A small business does not need an enterprise security department to reduce common risks. It does need named owners, a current inventory, strong account controls, recoverable backups, and a rehearsed way to respond. This checklist turns broad security advice into evidence a team can maintain.
Prioritize by consequence: protect the accounts and systems that can move money, expose customer or employee data, interrupt operations, or grant administrative access. Do not begin by buying tools before identifying what must be protected.
1. Govern: assign responsibility and limits
- Name one accountable leader and an operational owner for security work.
- List legal, regulatory, contractual, insurance, and customer requirements that apply to the business.
- Define who can accept risk, approve vendors, authorize emergency changes, and contact outside help.
- Schedule a quarterly review and a review after material system or staffing changes.
The NIST Cybersecurity Framework 2.0 small-business resources organize risk work around Govern, Identify, Protect, Detect, Respond, and Recover. The framework is a way to structure decisions, not a certification that makes a business secure.
2. Identify: inventory what the business depends on
Create a short register of devices, email tenants, cloud applications, websites, domains, payment systems, file stores, backups, vendors, administrators, and sensitive data. Record an owner, business purpose, access method, recovery dependency, and retirement decision for each.
| Asset | Owner | Sensitive data or authority | Recovery dependency |
|---|---|---|---|
| Email and identity tenant | Operations lead | Password resets, invoices, customer messages | Provider recovery and protected owner accounts |
| Accounting platform | Finance lead | Banking, payroll, tax records | Vendor continuity and exported records |
| Website and domain | Web owner | Public trust, forms, DNS authority | Registrar access, source, content, configuration backup |
| Customer records | Service owner | Contact and service history | Documented retention and export process |
3. Protect identities first
- Require unique passwords stored in an approved password manager.
- Enable multifactor authentication for email, finance, payroll, remote access, file storage, domains, cloud administration, and social accounts.
- Prefer phishing-resistant methods for high-impact accounts where available.
- Give administrators separate privileged accounts and use standard accounts for routine work.
- Remove access immediately when roles change or people leave.
- Review shared accounts and replace them with named access where the service allows it.
CISA's MFA guidance for small and medium businesses recommends enabling MFA broadly and using the strongest practical option, especially for administrative and sensitive access.
4. Protect devices, software, and data
- Enable supported automatic updates for operating systems, browsers, business software, plugins, and network equipment.
- Track unsupported systems and replace or isolate them through a dated plan.
- Encrypt managed laptops and mobile devices, and require screen locks.
- Use centrally managed endpoint protection where appropriate.
- Restrict local administrator rights and software installation.
- Collect only necessary data and follow a documented data retention schedule.
5. Make backups recoverable
A successful backup job is not the same as a successful recovery. Keep protected copies that are not all continuously writable from the production environment. Document what is included, encryption and key ownership, frequency, retention, restoration order, and the person authorized to recover.
Test a representative restore at least quarterly and after major platform changes. Record the recovery time, missing dependencies, integrity checks, and corrective work. For a WordPress site, pair the business controls here with the WordPress security checklist.
6. Teach a small number of repeatable behaviors
Training should match actual workflows. Staff need to know how to report suspicious messages, verify payment or bank-detail changes through a separate channel, recognize unexpected MFA prompts, protect customer information, and contact the incident lead quickly. Short recurring exercises are more useful than an annual presentation nobody can apply.
7. Detect meaningful changes
- Enable alerts for new administrators, risky sign-ins, MFA changes, forwarding rules, payment changes, and disabled security controls.
- Retain logs long enough to investigate likely incidents and meet obligations.
- Monitor domain, DNS, website files, backups, and critical cloud settings.
- Route alerts to a monitored destination with an escalation path.
- Test that one real person can receive and act on each critical alert.
8. Review vendors as part of the system
Ask what data and access a vendor receives, how administrators authenticate, how incidents are communicated, what logs and exports are available, how data is deleted, and what happens when the relationship ends. Reassess high-impact vendors when scope, ownership, or terms change.
9. Write and rehearse the response plan
First-hour incident card
Incident lead and backup: ______
Emergency IT/security contact: ______
Legal, insurer, provider, and law-enforcement decision contacts: ______
Systems that can be isolated safely: ______
Evidence-preservation instructions: ______
Approved internal and customer communication owners: ______
Do not improvise destructive cleanup before preserving evidence and understanding the scope. The correct notification and reporting path depends on facts, jurisdiction, contracts, and industry obligations; involve qualified counsel or incident professionals when needed.
A practical first 30 days
- Week 1: secure email, finance, domain, cloud, and administrator accounts with strong MFA and recovery controls.
- Week 2: inventory devices, software, data, vendors, and owners; remove stale access.
- Week 3: verify updates, endpoint controls, protected backups, logging, and alert delivery.
- Week 4: run one phishing/payment-verification exercise and one tabletop incident scenario.
Review the public-facing disclosures with the website privacy policy checklist. For service teams, the existing minimum-necessary call intake template can reduce the sensitive information collected before it reaches business systems.