Security

Small Business Cybersecurity: A Practical Checklist

Protect business accounts, email, devices, and backups with a prioritized checklist and concrete recovery checks.

Start with the accounts that can stop your business: email, banking, domain registration, file storage, and the systems that take orders or bookings. A long list of security products is less useful than knowing who owns those accounts, how they are protected, and how you would recover them.

Use this checklist to assign work to a named person. It combines account, email, device, and recovery basics without assuming you have a dedicated security team.

1. Protect the accounts that control everything else

Use individual accounts rather than shared logins wherever possible. Store unique passwords in a business password manager and require multifactor authentication, starting with administrators and email. Prefer phishing-resistant methods such as supported security keys. An authenticator code is still better than a password alone, but can be stolen by a convincing fake sign-in page.

Document account ownership and store recovery codes securely. Confirm that recovery does not depend solely on one employee's phone or an inbox on the same system you are trying to recover.

2. Treat email as an administrative system

Email often resets passwords for other services. Review administrator access, forwarding rules, recovery addresses, connected applications, and available sign-in alerts. Keep spam and phishing protection enabled and provide a clear way for staff to report suspicious messages.

Have your email provider or administrator check SPF, DKIM, and DMARC for every service sending mail from your domain. Inventory legitimate senders before tightening enforcement so you do not block your own invoices or order confirmations. These controls help address domain spoofing; they do not make every message safe.

Do not assume ordinary business email is end-to-end encrypted. Transport encryption and encryption at rest are different protections. For sensitive records, use an approved sharing method with appropriate access restrictions.

3. Verify payment changes outside the message

A plausible invoice or message from a familiar account can still be fraudulent. Confirm bank-detail changes and unusual payment requests using a known phone number or an established separate channel, not the contact information supplied in the request. Make this a normal process, so staff do not have to choose between questioning a manager and following procedure.

4. Keep devices and software supported

Maintain a list of business computers, phones, routers, websites, and key applications, with an owner for updates. Enable automatic security updates where practical; for systems needing staged updates, set a prompt maintenance process and a rollback plan. Replace unsupported software rather than treating it as permanently exempt.

Enable disk encryption, screen locks, host firewalls, and supported endpoint protection. Keep recovery keys accessible to authorized staff. Separate guest Wi-Fi from business systems. Hiding a network name is not a meaningful substitute for access controls, and a consumer VPN does not solve phishing or compromised accounts.

5. Remove access when roles change

Grant only the access a person needs. At departure, disable accounts, revoke sessions and tokens, review shared passwords, remove public sharing links where appropriate, and transfer owned files. Include contractors and connected third-party apps. Recheck permissions periodically; a former employee should not retain access simply because nobody remembered one service.

6. Prove that backups restore

List the data you cannot operate without: documents, email, website databases, financial records, and application settings. Choose a backup frequency based on how much work you could afford to lose. File synchronization alone is not a backup strategy: deletion or corruption can synchronize too.

Keep protected copies separate from the primary system, including an off-site copy and protection against an attacker deleting all copies. CISA recommends the 3-2-1 approach and regular recovery tests. Restore a representative file or application into an isolated location, record the time taken, and confirm it actually works. A green “backup complete” message is not that test.

7. Write a one-page incident plan

Name who can isolate a device, disable an account, contact your IT provider, and authorize recovery. Keep the contact list available outside your main email account. Include your insurer and legal adviser where relevant, and identify who assesses notification obligations.

If something is compromised, preserve logs and evidence and get qualified help before wiping systems or restoring over them. Recovery needs to address the entry point, not just make the screen look normal again.

What to verify this week

  • Critical accounts have an owner, MFA, and a usable recovery path.
  • A sample restore succeeds, with the time and result recorded.
  • A departing employee's access can be removed from a written inventory.
  • Staff know how to report suspicious activity and verify payment changes.

This is a starting baseline, not a compliance certification or a guarantee against compromise. Websites also need application-specific checks; see our website stack audit guide.

Sources

Need a technical partner?

Let’s make the next move cleaner.

If this surfaced a messy system, a privacy concern, or a website issue you want handled, we can help you turn it into a practical plan.