Skip to content

Island-wide delivery, free over Rs 25,000 Installation across the Central Province

GuidesSecurity & CCTV

Cybersecurity Basics Every Sri Lankan SME Should Have

Passwords and MFA, updates, backups, antivirus, phishing awareness and secure Wi-Fi: the basic controls that make a small business a much harder target.

Most cyber attacks on small businesses are not sophisticated. They rely on reused passwords, convincing fake messages and software that has not been updated. The good news is that a handful of basic controls makes you a much harder target. Here is a practical checklist for small and medium businesses in Sri Lanka.

1. Strong passwords and multi-factor authentication

  • Use a password manager so everyone can have long, unique passwords without writing them down.
  • Turn on multi-factor authentication (MFA) for email, banking, accounting, social media, your website and your domain account.
  • Prefer an authenticator app or security key to SMS codes where possible, and never share one-time codes with anyone who calls or messages you.
  • Give each staff member their own account instead of sharing one login.

2. Keep everything updated

Turn on automatic updates for Windows, macOS, phones and browsers. Do not forget routers, CCTV recorders and website plugins, which are often left untouched for years. Plan to replace systems that no longer receive security updates. Windows 10, for example, reached the end of support in October 2025.

3. Back up, and test your backups

Follow the 3-2-1 rule: three copies of important data, on two types of storage, with one copy off-site. Keep at least one copy offline or immutable so ransomware cannot reach it, and test a restore every few months.

4. Protect every device

  • Use reputable antivirus or endpoint protection. Microsoft Defender is built into Windows, and business versions add central management and alerts.
  • Encrypt laptops with BitLocker or FileVault, so a stolen laptop does not mean stolen data.
  • Set screens to lock automatically.
  • Use licensed software only. Cracked programs are a well-known route for malware.

5. Train your team to spot phishing

Phishing arrives by SMS and WhatsApp as well as email. In September 2026, Sri Lanka Police warned about a fake website imitating the government’s GovPay platform, promoted to motorists through SMS and WhatsApp links. Teach staff to watch for:

  • Urgent requests to pay, log in or “verify” an account.
  • Links to web addresses that look almost right.
  • Unexpected changes to a supplier’s bank details. Always confirm by calling a number you already have.
  • Requests for one-time codes, passwords or card details.

6. Secure your Wi-Fi and network

  • Change the router’s default admin password and keep its firmware updated.
  • Use WPA2 or WPA3 encryption with a strong Wi-Fi password.
  • Give customers and visitors a separate guest network.
  • Put CCTV and smart devices on their own network where possible, and do not open recorder ports to the internet. Use the manufacturer’s app or a VPN for remote viewing.
  • Turn off WPS and remote management if you do not need them.

7. Control who has access

Give people access only to what they need. Use standard user accounts for daily work and keep administrator accounts for IT tasks. When someone leaves, disable their accounts and change any shared passwords the same day.

Personal data and the PDPA

The Personal Data Protection Act, No. 9 of 2022 sets rules for handling personal data, and its provisions on processing personal data and on controllers and processors come into operation on 1 January 2027. Start by listing the personal data you hold, such as customer details, staff records and CCTV footage. Keep only what you need and protect it with the controls above. For your specific obligations, check the Data Protection Authority’s guidance or speak to a lawyer.

If something goes wrong

  1. Disconnect the affected device from the network.
  2. Call your bank straight away if payments or card details are involved.
  3. Change passwords from a clean device, starting with email.
  4. Contact your IT support provider and report the incident to Sri Lanka CERT.

Frequently asked questions

Is free antivirus enough for a small business?

Built-in protection such as Microsoft Defender is a solid baseline. As you grow, business endpoint protection adds central management, so you can check every device in one place. Updates, MFA and backups matter just as much.

What is multi-factor authentication?

MFA asks for a second proof of identity, such as a code from an app, as well as your password. Even if a password is stolen, an attacker usually cannot sign in without that second factor.

How often should staff have security training?

Short refreshers every few months work better than one long session a year. Share real examples, such as fake payment requests or look-alike websites, when they appear.

Our cybersecurity services help small businesses put these basics in place, from MFA and device protection to secure Wi-Fi and backups. To talk it through, call our Kandy team on +94 72 299 9915 or email info@eudora.lk.

#cybersecurity #mfa #passwords #pdpa #phishing

Share
Written by the Eudora team

Eudora Technology is a Kandy-based team working on CCTV, networks, IT support, cloud and websites for homes and businesses across Sri Lanka.

Keep reading

Tech tips, offers and security alerts

A short email about twice a month. No spam, unsubscribe any time.