Two businesspeople standing behind a desk working on a laptop.

Protect your business from cyber threats

Updated June 25, 2026 . AmFam Team

Running your business’s sales operations from the cloud can be an efficient way to manage accounts and generate revenue. But convenience can come with risk: If you and your team don’t understand where you’re vulnerable, a simple mistake can open the door to a cyberattack.

“Cyberthreats are a very real problem for small businesses,” says Robert Siciliano (Opens in a new tab), fraud prevention specialist and author of 99 Things You Wish You Knew Before Your Identity Was Stolen. “This is why educating and training your employees about cybersecurity is paramount.”

Think you know what it takes to keep your business safe? Here are five common cybersecurity myths—plus the truths that may help you lower your risk.

Myth 1: Small businesses are too small to be targeted.

Truth: All companies have vulnerable data. “Every business is a target regardless of size,” Siciliano says. Credit card numbers, employee Social Security numbers, proprietary data, trade secrets, and even bank accounts can be accessed by criminals.

What to do: Consider bringing in a qualified data security professional to test your current system, identify possible weak points, and recommend fixes.

Myth 2: Employees aren’t a security risk.

Truth: Many incidents start with a human element. Even great employees make mistakes that can adversely affect your company—clicking a risky link, reusing a password, or accidentally disabling a firewall and giving network access to a cyber intruder. Also, while it’s uncomfortable to think about, insider threats are possible too. “There can be malicious intent by disgruntled employees,” says Siciliano. In rare cases, a bad actor may even seek employment to gain network access.

What to do:

  • Use screening practices, like background checks, where permitted.
  • Limit access to sensitive systems based on role.
  • Consider monitoring tools to flag unusual activity and risky behavior.

Myth 3: Cybersecurity is only an online problem. 

Truth: Digital security starts with physical security. Online defenses matter, but data security should start within the walls of your company. “The desktops must be secure, the perimeter protected, and video cameras should be installed,” Siciliano says.

What to do:

  • Lock up sensitive documents, and don’t leave passwords in plain sight.
  • Require strong passwords and set devices to lock automatically when unattended.
  • Verify visitors and limit access to work areas.
  • Work with a locksmith or security expert to add access-control measures.

Myth 4: Security training is one and done. 

Truth: Training needs to keep up with changing threats. Technology evolves fast, and so do scams. According to Siciliano, training should be “ongoing, perpetual, and forever.”

What to do:

  • Host short, regular refreshers—not just annual training.
  • Teach employees how to spot phishing and social engineering.
  • Run internal test phishing exercises and follow up with coaching.
  • Use quick, quarterly quizzes to keep good habits top of mind.

Myth 5: Shredding paperwork will protect your company.

Truth: Shredding helps, but it only addresses one layer of the problem. While a shredder may help protect you from “dumpster divers,” it won’t prevent hackers from accessing your data digitally.

What to do: Keep shredding, but prioritize secure systems, access controls, updated software, and employee training.

Make security part of how you do business

After your team learns the basics, the real goal is consistency. “Once employees go through an initial training program, it’s up to company leaders to make sure employees retain this information and, more importantly, apply it,” says Siciliano.

Want more practical ways to strengthen your business? Check out our business resource center. And if you’d like to explore coverage options for your business, connect with an agent today to learn more.

This article is for informational purposes only. The information is widely available through different sources. This information does not, and is not intended to, constitute legal advice. Compliance does not guarantee conformity with building codes, or federal, state, or local laws and regulations, nor does it guarantee coverage. We do not make any guarantees or promise any results based on this information. We are not responsible for the content of any third-party sites that may be linked in this article. The loss control services listed above follow generally accepted safety standards. Compliance does not guarantee that you will be in conformance with any building code, or federal, state, or local regulations regarding safety or fire. Compliance does not ensure the absolute safety of your operations or place of business.

Tools & resources

Explore our tools and smart tips.