Relentless Tech Solutions Logo
Back to Services

Guide

The Small Business Cybersecurity Checklist

You don't need a Fortune 500 budget to build a real security strategy. You need a plan. This is the practical, plain-language checklist we walk every small business through — covering MFA, employee awareness, backups, and disaster recovery.

Small businesses are the #1 target for cyber attacks — not because they're valuable, but because they're easy. Most breaches happen because basic protections were never put in place.

The good news: roughly 90% of attacks against small businesses are stopped by a short list of fundamentals. Work through this checklist in order. Each step is something a non-technical owner can request, verify, or hand to an IT partner.

Why a Strategy Beats Tools

Buying products doesn't make you secure. A simple, layered strategy does — and it doesn't have to be expensive.

Layered Defense

One control will fail. Two won't. Layering MFA, endpoint protection, email filtering, and backups means a single mistake doesn't end your business.

People Are the Front Line

Over 80% of breaches start with a human — a clicked link, a reused password, a wired-payment scam. A 15-minute monthly habit cuts that risk dramatically.

Recovery, Not Just Prevention

Assume a breach will happen. Tested backups and a written response plan turn a catastrophe into an afternoon of inconvenience.

Compliance Follows Security

HIPAA, PCI, and cyber-insurance requirements all map back to these same fundamentals. Get the basics right and compliance gets easier.

The 8-Step Small Business Cybersecurity Checklist

Work through these in order. Each step is independently valuable — but together they form a complete strategy.

Step 01

Turn On Multi-Factor Authentication (MFA)

MFA alone blocks over 99% of automated account-takeover attacks. This is the single highest-impact step you can take today.

  • Enable MFA on email (Microsoft 365 / Google Workspace) for every user
  • Enable MFA on banking, payroll, and accounting platforms
  • Enable MFA on remote access (VPN, RDP, admin portals)
  • Use an authenticator app or hardware key — not SMS — for admins
  • Require MFA on any account that touches customer data

Step 02

Train Your People (Security Awareness)

Phishing and social engineering bypass every firewall you own. A short, recurring training program turns your team into a defense layer.

  • Run monthly 10-minute security awareness training
  • Send simulated phishing tests to measure real-world risk
  • Establish a 'verify by phone' rule for any payment or wire change
  • Document a procedure for reporting suspicious emails
  • Onboard new hires with a security orientation in week one

Step 03

Protect Every Endpoint

Laptops, desktops, and phones are how attackers get in. Modern endpoint protection (EDR) does what old-school antivirus never could.

  • Deploy managed endpoint detection & response (EDR) on every device
  • Enforce automatic OS and application patching
  • Enable full-disk encryption (BitLocker / FileVault) on all laptops
  • Lock screens after 10 minutes of inactivity
  • Maintain an inventory — you can't protect what you don't know about

Step 04

Lock Down Email

Email is the #1 attack vector. A few simple settings stop the vast majority of phishing and business email compromise (BEC) attempts.

  • Configure SPF, DKIM, and DMARC for your domain
  • Enable advanced threat protection on Microsoft 365 / Google Workspace
  • Block auto-forwarding of email to outside addresses
  • Disable legacy protocols (IMAP, POP, basic auth)
  • Flag external emails with a clear visual banner

Step 05

Secure Your Network

Your office Wi-Fi and firewall are the perimeter. Most are still running default settings from the day they were installed.

  • Replace consumer-grade routers with a business firewall
  • Segment guest Wi-Fi from your business network
  • Change all default passwords on routers, switches, printers, cameras
  • Keep firmware up to date on every network device
  • Disable remote management on edge equipment unless required

Step 06

Back Up Like Your Business Depends On It

Ransomware doesn't ask politely. Tested, off-site backups are the difference between a one-day outage and going out of business.

  • Follow the 3-2-1 rule: 3 copies, 2 media types, 1 off-site
  • Back up Microsoft 365 / Google Workspace data (it's not automatic)
  • Verify backups monthly — a backup you've never restored isn't a backup
  • Keep at least one copy immutable / air-gapped from your network
  • Document your recovery time objective (RTO) and test against it

Step 07

Write an Incident Response Plan

The middle of a breach is the worst time to figure out who to call. A one-page plan saves hours of panic and thousands of dollars.

  • Document who decides, who communicates, and who executes
  • List contact info for IT, legal, insurance, and law enforcement
  • Decide in advance how you'll communicate if email is down
  • Know your cyber-insurance carrier's required notification window
  • Rehearse the plan once a year — even a 30-minute tabletop helps

Step 08

Review and Improve Quarterly

Security is a habit, not a project. A short quarterly review keeps your posture from quietly drifting backwards.

  • Audit user accounts — remove anyone who left the company
  • Review admin access — least privilege, all the time
  • Check that backups, MFA, and EDR are still running everywhere
  • Review the past quarter's incidents and near-misses
  • Update the incident response plan with new contacts or systems

If You Only Do Five Things This Month

We get it — you're running a business. If the full checklist feels like a lot, start here. These five moves block the vast majority of attacks small businesses actually face.

  • 01Turn on MFA everywhere — especially email and banking
  • 02Deploy modern endpoint protection on every device
  • 03Verify you have a tested, off-site backup of Microsoft 365 / Google data
  • 04Run one phishing simulation and one 10-minute training session
  • 05Write a one-page incident response plan and tape it to the wall

Don't Wait for a Wake-Up Call. Build the Plan Now.

Every item on this checklist is something Relentless Tech Solutions implements for small businesses every week. If you want a second set of eyes on your current posture — or a partner to handle it end to end — let's talk.