Cybersecurity for Business in Uzbekistan: A Basic Checklist

Business digitalization in Uzbekistan is moving fast: card payments via Uzcard and Humo, integrations with government portals like my.gov.uz and soliq.uz, CRM systems, Telegram bots, mobile apps. The more digital touchpoints you have, the wider your attack surface. Yet most small and medium businesses still treat cybersecurity as "an expensive thing for banks." That is a dangerous misconception: attackers don't go after the biggest companies, they go after the least protected ones.
Below is a no-fluff practical checklist. Not theory, but what you should actually do in the coming weeks if you are responsible for the business, IT, or customer data.
The threats that matter right now
Most incidents in our region are not the work of a genius hacker but the result of basic negligence. The typical scenarios look like this:
- Phishing and social engineering. Fake emails "from the bank," fake Telegram messages impersonating a manager asking to urgently pay an invoice, fake corporate email login pages.
- Ransomware. It encrypts files on computers and servers, then demands a ransom. For a company without backups, this means a complete halt to operations.
- Data leaks. Customer databases, phone numbers, passport details leak through unprotected admin panels, exposed databases, and former employees who still have access.
- Weak and reused passwords. The same password for email, CRM, and the bank account — compromise one service and everything else opens up.
- Vulnerabilities in websites and apps. Outdated CMS, WordPress plugins, open ports, unsecured file upload forms.
Baseline protection: the foundation everything else rests on
Before buying expensive solutions, close the basics. These measures deliver 80% of the result at minimal cost:
- Two-factor authentication (2FA) on every critical service: corporate email, banking client, CRM, hosting, domain, social media and Telegram accounts. It is the cheapest and most effective barrier.
- A password manager for the team instead of sticky notes and Excel sheets. A unique, strong password for every service.
- Regular updates. OS, CMS, plugins, server software. Most breaches exploit already-known vulnerabilities that have long had a patch.
- Backups following the 3-2-1 rule: three copies of your data, on two types of media, one of them off-site (cloud or another data center). Most importantly — regularly verify that the backup actually restores.
- Access segmentation. An employee should only have access to what their job requires. An accountant doesn't need root on the server, a sales rep doesn't need a full export of the entire database.
Customer data protection and the law
Since 2021, Uzbekistan has enforced data localization requirements for citizens' personal data: data of Uzbek citizens must be stored on servers physically located in the country and registered with the State Personalization Center's registry. This is not only a legal matter — it is reputation and customer trust.
The practical minimum for handling data:
- Encrypt data in transit (HTTPS/TLS on all websites and APIs) and encrypt sensitive data at rest.
- Minimize collection: don't store what you don't actually need. Less data means less risk.
- Keep an inventory of where and what personal data you hold. Many companies don't even know this.
- Set up access logging for databases so you know who accessed sensitive information and when.
Employees: the weakest and most manageable link
Statistically, most successful attacks start with a person: someone clicked a link, opened an attachment, read out an SMS code to the "bank security service." Technology can be configured once, but people need systematic training.
- Run short, regular phishing briefings — a 30-minute session once a quarter beats one big seminar every three years.
- Introduce a simple rule: any request for an urgent money transfer or change of payment details is verified through a second communication channel (a phone call, not just chat).
- Set up an offboarding process: when an employee leaves, access is revoked the same day and passwords to shared services are changed.
- Prohibit work data on personal messengers and personal devices without oversight.
What to implement first
If resources are tight but everything needs doing, move by priority. Here is the order we recommend to businesses:
- Step 1. Enable 2FA everywhere there is money and data. One day of work for a multifold reduction in risk.
- Step 2. Set up automated backups and verify restoration. This is your insurance against ransomware.
- Step 3. Audit access rights and remove the unnecessary ones, especially for former employees and contractors.
- Step 4. Update all software and close obvious vulnerabilities on websites and servers.
- Step 5. Train the team in basic hygiene and introduce a rule for verifying financial requests.
- Step 6. Commission a security audit from specialists — an outside view finds what becomes invisible from the inside.
Conclusion
Cybersecurity is not a one-time purchase but a process and a culture. For businesses in Uzbekistan, a basic checklist closes the bulk of risks at a reasonable cost: 2FA, backups, access control, updates, and a trained team. Start with the cheapest and most effective measures, then build the complex on top of a solid foundation. If you want to assess your current level of protection, get your personal data storage in order under the law, or run an audit of your systems — discuss your project with the OneDev team: we'll help you build security tailored to the realities of your business.
Where should a small business with a limited budget start?
Is it mandatory to store customer data in Uzbekistan?
How do you protect against ransomware?
Do I still need antivirus if I have 2FA and backups?
How often should employees be trained?
What should I do if a leak has already happened?
Need a similar system or want to discuss your project?
Describe the task — we will propose architecture, technical approach and a work plan. A short call is usually enough to get started.
Discuss project