Guide
The Small Business Cybersecurity Checklist
You don't need a Fortune 500 budget to build a real security strategy. You need a plan. This is the practical, plain-language checklist we walk every small business through — covering MFA, employee awareness, backups, and disaster recovery.
Small businesses are the #1 target for cyber attacks — not because they're valuable, but because they're easy. Most breaches happen because basic protections were never put in place.
The good news: roughly 90% of attacks against small businesses are stopped by a short list of fundamentals. Work through this checklist in order. Each step is something a non-technical owner can request, verify, or hand to an IT partner.
Why a Strategy Beats Tools
Buying products doesn't make you secure. A simple, layered strategy does — and it doesn't have to be expensive.
Layered Defense
One control will fail. Two won't. Layering MFA, endpoint protection, email filtering, and backups means a single mistake doesn't end your business.
People Are the Front Line
Over 80% of breaches start with a human — a clicked link, a reused password, a wired-payment scam. A 15-minute monthly habit cuts that risk dramatically.
Recovery, Not Just Prevention
Assume a breach will happen. Tested backups and a written response plan turn a catastrophe into an afternoon of inconvenience.
Compliance Follows Security
HIPAA, PCI, and cyber-insurance requirements all map back to these same fundamentals. Get the basics right and compliance gets easier.
The 8-Step Small Business Cybersecurity Checklist
Work through these in order. Each step is independently valuable — but together they form a complete strategy.
Step 01
Turn On Multi-Factor Authentication (MFA)
MFA alone blocks over 99% of automated account-takeover attacks. This is the single highest-impact step you can take today.
- Enable MFA on email (Microsoft 365 / Google Workspace) for every user
- Enable MFA on banking, payroll, and accounting platforms
- Enable MFA on remote access (VPN, RDP, admin portals)
- Use an authenticator app or hardware key — not SMS — for admins
- Require MFA on any account that touches customer data
Step 02
Train Your People (Security Awareness)
Phishing and social engineering bypass every firewall you own. A short, recurring training program turns your team into a defense layer.
- Run monthly 10-minute security awareness training
- Send simulated phishing tests to measure real-world risk
- Establish a 'verify by phone' rule for any payment or wire change
- Document a procedure for reporting suspicious emails
- Onboard new hires with a security orientation in week one
Step 03
Protect Every Endpoint
Laptops, desktops, and phones are how attackers get in. Modern endpoint protection (EDR) does what old-school antivirus never could.
- Deploy managed endpoint detection & response (EDR) on every device
- Enforce automatic OS and application patching
- Enable full-disk encryption (BitLocker / FileVault) on all laptops
- Lock screens after 10 minutes of inactivity
- Maintain an inventory — you can't protect what you don't know about
Step 04
Lock Down Email
Email is the #1 attack vector. A few simple settings stop the vast majority of phishing and business email compromise (BEC) attempts.
- Configure SPF, DKIM, and DMARC for your domain
- Enable advanced threat protection on Microsoft 365 / Google Workspace
- Block auto-forwarding of email to outside addresses
- Disable legacy protocols (IMAP, POP, basic auth)
- Flag external emails with a clear visual banner
Step 05
Secure Your Network
Your office Wi-Fi and firewall are the perimeter. Most are still running default settings from the day they were installed.
- Replace consumer-grade routers with a business firewall
- Segment guest Wi-Fi from your business network
- Change all default passwords on routers, switches, printers, cameras
- Keep firmware up to date on every network device
- Disable remote management on edge equipment unless required
Step 06
Back Up Like Your Business Depends On It
Ransomware doesn't ask politely. Tested, off-site backups are the difference between a one-day outage and going out of business.
- Follow the 3-2-1 rule: 3 copies, 2 media types, 1 off-site
- Back up Microsoft 365 / Google Workspace data (it's not automatic)
- Verify backups monthly — a backup you've never restored isn't a backup
- Keep at least one copy immutable / air-gapped from your network
- Document your recovery time objective (RTO) and test against it
Step 07
Write an Incident Response Plan
The middle of a breach is the worst time to figure out who to call. A one-page plan saves hours of panic and thousands of dollars.
- Document who decides, who communicates, and who executes
- List contact info for IT, legal, insurance, and law enforcement
- Decide in advance how you'll communicate if email is down
- Know your cyber-insurance carrier's required notification window
- Rehearse the plan once a year — even a 30-minute tabletop helps
Step 08
Review and Improve Quarterly
Security is a habit, not a project. A short quarterly review keeps your posture from quietly drifting backwards.
- Audit user accounts — remove anyone who left the company
- Review admin access — least privilege, all the time
- Check that backups, MFA, and EDR are still running everywhere
- Review the past quarter's incidents and near-misses
- Update the incident response plan with new contacts or systems
If You Only Do Five Things This Month
We get it — you're running a business. If the full checklist feels like a lot, start here. These five moves block the vast majority of attacks small businesses actually face.
- 01Turn on MFA everywhere — especially email and banking
- 02Deploy modern endpoint protection on every device
- 03Verify you have a tested, off-site backup of Microsoft 365 / Google data
- 04Run one phishing simulation and one 10-minute training session
- 05Write a one-page incident response plan and tape it to the wall
Don't Wait for a Wake-Up Call. Build the Plan Now.
Every item on this checklist is something Relentless Tech Solutions implements for small businesses every week. If you want a second set of eyes on your current posture — or a partner to handle it end to end — let's talk.