause and verify before clicking, which is often the difference between a contained incident and a full-blown breach.

Putting it all together

None of these six actions work well in isolation. A firewall without regular backups still leaves a business exposed to ransomware. Strong passwords without restricted access still allow a compromised account to reach everything. The real strength of this framework comes from layering these controls together, so that if one fails, another catches the problem before it becomes a crisis. For a commerce student stepping into a business environment, understanding this layered approach is less about becoming an IT expert and more about knowing what questions to ask, and what basic protections no business should operate without.

What do you think? If you were setting up IT security for a small business from scratch with a limited budget, which of these six actions would you prioritise first, and why? Do you think employee training deserves to be treated as a seventh essential action rather than a supporting practice?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://in.newsroom.ibm.com/India-Records-its-Highest-Average-Cost-of-a-Data-Breach-2026
  2. https://www.cert-in.org.in/PDF/CSA_Booklet.pdf
  3. https://www.fcc.gov/communications-business-opportunities/cybersecurity-small-businesses
  4. https://pages.nist.gov/800-63-4/sp800-63b.html
  5. https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/back-up-business-data
  6. https://www.sba.gov/business-guide/manage-your-business/strengthen-your-cybersecurity
  7. https://www.cisa.gov/stopransomware/ransomware-guide

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Computer Application in Business

1 Introduction to Computer

  1. Overview of Computers
  2. Evolution of Computers
  3. Classification of Computers
  4. Components of a Computer System
  5. Applications of Computers
  6. Advantages and Disadvantages of Computers

2 Application of Computers

  1. Role of Computers in Business Organisation
  2. Computers for Society
  3. Role of Computers in Business, Trade, and Commerce
  4. Computer Role in Online Business
  5. Computer Role in Online Banking and Finance
  6. Importance of Computer Networks

3 Web Applications

  1. Web Browser
  2. Google Drive
  3. What is Google Docs?
  4. File Storage and Synchronization Service
  5. Setting Up of a Google Account
  6. Navigating Google Docs
  7. Creating New Google Docs Projects
  8. Google Sheets
  9. Google Slides
  10. Google Suite
  11. Sharing, Publishing and Collaborating
  12. Google Forms
  13. Cloud Based System

4 Basics of Computer Software

  1. Software and its Types
  2. Windows Operating System
  3. Android Operating System for Mobile
  4. Free and Open Software
  5. Google Play Store
  6. Google Chrome
  7. App Based Software

5 Business Information System

  1. Data and Information
  2. Introduction to Business Information System
  3. Database Management System (DBMS)
  4. Relational Data Base Management System (RDBMS)
  5. Decision Support System (DSS)
  6. Enterprise Resource Planning (ERP)
  7. Management Information System (MIS)
  8. The General Data Protection Regulation (GDPR)

6 IT Security Measures in Business

  1. Why Systems Are Not Secure?
  2. Cyber Security
  3. Identity Theft
  4. Key Security Principles
  5. Six Essential Security Actions
  6. Applying Principles to Information Security Policy
  7. Security Self-Assessment
  8. Digitization
  9. CAPTCHA Code
  10. One Time Password (OTP)

7 Internet Services and E-mail Configuration

  1. About the Internet
  2. Types of Internet Services
  3. About E-mail and its Configuration
  4. Web Browsers
  5. World Wide Web (WWW)
  6. Uniform Resource Locator (URL)
  7. Domain Names

8 Plastic Money, E-Wallet and Online Pay

  1. Origin of Plastic Money
  2. Usage of Plastic Money
  3. E-Wallet
  4. Development of E-Wallet System
  5. E-Payment System in Commerce
  6. Mobile Wallets, Payment & Card Network
  7. Consumer Adoption in Mobile Wallet
  8. Effects of Demonetization on Digital Payment
  9. Success Story of Wallets

9 Basics of Word Processing

  1. Word Processing
  2. Salient Features of MS-Word
  3. Letโ€™s Start MS-Word
  4. Main Menu Options (Tabs in MS Word)
  5. Creating Documents by MS Word

10 Working with Word Processing

  1. File Management in MS Word
  2. Entering and Editing Text
  3. Creating and Managing Tables
  4. Working with Graphics
  5. Working with Google Docs
  6. Comparison between MS Word and Google Docs

11 Advanced Tools Using Word Processing

  1. Meaning of Mail Merge
  2. Components of Mail Merge
  3. How to Merge Mail
  4. Equation Editor
  5. Tracking
  6. References

12 Creating Business Documentation

  1. Creating a Business Report
  2. Using MS Word for Report Writing
  3. Report Finalization
  4. Sample Business Documentation
  5. Creating Detailed Project Report

13 Working with PowerPoint

  1. PowerPoint Basics – Inserting a New Slide
  2. Slide Views
  3. Inserting a Graph & Diagram
  4. Inserting Picture
  5. Inserting Sound
  6. Inserting Video
  7. Saving PPT Files in External Memory & Cloud

14 Multimedia, Video-Making and YouTube

  1. Meaning of Multimedia
  2. Advantages of Multimedia
  3. Usage and Making Multimedia
  4. Challenges Faced in Implementing Multimedia Tool in Business
  5. Doing Designing Using Graphics
  6. Animation
  7. Making Presentation Using Graphics
  8. Making Presentation Using Multimedia
  9. Making Presentation Using Animation
  10. YouTube
  11. Application of YouTube in Business
  12. Uploading a Video through YouTube
  13. Earning Advertisement Revenue from YouTube
  14. Google AdSense
  15. Creating a YouTube Personal Channel
  16. Subscribe Follow YouTube Channel
  17. Uploading Videos on Channel
  18. Create Playlist to Organize Videos
  19. Future of Animation with Artificial Intelligence

15 Creating Business Presentation

  1. Making Presentation with Features of PowerPoint
  2. Making Business Presentation
  3. Making Research Proposal Presentation
  4. Making Project Presentation

16 Spreadsheets Concept

  1. Starting MS Excel
  2. Excel Screen Layout
  3. Excel Menu
  4. Making Worksheets
  5. Data Handling & Editing
  6. Formatting
  7. Cell Comments
  8. Naming Cells and Range
  9. Addressing and Its Types
  10. Organizing Charts and Graphs

17 Formulas and Functions

  1. Formulas
  2. Constructing Formulas
  3. Array Formulas
  4. Functions
  5. Inserting Functions
  6. Built-in Functions
  7. Mathematical Functions
  8. Statistical Functions
  9. Financial Functions
  10. Logical Functions
  11. Text and Formatting Functions
  12. Date and Time Functions

18 Graphical Presentations of Data

  1. Charts and Its Types
  2. Preparing Your Data
  3. Transforming Your Data into Charts
  4. Cross Tabulation and Charting

19 Advanced Options in Spreadsheets

  1. Sorting Data
  2. Filtering Data
  3. Searching Data
  4. Lookup
  5. Referencing
  6. Frequency Distribution Using Array Formulas
  7. Loading Data Analysis ToolPak
  8. Descriptive Statistics
  9. Correlation & Regression
  10. Hypothesis Testing

20 Creating Business Spreadsheets

  1. Loan & Lease Statements
  2. Ratio Analysis
  3. Payroll Statements
  4. Capital Budgeting
  5. Depreciation Accounting