Insights · Cybersecurity

The Small Business Cybersecurity Checklist

The controls that actually stop the incidents small organizations face, in the order a real budget should tackle them.

August 1, 202610 min readCybersecurity

Most cybersecurity advice for small organizations reads like it was written for the Pentagon. Long frameworks, dense checklists, and language that assumes a full security team. That gets ignored, and then the organization gets breached anyway.

This checklist is different. It's the short list of controls that actually stop the incidents small businesses, nonprofits, and public agencies face. in the order a real budget should tackle them.

Before the checklist: what you are actually defending against

The threats that hit small organizations are boring on purpose. Attackers don't need sophistication when the fundamentals are missing. In practice, ~90% of real-world incidents come from four sources:

  • Phishing that harvests a legitimate login.
  • Account takeover when that login lacks multi-factor authentication.
  • Ransomware that spreads through unpatched endpoints and unbacked-up data.
  • Cloud misconfiguration that exposes data or accounts unnecessarily.

The rest of this checklist is organized around stopping those four.

The essential checklist (in priority order)

1. Turn on multi-factor authentication (MFA) everywhere

No single control has a higher return on investment. Enable MFA on every account. email, Microsoft 365 or Google Workspace, banking, payroll, key SaaS. and enforce it as a requirement, not a suggestion.

  • Prefer app-based MFA (Microsoft Authenticator, Duo, Google Authenticator) over SMS.
  • Require MFA on all admin accounts without exception.
  • Document backup codes in a secure password manager, not in email.

2. Deploy modern endpoint protection on every device

Traditional antivirus is not enough. Modern endpoint protection (often called EDR) watches behavior, not just signatures, and gives you visibility when something goes wrong.

  • One product, deployed on every laptop, desktop, and server.
  • Managed centrally. not left to each user to install.
  • Alerts routed to someone who is paid to respond to them.

3. Patch operating systems and browsers automatically

Most ransomware exploits vulnerabilities that were patched months earlier. Automate the following:

  • Operating-system updates on all endpoints and servers.
  • Web browser updates.
  • High-risk applications (Adobe, Zoom, Java if you still have it).

4. Back up everything that matters. and test the restore

The single biggest predictor of ransomware survival is whether you can restore. That requires backups that are actually tested.

  • Back up cloud data (Microsoft 365 / Google Workspace) to a separate system.
  • Back up critical files and servers on a defined schedule.
  • Keep at least one backup copy offline or in a separate tenant.
  • Restore a test file every month to verify the backups work.

5. Enforce a password manager

Password reuse is how a breach at a random SaaS vendor becomes a breach at your organization. A password manager makes strong, unique passwords the path of least resistance.

  • Choose one manager for the whole organization (1Password, Bitwarden, Keeper).
  • Require its use for all work accounts.
  • Store shared credentials in vaults, not in shared spreadsheets or notes.

6. Train staff to recognize phishing (briefly and repeatedly)

Your staff are your last layer of defense, and the most cost-effective one. Effective awareness training is short, frequent, and practical. not a two-hour compliance video once a year.

  • Quarterly micro-training on real phishing patterns.
  • Simulated phishing tests. paired with coaching, not punishment.
  • A no-blame reporting channel for suspicious messages.

F.Y.I. builds this kind of program inside Technology Training.

7. Review and tighten cloud account permissions

Most cloud tenants (Microsoft 365, Google Workspace, key SaaS) drift toward everyone having access to everything. Once a year, review:

  • Who has admin access and whether they still need it.
  • Guest accounts and external sharing on files and folders.
  • Legacy accounts for former employees or contractors.
  • API integrations connected to your tenants.

8. Write down an incident-response plan (short is fine)

A one-page document is worth more than none. It should answer:

  • Who is called first if we suspect a breach or ransomware event?
  • Where are the credentials to isolate accounts and endpoints?
  • Which insurance carrier, attorney, and technology partner do we notify?
  • What are our legal and contractual reporting obligations?
Reality check. Items 1-4 stop the majority of small-business incidents. If budget or time only lets you tackle four things, tackle those.

What this checklist deliberately does not include

  • Formal compliance certifications (SOC 2, HIPAA audits). important for specific industries, not the first step.
  • Advanced threat hunting or a full SOC. valuable, but only after the fundamentals above are in place.
  • Cyber insurance is not a substitute for controls. carriers now require most of the items above just to issue a policy.

The next step

This checklist is deliberately short because that is what makes it usable. If you would like help sequencing these controls inside a real budget, F.Y.I. builds programs like this every day. See the Cybersecurity service page or start with a strategy call.

If the deeper question is "do we need someone at the leadership table for this?", that's a signal it might be time for a Fractional CTO conversation.

Talk to F.Y.I.

If any of this hit close to home, a strategy call is the fastest way to see how F.Y.I. Technologies would approach it inside your organization. no obligation, no script.

Schedule a Strategy Call
Final Word

Technology shouldn't be stressful.
That's where F.Y.I. comes in.

Technology, visibility, leadership, and support under one roof.
No jargon.
No pressure.
Just practical guidance from a trusted partner.