Small business cybersecurity checklist: 12 things to fix first
· 10 min read
Almost nobody targets a small business by name. They get in because a scan found an easy way and nobody was watching. This list is ordered by how much risk each item removes for the effort it takes.
If you only do three things
- 1
- Turn on multi-factor authentication for email, everywhere, no exceptions
- 2
- Get a backup running that a compromised computer cannot delete, and test a restore
- 3
- Put monitored endpoint protection on every machine, including the one in the back office
Those three cover the overwhelming majority of what actually happens to small businesses.
Fix this week
1. Multi-factor authentication on email
Email is the master key. Whoever controls it can reset the password on nearly everything else, read your invoices and email your customers as you. Stolen passwords are cheap and plentiful, and MFA is what makes a stolen password useless on its own.
Turn it on for every account including the owner, the shared info@ mailbox and anyone who left but whose account still exists. Use an authenticator app rather than text messages where you can. If you are on Microsoft 365, this is a setting, not a purchase.
2. Find out who still has access
Every business we look at has at least one account belonging to someone who left. Sometimes several. List every account in your email system, your accounting software and your line of business system, and disable anything that is not a current employee. Then check which accounts are administrators, because it is usually more than it should be.
3. Check your backups actually ran, and restore something
Most businesses have a backup. Fewer have a backup that finished, and fewer still have ever restored from it. Open the console, confirm the last successful run, then actually restore a file and open it.
The important part for ransomware: at least one copy has to be somewhere a compromised machine cannot reach or delete. Modern ransomware looks for the backup first. A USB drive left plugged in permanently is not protection.
4. Look at what is protecting each computer
Walk the list of machines and check what is installed, whether it is current, and whether anyone would find out if it alerted. The gap is usually not the main office computers, it is the one machine at the back running a specific piece of equipment that everyone forgot about. See our longer piece on choosing endpoint protection for what to look for.
Fix this month
5. Patch Windows and the software on it
Not just Windows Update. Browsers, PDF readers, Java if you still have it, and whatever line of business software you run. Attackers use known holes with published fixes far more often than anything clever. This should be automatic and reported on, not something someone remembers to do.
6. Replace anything running unsupported software
An operating system past end of support stops receiving security fixes entirely. It will keep working, which is exactly why it lingers. It is also the machine that gets used to get in, and it will fail a cyber insurance questionnaire.
7. Stop everyone being an administrator
If staff log in with accounts that can install software, then anything they run can install software too. Day-to-day accounts should be standard users, with a separate admin account for when it is genuinely needed. This one change stops a large share of malware from ever getting a foothold.
8. Sort out passwords properly
Not a spreadsheet, not a shared document, not the same password with a number on the end. A business password manager, unique passwords everywhere, and shared credentials held in a vault rather than in someone's head or on a sticky note under a keyboard. It also solves the awkward problem of what happens when that person leaves.
9. Train people on the three scams that actually land
Skip the hour-long course. Most small business losses come from three things:
- A fake login page. An email says a document is waiting, the page looks exactly like Microsoft, the password goes to someone else.
- A changed bank account. An email that appears to be from a supplier or the owner asks for payment details to be updated. Always verify by phone on a number you already had.
- Urgency from the boss. A message claiming to be the owner, needing something done quickly and quietly.
Give staff explicit permission to slow down and check. That is worth more than any slide deck.
Fix this quarter
10. Put a real firewall in, and separate your networks
The box the internet provider supplied is not a business firewall. You want something maintained and updated, with guest Wi-Fi kept completely separate from the network your computers and card terminals sit on. If you have cameras, smart TVs or door controllers, those belong on their own segment too. They are rarely updated and they are a common way in.
11. Get monitoring with a person attached
This is the difference between having security tools and being protected. Detection that nobody reads is a log file. Ask directly: when something triggers at 3am, who sees it, how fast, and what can they do without waiting for me?
12. Write down what you would do on a bad day
One page is enough. Who to call first, how you keep serving customers while systems are down, where the backups are and how long a restore takes, who tells staff and customers, and your cyber insurance policy number and claims line. Nobody thinks clearly at 6am with everything encrypted. Print it, because if it only exists on the network you cannot read it.
What cyber insurance will ask you
Renewal questionnaires have become genuinely strict, and answering optimistically can leave you with a policy that will not pay. Expect to be asked about multi-factor authentication on email and remote access, endpoint detection and response, offline or immutable backups, whether you run any unsupported systems, how administrator accounts are controlled, and whether you run staff security training.
Work through this list and most of those answers become straightforwardly yes, with evidence behind them.
The honest summary
None of this makes you unbreakable, and anyone promising that is selling something. What it does is move you out of the group that gets caught by automated attacks, which is where nearly all small business incidents come from. The first four items on this list cost very little and remove most of the risk. The rest is steady maintenance rather than a project.
If you would rather not work through it alone, that is what our cybersecurity service covers, and a free IT check-up will tell you where you currently stand on every item above.
Common questions
Are small businesses really targeted by hackers?
Not usually by name. Most attacks are automated: something scans huge numbers of addresses looking for a known weakness or tries stolen passwords across many sites at once. Small businesses get caught because they are easy, not because someone chose them.
What is the single most important thing to do first?
Multi-factor authentication on email. It is free on most platforms, takes an afternoon, and stops the most common way small businesses lose money.
Is antivirus enough on its own?
No. Antivirus is necessary but it only covers one route in. It does nothing about a stolen password, a staff member typing details into a convincing fake login page, or a backup that has quietly not run for months.
How much should a small business spend on cybersecurity?
Less than most people expect for the basics. The first four items on this list are mostly configuration rather than purchases. Ongoing monitored protection is normally a modest per-computer monthly cost, and it is generally cheaper than the deductible on a cyber insurance claim.
We use Microsoft 365, is that not already secure?
Microsoft secures the platform. Your account settings, who has access, whether MFA is enforced, and whether anyone is watching the alerts are all your responsibility. Microsoft also does not keep a long-term backup of your mail and files in the way most people assume.
Find out what's actually wrong - before you commit to anything.
A free IT check-up gives you a written picture of your computers, network, backups and security. No obligation, and it's yours to keep even if you never hire us.
Not ready? See how pricing works or read the FAQ.