On Cybersecurity & Identity Protection
You Are the Attack Surface
Small business owners hold the keys to everything simultaneously — personal finances, business accounts, employee data, tax records. When their identity is compromised, the business gets compromised with it.
Cale · Dansbee Designs
I know what tax identity theft looks like from the inside — not from a case study, but from my own return. Someone filed under my Social Security number before I did, collected the refund, and disappeared. What followed was months of paperwork, phone calls to agencies not designed to move quickly, and the particular frustration of trying to prove you are who you say you are to an institution that has already decided otherwise.
That experience is what led me to build a free resource — lockdownyourid.com — with every concrete step I wished I'd known before it happened. But working with small business owners over the years has shown me something the consumer-facing guides miss entirely: when a founder's identity is compromised, it isn't just a personal problem. It becomes a business problem. And nobody is writing about that version of the story.
Roughly fifteen million Americans experience identity theft every year. The ones who feel it the most are not the ones who have the least to lose.
"The more senior a person is in a company, the less they want to be bothered with security. In my experience, that behavior is exactly 180 degrees wrong."
In my direct experience working with dozens of small business owners, one pattern was consistent: the higher up in a company a person sat, the more resistant they were to anything that added friction to their day. Security measures felt like an imposition — something for the IT department to worry about, not the person running the company. But the higher up in a company a person sits, the more sensitive and important information they hold. The founder who won't set up two-factor authentication is also the person with access to the business bank account, the payroll system, the client contracts, and the employee records. They are not the lowest-risk person in the organization to attack. They are the highest-value target in it.
The Reality
Why Small Business Owners Make Valuable Targets
Large companies get the headlines when they're breached. They also have security teams, incident response plans, cyber insurance, and legal counsel on retainer. The attacker who goes after a Fortune 500 company is contending with layers of defense specifically designed to stop them.
The attacker who goes after a small business owner is contending with one person who's also managing payroll, client deliverables, and a leaky faucet in the office bathroom. The asymmetry is the point. Small business owners are targeted not despite being small — but because of it.
And unlike an individual consumer, a compromised founder hands over access to an entire ecosystem. Personal bank accounts. Business credit lines. The Employer Identification Number used on tax filings. Employee Social Security numbers stored in payroll software. Every client relationship that lives in their email. The attack surface isn't one person — it's every system that person has ever authenticated into.
The Cost
What a Compromise Actually Looks Like
The average identity theft case takes six to eighteen months to resolve. For an individual, that's a miserable stretch of paperwork and waiting. For a business owner, those same eighteen months might contain a commercial lease renewal, a bank loan application, a line of credit needed to cover a seasonal gap, or a key hire that requires a background check.
A frozen or flagged credit profile doesn't politely wait for the investigation to conclude before affecting those things. The business that needed capital to take on a new contract doesn't get to pause while the founder sorts out a fraudulent tax return filed two years ago. The timeline of resolution and the timeline of the business don't negotiate with each other.
Tax identity fraud alone accounts for roughly one million cases per year. The typical financial impact to the individual is around $1,300 — but that number doesn't capture the cost of the business decisions that had to be delayed, deferred, or abandoned during the months it took to get there.
The Protection
Five Things That Actually Work
None of what follows requires a security team or a significant budget. It requires decisions — made once, before the moment they're needed. These are the five I recommend to every founder, in the order I'd do them.
Freeze your credit at all three bureaus
A credit freeze blocks any new credit inquiry against your file — no new accounts can be opened in your name without you first lifting the freeze. It's free, it's the strongest protection available, and it takes about fifteen minutes across Equifax, Experian, and TransUnion. Most people skip it because they assume it's complicated or will affect their existing accounts. It doesn't. When you need to apply for something, you lift the freeze temporarily, then refreeze. This one action eliminates the most common form of identity theft.
Get an IRS Identity Protection PIN
The IRS offers a six-digit PIN that must be included on any tax return filed under your Social Security number. Without it, a return can't be processed. Once you have one, a fraudulent filing under your SSN goes nowhere. The PIN renews annually each January. Given that tax identity fraud takes some of the longest to resolve — and hits at the worst possible times for a business owner's credit — this is fifteen minutes that returns years of protection.
