This document provides guidance for small businesses on cyber security risks and recommendations for managing those risks. It discusses how common cyber attacks target business information and systems. The document recommends a three-step approach to managing cyber security risks: 1) planning, which involves identifying critical assets and risks; 2) implementation, such as installing antivirus software and passwords; and 3) review, like periodically testing controls and monitoring for attacks. Basic security practices are advised to protect a business without needing expert knowledge or significant costs.