# Business system security: 10 essential practices that don’t need a big budget

> Most breaches at small and mid-size companies come through weak or leaked passwords, over-privileged accounts, unpatched systems and missing backups. Ten simple practices — including two-factor authentication, least privilege, updates and tested backups — close most of those doors.

Source: https://www.al-arjan.com/en/blog/software-security-basics · العربية: https://www.al-arjan.com/ar/blog/software-security-basics.md

Author: [AUTHOR_NAME] — 2026-09-26

## The ten practices

- Strong passwords and a password manager.
- Two-factor authentication for email, systems and admin panels.
- Least privilege: each person sees only what they need.
- Revoke leavers’ accounts immediately.
- Update systems and libraries regularly.
- Encrypt traffic (HTTPS) and sensitive data.
- Automatic, tested backups.
- An audit log of who did what and when.
- Service and domain accounts in the company’s name, not individuals’.
- Train staff to spot phishing.

## Where to start today

Start with three: enable 2FA on email and admin panels, review the user list and remove leavers, and confirm your latest backup actually restores. These take a day and close the most dangerous gaps.

## Frequently asked questions

### Do we need a penetration test?

For systems holding financial or health data or used by the public, yes — periodically, by an independent party.

---

Contact Al-Arjan: +964 773 545 2792 (phone & WhatsApp, 24/7) — [Request a quote](https://www.al-arjan.com/en/quote)
