written by
Greg

The small-business cybersecurity plan you can actually maintain

Cloud Computing Cyber Security cybersecurity security 7 min read
Photographer: Ellicia | Source: Unsplash

A small business does not need an enterprise security department or dedicated security staff to make meaningful progress. It does need a short list of controls that someone owns, checks, and tests.

This small-business cybersecurity checklist focuses on the basics that protect access, reduce data loss, and make recovery less chaotic. It also includes two items many checklists underplay: knowing who owns your data and proving that your backups can be restored.

The goal is not to build a perfect security program. The goal is to make the biggest vulnerabilities less likely and less damaging.

Start with the accounts that control everything else

Your email account is usually the first account to protect. Whoever controls it may be able to reset passwords for your website, cloud storage, social profiles, accounting tools, and other services.

Make a list of your highest-impact accounts:

  • Primary email
  • Domain registrar and DNS provider
  • Website and hosting account
  • Banking, payment, and accounting services
  • Google Workspace or Microsoft 365
  • Password manager
  • Cloud storage
  • Social media and advertising accounts
  • Customer relationship or mailing-list platform

For each account, record the owner, recovery email, recovery phone, billing contact, and the person who can approve a security change. Keep the inventory somewhere you can access if your normal systems are unavailable.

The NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide, published by the National Institute of Standards and Technology, recommends beginning with an inventory of the hardware, software, systems, and services a business relies on. That is useful because you cannot protect or recover something you have forgotten exists. This inventory also supports a basic risk assessment.

Turn on multi-factor authentication first

Multi-factor authentication, often shortened to MFA, adds another verification step after your password. It may be an authenticator-app code, a security key, or a prompt on a trusted device.

Enable MFA on every important account that offers it, starting with:

  1. Email
  2. Password manager
  3. Domain and website accounts
  4. Banking and payment services
  5. Google, Microsoft, or Apple accounts
  6. Cloud storage
  7. Social and advertising accounts
  8. Accounting, payroll, and customer systems

MFA is not a complete security plan. It does make a stolen or reused password less useful. Use an authenticator app or security key where practical, and keep backup codes in a secure place that is not dependent on the account you are trying to recover.

Also avoid shared logins. Give each person their own account, use the minimum access they need, and remove access promptly when someone leaves or changes responsibilities. This identity hardening is especially important for Google Workspace identities and other cloud accounts.

Photographer: Sasun Bughdaryan | Source: Unsplash

Use a password manager, not a spreadsheet

A password manager helps you create long, unique passwords without asking you to memorize every one. It also makes it easier to share access safely when a team member needs it, without sending credentials through email or chat.

Choose a manager that lets you:

  • Create separate accounts for each person
  • Require MFA
  • Recover the account through a documented process
  • Export your vault in a usable format
  • Review access and remove former team members

The export question matters. A tool can be convenient and still become a problem if you cannot retrieve your credentials when you need to change providers. Strong password security is one of the simplest security best practices to maintain.

Keep independent copies of important data

Cloud storage is useful, but “it is in the cloud” does not automatically mean “it is backed up.” A synced folder can copy deletions, corruption, or ransomware damage to every connected device.

Identify the data your business would struggle to replace:

  • Customer records and invoices
  • Website content, media, and design files
  • Email lists and marketing materials
  • Contracts and financial records
  • Product, service, or project files
  • Domain, DNS, and account information
  • Podcast, video, and other original media

These may include valuable assets, financial records, and intellectual property. Keep more than one copy, use more than one storage method, and make sure at least one copy is separated from the systems it protects. The right arrangement depends on your business, but the principle is simple: one compromised account or device should not destroy every copy.

Your existing plain-English guide to small-business data protection covers the ownership and vendor-shutdown problem in more detail.

Photographer: Sandisk | Source: Unsplash

Test restoring a backup

A backup that has never been restored is a hope, not a recovery plan.

Choose a small test each quarter. Restore:

  • A sample customer or financial file
  • A folder of website content or images
  • One project file from your creative workflow
  • A configuration or account record you would need after a failure

Check that the files open, are complete, and can be used with the software you have available. Record the date, what you tested, and what failed.

