Five Cyber Security Habits Every Nepali Business Should Have by Friday

Most breaches at small and medium businesses are not sophisticated. They are someone reusing a password, or an unpatched machine, or a staff member clicking a link. Here are five things that cost nothing and close the most common doors.
1. Turn on multi-factor authentication everywhere
Email first, then banking, then anything with customer data. Password theft stops being fatal the moment a stolen password isn't enough on its own. This is the single highest-value change on the list and it takes ten minutes per account.
2. Stop sharing one login
The shared admin account that four people use is invisible in an audit — you cannot tell who did what, and offboarding one person means changing a password everybody has to relearn. Individual accounts with appropriate permissions, always.
3. Patch on a schedule, not on a feeling
Operating systems, browsers, and anything internet-facing. Pick a day, make it someone's job, write down that it happened. Most exploited vulnerabilities have had a patch available for months.
4. Back up, and then restore from the backup
An untested backup is a hope, not a plan. Once a quarter, actually restore something from it and confirm the file opens. Keep one copy offline — ransomware encrypts network drives too.
5. Train people on phishing, specifically
Not a generic security lecture. Show your staff real phishing emails, including ones targeting Nepali businesses, and walk through what gave each one away. The urgency, the authority, the near-miss domain name. Fifteen minutes, once a quarter.
Where this goes next
These five are the floor, not the ceiling. Behind them sit network segmentation, logging, incident response, and knowing what you'd actually do at 2am when something goes wrong.
That's the territory our Cyber Security Fundamentals course covers — and it starts with the same premise as this list: security is a set of habits and controls, not a product you buy.