"Too small to be a target" is exactly what makes small businesses the favourite target - attackers automate, and automation doesn't care about company size. The good news: the basics stop the overwhelming majority of attacks, and none of them require an IT department.
Multi-factor authentication on email first, then everything - a stolen password on its own becomes useless. Updates applied promptly on every device; most breaches walk through holes patched months earlier. Backups that live off-site, run automatically, and - crucially - have been test-restored. An untested backup is a hope, not a plan.
Nearly every small-business incident starts in an inbox: an invoice with 'new bank details', a fake login page, an 'urgent' request from the boss. Slow down anything involving money or passwords, verify by phone on a number you already have, and brief the whole team - the newest hire is the most-targeted person in the company.
Know who you call, what you disconnect and how you restore before it happens. One page, printed, is enough. If nobody in the business owns this, that is exactly the gap our IT consultancy fills for Dorset firms - a security review costs a fraction of one incident.