Cyber Security for Small Business 101
This course is for the small-business owner in Jordan and the region who is "not technical" but knows their business is exposed — and doesn't know where to start. You do not need to become a cyber-security expert. You need to close the doors criminals actually walk through: your accounts, your devices, your business WhatsApp, your payments, and your customers' data.
The Real Threat: Who Targets Your Small Business and Why
By the end of this lesson you will be able to:
- Dismantle the myth of 'I'm too small to be a target' and understand why small businesses actually get attacked
- Recognize the five attacks that actually hit small businesses in our region, and know which lesson defends against each
- Understand what an attacker specifically wants from a business like yours: money, your accounts as tools, your customer data, or ransom
- Build a one-page asset inventory that the rest of this course is built on
The call that changes how you think
It is 9:40 on an ordinary Tuesday morning in Amman. The owner of a small dental clinic gets a WhatsApp message from a patient: "Doctor, I sent the deposit to the CLIQ alias you messaged me yesterday — when is my appointment?" The clinic never messaged anyone. Overnight, someone took over the clinic's Instagram account and started messaging patients one by one, asking for a "booking deposit." The owner's first thought was the same one nearly every small-business owner has: "Why me? I'm a small clinic — who would bother?"
That question is the reason this course exists, because it carries the most dangerous myth in small-business security.
The myth: "I'm too small to be a target"
Here is the plain truth: in the overwhelming majority of cases, the attacker does not choose you. Software chooses you. Criminal groups run automated tools that try leaked passwords against thousands of accounts, blast phishing messages to enormous mailing lists, and scan websites for outdated plugins. Those tools don't know your name or your size, and they don't care. They are looking for exactly one thing: an unlocked door.
A small shop with a reused password, no two-factor authentication, and a website that hasn't been updated in a year is an easier payday than a bank with a full security team. So flip the sentence in your head: you are not targeted because you are important — you are attacked because you are unprotected. And the good news hiding inside that sentence: since the cause is missing protection, not your importance, a set of simple and mostly free steps takes you off the "easy doors" list. That is exactly what the coming lessons do.
The five attacks that actually hit small businesses
1. Account takeover. The attacker gets into your email, Instagram, or business WhatsApp using a leaked or guessed password, then changes it and locks the door behind them. Like the clinic above: your own account becomes a weapon aimed at your customers. Defense: Lesson 2.
2. Phishing and social engineering. A message pretending to be your bank, a courier, or "Facebook Support": "Your account will be closed, click here." The click leads to a fake page that steals your password — or a call from a "bank employee" asking for your verification code. Defense: Lesson 4.
3. Payment and invoice fraud. A supplier you've worked with for years "changes their bank account number" via a hacked email, or a "customer" sends a doctored transfer receipt and pressures you to hand over goods before the money actually lands. Defense: Lessons 4 and 6.
4. Ransomware and data loss. An attachment or a "cracked" program encrypts every file on the laptop — invoices, customer lists, photos — and demands a ransom to unlock them. Sometimes there's no attacker at all: a laptop dies, a phone gets stolen, and the result is identical if there is no backup. Defense: Lesson 3.
5. Website compromise. Your business website — especially WordPress with old plugins — gets breached automatically and used to host scam links or phishing pages under your name; you may only find out when Google blocks it. Defense: Lesson 5.
What attackers actually want from YOU
Understanding the motive makes every later lesson make sense. An attacker wants one or more of four things. Money, directly — a fraudulent transfer or an altered invoice. Your accounts as tools — your business WhatsApp and Instagram are treasure, because your customers trust them; whoever takes them over scams your customers in your voice. Your customer data — names, phone numbers, and addresses that get sold or used in later scams. Ransom — encrypting your files or holding your account hostage, then charging you to get it back. Notice that three of the four don't require you to be a "big company" — they only require you to have customers who trust you.
Your first task: the asset inventory
You cannot protect what you don't know you own. This lesson's hands-on task is one page, one table, filled in today. You will reuse it in Lessons 2, 3, 5, and 8.
| Asset | Type | Who has access? | Notes |
|---|---|---|---|
| Business Gmail | Account | Just me | The recovery hub for everything |
| Shop Instagram | Account | Me + one employee | Shared password! |
| Accounting laptop | Device | Me | All invoices live here |
| Customer phone list | Customer data | Everyone in the shop | Paper notebook on the counter |
Fill four sections: Accounts (email, social media, banking, Google Business, website/hosting), Devices (every phone and laptop used for work), Where customer data lives (notebook, Excel, phone contacts, accounting system), and People (who knows which password, who holds which device). Be brutally honest in the "who has access" column — that column is where the surprises live.
The attacker's-eyes exercise
Answer three questions in writing — on the same inventory page. Do not solve anything yet; just write honest answers:
- If someone got my email password, what could they reach? (Hint: mentally run "Forgot password" on your other accounts.)
- If my phone were stolen today, what would the business lose and what would the thief gain?
- If my laptop died right now, which data has no second copy anywhere?
If the answers make you uncomfortable, that's excellent — it means you are seeing your business through an attacker's eyes for the first time, before the attacker does.
Where this course goes
This course is a ladder with eight rungs. Lesson 2 hardens your accounts (passwords and two-factor authentication), Lesson 3 hardens your devices and backups, Lesson 4 trains you to spot phishing and payment fraud, Lesson 5 protects your customers' data and your website, Lesson 6 secures your Wi-Fi, point of sale, and payments, and Lesson 7 gives you the "it already happened" playbook. Lesson 8 then assembles everything into a practical 30-day implementation plan. The inventory page you wrote today is the thread that ties the whole journey together.
That was the full sample — here is the rest
What you just read is one part. The full edition includes:
- All 8 lessons: accounts, devices, phishing and payment fraud, customer data, Wi-Fi and point of sale, incident response
- The hands-on task and quiz that close every lesson — neither is included in this sample
- A hands-on task after every lesson and a short quiz that locks the learning in
- A completion certificate in your name, in Arabic and English