resources
the small business cybersecurity checklist.
july 21, 2026 · 6 min read
Most cybersecurity advice for small businesses is either too vague to act on or written for companies with a security team. This is neither. It is the checklist we actually run against small businesses, written so you can walk through it yourself in an afternoon. Check what passes, mark what fails, and fix the failures in the order they appear here; the list is roughly sorted by how often each gap causes real damage.
passwords and MFA
- Multi-factor authentication is on for email, banking, payroll, and every admin account. Email first: whoever controls email can reset everything else.
- A password manager is in use, so passwords are long, unique, and not reused between accounts. One reused password is one breach away from being every account.
- No shared logins where a personal account would work. When someone leaves, you should be able to cut their access without changing a password everyone else uses.
- Default passwords are gone from the router, firewall, printers, and cameras. Attackers know every factory default.
updates
- Automatic updates are on for Windows or macOS and for browsers.
- Someone owns a monthly reminder to update what does not update itself: firewall, server, point of sale, industry software.
- Nothing on the network runs an operating system its vendor no longer supports. If a machine cannot be upgraded, it gets replaced or taken offline.
backups
- Everything you could not stand to lose is backed up automatically, on a schedule, with no human in the loop.
- At least one backup copy is offsite or in the cloud, and cannot be altered or deleted with your everyday admin credentials. Ransomware goes hunting for backups first.
- You have restored a real file or server from backup in the last quarter and know how long a full restore takes. An untested backup is a guess.
- Phishing protection is enabled in Microsoft 365 or Google Workspace: link checking, attachment scanning, spoofing protection.
- Messages from outside the company are visibly tagged external.
- Everyone knows the money rule: any request to change payment details, buy gift cards, or wire funds gets verified by phone at a number you already had, no matter who the email appears to be from.
Wi-Fi and network
- Guest Wi-Fi is separate from the business network. Customers and personal phones never share a network with the register or the server.
- Wi-Fi uses WPA2 or WPA3 with a strong passphrase, not WEP or an open network.
- The router or firewall admin page is not reachable from the internet, and its firmware has been updated within the last year.
- Old remote access is closed: no forgotten remote desktop ports, no vendor tools nobody remembers installing.
who can touch what
- People have access to what their job needs and nothing more. The part-timer who runs the register does not need payroll.
- Daily-use accounts are not administrator accounts, on computers or in cloud services.
- Offboarding is a written list: accounts disabled, MFA devices removed, keys and hardware returned, ideally the same day someone leaves.
- A current list exists of every account, device, and software subscription the business owns. You cannot secure what you forgot you have.
if something goes wrong
- A one-page plan exists on paper, not only on the server it might be locked out of, naming who to call: IT partner, insurance carrier, bank.
- Staff know that clicking something bad is reported immediately and never punished. Fast reporting turns disasters into incidents.
- You know what your cyber insurance actually requires. Many policies quietly demand MFA and tested backups, and a claim can be denied without them.
where we fit
Everything on this list is work we do for clients every week, from one-time assessments to ongoing monitoring. If you would rather have a second set of eyes run the checklist with you, our cybersecurity services page is the place to start.