NIST’s small-business guidance specifically includes regularly backing up data and testing those backups. It also recommends planning recovery responsibilities and restoration priorities before an incident happens. Read the NIST quick-start guide.

Know what happens if a vendor disappears

A vendor shutdown can create a security and continuity problem even when nobody hacked you. If a service closes, locks your account, changes its terms, or suffers a long outage, you may lose access to important work.

For every critical provider, ask:

  • Do I own the data I put here?
  • Can I export it without contacting support?
  • What format will the export use?
  • How often should I export it?
  • Where will I store the export?
  • What happens to backups, media, and account history if the service closes?
  • Who controls the billing account and recovery email?

Do not wait until a provider announces a shutdown. Test one export from your website, customer list, cloud storage, and accounting system. Open the exported files and confirm that they are useful across your email environments and other business systems.

This is one reason to avoid building your entire business around a single tool. Convenience is valuable, but portability is part of control.

Write a one-page incident response plan

When something looks wrong, people lose time deciding what to do first. A one-page incident response plan gives you an order of operations and supports your business continuity plan.

Include:

  • Who has authority to make urgent decisions
  • Who manages technology or outside support
  • Who contacts the bank, insurer, legal adviser, or relevant provider
  • How to disable a compromised account
  • How to preserve evidence, such as suspicious messages and login alerts
  • Which systems should be disconnected, and when
  • How customers or partners will be informed if necessary
  • Where offline copies of contacts and recovery information are stored

The plan should be practical enough to use during stress. Keep an offline copy because your email, cloud drive, or password manager may be part of the problem.

If an account may have been taken over, start with the account takeover and modern scam response steps. Do not reuse a compromised device or session for sensitive password changes if you have reason to believe it is infected.

Review the devices and software people actually use

Security plans often focus on the office network while ignoring the laptop, phone, browser, and personal mobile devices used to access the business.

At minimum:

  • Turn on automatic updates where they do not disrupt critical work
  • Use screen locks and full-disk encryption where available
  • Remove software and browser extensions that are no longer needed
  • Install reputable anti-malware protection appropriate to the device
  • Separate administrator accounts from everyday work where possible
  • Review which personal devices can access business data
  • Use a guest network for visitors and untrusted devices when appropriate

You do not need to buy every security product recommended in an advertisement. Start by reducing unnecessary access, keeping the devices you already use current, and making sure you have full endpoint visibility across business systems.

Photographer: Microsoft Copilot | Source: Unsplash

Treat AI tools like other business vendors

AI tools may receive customer information, internal documents, prompts, recordings, or unpublished content. Before using one for business work, check:

  • What information the tool receives
  • Whether submitted material is used to improve models
  • How long data is retained
  • Who can access the account
  • Whether you can delete or export your information
  • What happens if you stop paying or the service changes direction

For a practical example, see what happens to your PDFs and notes in NotebookLM. The right choice depends on the sensitivity of the material and the controls the service actually provides.

Use a simple monthly maintenance routine

You can make steady progress with 30 minutes each month:

  1. Review recent login alerts and unusual account activity.
  2. Confirm MFA is still enabled on critical accounts.
  3. Remove former users and unnecessary access.
  4. Check that backups completed.
  5. Export one important dataset or account record.
  6. Update devices, operating systems, browsers, and important software.
  7. Review one vendor’s privacy, export, and shutdown terms.
  8. Record one improvement for the next month.

Once a quarter, perform a restore test and review the one-page incident response plan. If your business changes, update the inventory and risk assessment too.

The practical order of operations

If you are starting from scratch, use this step-by-step cybersecurity checklist:

  1. Protect your primary email and password manager with MFA.
  2. Inventory accounts, devices, services, and important data.
  3. Create independent backups and test one restore.
  4. Remove shared logins and unnecessary access.
  5. Export critical data from your highest-risk vendors.
  6. Write and store the incident response plan.
  7. Repeat a short review every month.

You do not need to finish everything in one afternoon. Start with the accounts that unlock other accounts, then make sure the files that keep the business running can be recovered.

A small-business cybersecurity checklist is useful when it becomes a routine, not when it becomes another document nobody opens. Pick one owner, choose one improvement, test it, and keep going.

cloud security databackup AI smallbusiness cybersecurity mfa cloud computing privacy