Insights
Small business cybersecurity checklist: 10 controls that stop most attacks
You don’t need an enterprise security team to stop most attacks. A short list of well-run basics blocks the large majority of the automated, opportunistic attacks small businesses actually face. Use this checklist to see where you stand.
The checklist
- Multi-factor authentication everywhere: email, remote access, banking and admin accounts first.
- Patch on a schedule: operating systems, browsers and business applications, monthly at minimum.
- Endpoint protection with detection and response: on every laptop, desktop and server.
- Email security: filtering plus SPF, DKIM and DMARC so attackers can’t easily spoof your domain.
- Backups you’ve tested: including at least one copy offline or immutable, out of ransomware’s reach.
- Least-privilege access: staff use standard accounts day to day; admin rights are separate and rare.
- A password manager: unique passwords for every system, shared securely where needed.
- Device management: encrypted drives, screen locks and the ability to wipe a lost laptop.
- Security awareness training: short and regular, with phishing simulations.
- An incident response plan: who to call, what to unplug, and how to restore, written down before you need it.
Where to begin
If you only do three things this month, turn on multi-factor authentication, confirm your backups restore, and set up automatic patching. Those three close the doors most attacks walk through.
Frameworks worth knowing
If clients or insurers ask about your security program, the NIST Cybersecurity Framework and the CIS Critical Security Controls are good, widely recognized reference points. This checklist maps onto their most important early steps.
Want a second opinion? Our cybersecurity services start with an assessment and a prioritized list of fixes, or contact us to talk it through.