The Small Business Cybersecurity Checklist
The essential protections every small business should have in place.
1. Multi-Factor Authentication
- MFA enabled on email for every user, with no exceptions
- MFA on remote access, VPN, and financial systems
- Administrator accounts require MFA
- Legacy sign-in methods that bypass MFA are disabled
2. Endpoint Security
- Business-grade endpoint protection on every computer and server
- Alerts monitored by a person, not just a dashboard
- Laptops encrypted
- Lost or stolen devices can be wiped remotely
3. Email Security
- Spam and phishing filtering in place
- External sender warnings enabled
- SPF, DKIM, and DMARC configured for your domain
- Automatic email forwarding to outside addresses restricted
4. Backups
- Cloud data and server data are both backed up
- Backups stored separately from the systems they protect
- Restores tested at least twice a year
- You know your recovery time and data loss tolerance
5. Patch Management
- Operating system updates applied on a schedule
- Browsers and third-party applications updated
- Firmware on firewalls and network gear kept current
- Unsupported systems identified and planned for replacement
6. Administrator Account Security
- Daily-use accounts are not administrators
- Separate, named admin accounts with MFA
- Former employees and vendors removed promptly
- Admin access reviewed at least annually
7. Password Policies
- Long passphrases instead of frequent forced resets
- A password manager in use company-wide
- No shared logins between employees
- Breached-password checking enabled where available
8. Security Awareness
- Staff know how to report a suspicious email
- Wire and payment changes are verified by phone
- Short, regular training instead of one annual lecture
9. Disaster Recovery
- A written plan for what to do during an outage or attack
- Contact list available offline
- Cyber insurance requirements reviewed and met
- The plan is tested, not just filed
Explore more