കേരളത്തിലെ ചെറുകിട ബിസിനസുകൾക്കുള്ള 2026 സൈബർ സുരക്ഷാ ചെക്ക്ലിസ്റ്റ്: അക്കൗണ്ട്, പേയ്മെന്റ്, ബാക്കപ്പ്.
Cybersecurity for a Kerala small business is not a security operations centre. It is a short list of controls that prevent the incidents already happening on MG Road and in small hospitals: taken-over WhatsApp accounts, fake payment pages, and a laptop with no backup. This checklist is defensive. It does not describe how attacks are built.
Accounts and access
- A password manager for the owner and anyone who touches email, ads, or banking. No shared “Shop@123”.
- Multi-factor authentication on Google, Meta, email, and net banking.
- Work and personal WhatsApp separated. The business catalog number is not the owner’s private chat with family.
- When a staff member leaves, remove them from ads, Instagram, and the billing tool the same day.
If a marketer runs your ads, apply the same ownership rule as in the freelancer hiring guide: the account stays yours.
Payments and staff habits
- Never share an OTP, even with someone who claims to be the bank or a courier.
- Confirm new supplier account numbers by a known phone call before you change a beneficiary.
- Treat unexpected “Google Ads billing” or “GST refund” links as fake until you open the real site yourself.
- Turn on automatic updates for phones and the shop PC. Replace machines that can no longer receive updates.
Backups and a one-page incident note
Keep a copy of customer and accounts data off the shop computer, updated at least weekly, and test that you can open it. Write down who to call if the WhatsApp business account is lost: your telecom provider, Meta’s recovery flow, and your bank.
This is also why a lead-generation website should not be the only copy of your enquiry list. Export form leads.
If a vendor proposes blockchain as your security programme, read blockchain versus hype first. A ledger does not replace passwords and backups.
Frequently Asked Questions
What is the minimum cybersecurity checklist for a Kerala shop or clinic?
Unique passwords in a manager, multi-factor authentication on email and banking, updates turned on, staff who know not to share OTPs, a backup, and a named person who can lock accounts if a phone is lost.
Do small businesses get targeted?
Yes. The common incidents are WhatsApp account takeovers, fake payment links, ransomware on an unpatched PC, and invoice fraud. You do not need to be a large company.
Is antivirus enough?
No. Most losses start with a person approving a prompt or reusing a password. Antivirus does not stop that.