Small Business Cybersecurity Checklist

Plain English, ordered by what stops the most damage first. No security team required.

Most small-business security advice is either terrifying enterprise jargon or a vague "use strong passwords." Neither helps when you're running a ten-person company and you're also the IT department.

So here's the honest version, in priority order. If you only do the first three, you've eliminated the large majority of how small companies actually get hurt. Everything after that is real, but it's not where you start.

01Turn on MFA everywheredo this first

Multi-factor authentication on email, banking, payroll, and your domain registrar. That's the list that matters most. Almost every small-business breach that ends in stolen money starts with one compromised email account — because email is where password resets for everything else land.

02Get backups that actually restore

Ransomware stops being a catastrophe and becomes an annoying afternoon the moment you have working backups. The key word is working.

03Patch the things facing the internet

You don't need a patch-management platform. You need automatic updates on, and a short list of anything exposed to the outside world — your router/firewall, VPN, any server, and every website plugin.

The one rule that saves companies: nothing gets exposed to the internet unless it has to be. Remote desktop (RDP, port 3389) reachable from anywhere is how a shocking number of small businesses get ransomed. Put it behind a VPN or turn it off.

04Lock down who can move money

The most expensive small-business attack usually isn't technical at all — it's an email that looks like the boss asking finance to pay an invoice. Beat it with process, not software:

05Know what you have

You can't protect what you haven't written down. One spreadsheet: devices, who has them, what cloud services you pay for, who has admin on each, and what data lives where. It takes an afternoon and it's the foundation of every other control — and every compliance questionnaire you'll ever be sent.

06Remove access the day someone leaves

Offboarding is where small companies quietly leak. Make a written list of every account a departing employee touches and work it the same day. Shared passwords make this nearly impossible — which is the real argument for a password manager.

07Write down what you'd do in a bad hour

Not a 40-page plan. One page: who to call, in what order, how to reach your IT help and your bank after hours, where the backups are, and who talks to customers. The value isn't the document — it's that somebody thought about it before 6am on a Saturday.

What about compliance? If clients start sending you security questionnaires, or you handle health, payment, or government-adjacent data, you'll need written policies — not just good habits. That's the point where informal stops being enough and you need the paperwork to exist.
Need the written policies, not just the checklist?

The SMB Cybersecurity & IT Compliance Toolkit — 20+ editable policy documents, built for small companies that suddenly have to prove this stuff on paper. Instant download, edit and go.

Get the toolkit — $99 →

The honest summary

MFA, tested backups, patch what's exposed, and a phone-call rule before money moves. Four things. They're unglamorous and they prevent most of what actually happens to companies your size. Do those, then work down the list as you have time.