Move to a password manager and stop reusing passwords
Roughly sixty-five percent of people reuse passwords across accounts. One breach cascades into every system that shares that credential. A password manager — Bitwarden is under two dollars a month, 1Password under three — generates and stores a unique strong password for every account, so a compromised login for one service exposes nothing else. The most important account to secure first is your email. Your email is the master key for resetting every other account. If it falls, everything connected to it is one reset link away from gone.
Enable two-factor authentication on everything critical
Two-factor authentication means a stolen password alone isn't enough to get in. An authenticator app (Authy, Google Authenticator) is significantly more secure than SMS text codes, which are vulnerable to SIM-swapping — a fraud where an attacker convinces your mobile carrier to transfer your phone number to a device they control, redirecting your verification texts. At minimum: enable 2FA on your email, bank accounts, IRS account, and any platform that touches payroll or client data. A hardware key like YubiKey is the most secure option available if you want to go further.
Monitor — don't just set and forget
After a breach, stolen credentials appear on dark web marketplaces within hours. Monitoring services alert you when your data surfaces before an attacker uses it. Google One offers dark web monitoring for Gmail addresses at no additional cost. Most major credit cards now include credit monitoring. Setting up real-time transaction alerts on your bank and credit accounts means fraud is caught in minutes, not months. Check HaveIBeenPwned.com now to see if your email address has already appeared in a known breach.
The Diagnostic
Four Questions Worth Answering Right Now
Before any conversation about tools or services, I ask four questions. The answers tell me more about a business owner's actual exposure than any technical audit.
If someone opened a line of credit in your name today, how long would it take you to find out?
Is your email account protected by something other than a password?
Do you use the same password — or variations of it — across more than one account?
If your phone was stolen right now, what would the person who found it be able to access?
The first question almost always lands quietly. Most people have no real answer — which means the answer is "months." That's the window an attacker has to do meaningful damage before the alarm sounds.
The fourth question is the one I find most useful. People's phones contain their email, their banking apps, their password reset pathways, and often their authenticator codes. A phone without a strong passcode — or set to biometric-only without a backup PIN — is a single point of failure for the entire account stack built on top of it.
The Reframe
Security is IT's problem, and I'm too small to be a real target anyway.
You are the highest-value target in your organization. The five protections above are free or nearly free. The cost of skipping them is measured in months, not dollars.
The founders I've worked with who had the hardest time accepting this were also the ones who had built the most. Something about having built a real business from nothing makes the idea of being a victim feel incompatible with the identity of being the person who built it. I understand that instinct. It's also exactly what makes the resistance to basic protection so costly when the moment arrives.
Every one of the five protections above can be completed in an afternoon. A credit freeze takes fifteen minutes across three websites. An IRS IP PIN takes a single enrollment. A password manager takes an hour to set up and a few weeks to fully migrate into. These are not ongoing burdens. They are one-time decisions that return years of protection — the same kind of decision you made when you chose the platform your business runs on, or the contract language that protects your client relationships.
The Starting Point
Start With the Worst Case
Before you close this page, sit with this one question.
The Question
If someone filed a fraudulent tax return under your Social Security number tomorrow, how long would your business wait?
Not how long would it take to resolve — that's six to eighteen months and largely outside your control once it happens. How long would your business wait for you to be able to sign a lease, close a loan, or clear a background check while the IRS works through a backlog that was not designed for urgency?
The protection is available. Most of it is free. The IRS IP PIN alone closes the most common attack vector in a fifteen-minute enrollment. A credit freeze at three websites removes the next one. The people who have done these things are not more technically sophisticated than the people who haven't. They're just the ones who asked the question before the answer became urgent.
Dansbee Designs
Don't wait for the moment that makes it urgent.
For the full step-by-step checklist — credit freezes, IRS IP PIN, passkeys, dark web monitoring, and emergency contacts — visit the free resource built from direct experience.
lockdownyourid.comor
Begin a Conversation with Dansbee Designs →