The Small Business Security Checklist
31 things worth fixing, in the order worth fixing them.
Written for a company of 5 to 200 people with no security team. Everything here is something a founder or an office manager can do without hiring anyone. Work top to bottom — the order is deliberate, and if you stop halfway you will still have done the half that matters most.
This is a practical starting point, not a compliance framework or legal advice. If you are subject to sector-specific rules (health, finance, defence), treat this as the floor, not the ceiling.
Want this in your inbox?
One email a week: what changed in security, what it means for a company your size, and the one thing worth doing about it. No vendor pitches, no fear.
Weekly. Unsubscribe in one click. See the checklist first.
1. Accounts and access
One stolen password should never be enough to reach anything that matters. This section is the highest-value hour in the whole list.
Enforce multi-factor authentication on company email
Enforced for every user, not offered. Email is where every password reset lands, which makes it the master key to everything else you own.
30 min + a week for staff to enrol · Read the guide
Secure the domain registrar and turn on registrar lock
The account nobody thinks about. Whoever controls your domain controls your email. It is usually years old, on someone's personal address, with an ancient password.
15 min · Read the guide
Turn on MFA for anything that holds or moves money
Business banking, payroll, payment processor, accounting, expense cards.
45 min · Read the guide
Roll out a password manager to the whole team
It ends password reuse, and it quietly blocks phishing: a manager will not autofill on a lookalike domain, because it matches the exact domain rather than the design.
1 hour + rollout
Count your administrators, then reduce the number
Administrator rights belong to the two or three people who genuinely need them. Everyone else gets a normal account.
20 min
Enable passkeys wherever they are offered
The only widely available form of MFA that a convincing fake login page cannot defeat, because the credential is bound to the real domain.
20 min per service · Read the guide
Buy two hardware security keys for your highest-privilege accounts
Two, not one. One carried, one in a safe. The failure mode of a single key is being locked out of your own company.
10 min to order
2. Money and email fraud
The most expensive thing likely to happen to you involves no malware at all: someone sends money because an email convincingly told them to.
Write the payment-verification rule and send it to your finance people
No bank-detail change and no unexpected urgent payment is executed on the basis of an email. Verification is by phone, on a number you already held, by someone other than the person who received the request.
20 min · Read the guide
State out loud that nobody can waive that rule — including you
The scam works by manufacturing an authority gradient. Your finance person must believe that following the rule will never make you angry.
One conversation · Read the guide
Require two people to approve payments above a threshold
Pick a number that matters to your business. This is also a control cyber insurers ask about directly.
30 min
Check for mailbox rules nobody created
Attackers add rules that auto-delete or forward mail containing words like 'invoice' or 'fraud', so their conversation stays invisible to the real owner. Check every quarter.
15 min
Set up SPF, DKIM and DMARC on your domain
Makes it materially harder for someone to spoof your company to your own customers. Your email provider documents all three.
1-2 hours
Create one obvious place to report a suspicious email
One address, one channel, one named person. If people have to work out who to tell, they tell nobody.
10 min · Read the guide
3. Backups and recovery
This section decides whether a bad Monday is a bad week or the end of the company.
List what would actually stop the business if it vanished
Not all your data — the short list: customer records, financial records, contracts and current work, email, production systems and the credentials for them.
30 min · Read the guide
Make sure one backup copy cannot be deleted by your own admin account
Immutable or physically offline. Ransomware operators hunt backups before they encrypt anything, and by then they hold your administrator credentials.
2-4 hours to set up · Read the guide
Stop treating cloud sync as your backup
Drive, OneDrive and Dropbox replicate changes — and encryption is a change. Version history is a useful safety net, not a recovery plan.
Understanding, then a decision · Read the guide
Back up your critical SaaS data independently
Your CRM and email provider protect against their hardware failing, not against you or an attacker deleting things. Retention windows are shorter than people assume.
1-2 hours
Restore something for real, and time it
Have someone who is not the usual administrator run it from your written procedure. Write down the number of minutes. That number is your actual recovery time.
90 min, once a quarter · Read the guide
Write a one-page recovery plan and print it
Who to call in what order, who decides what, where the backups are, your insurer's hotline. Keep a copy that does not depend on your systems working.
1 hour · Read the guide
4. Devices and updates
Attackers rarely spend novel exploits on companies your size. They use published vulnerabilities that nobody got around to patching.
Set operating systems, browsers and phones to install updates automatically
Install, not notify. A notification is a decision, and decisions get postponed.
30 min
Patch anything reachable from the internet first, and fast
VPN appliances, firewalls, routers, file transfer tools. Automated scanning finds a newly exposed weakness within hours.
Ongoing
Get remote desktop and management interfaces off the open internet
Put them behind a VPN or zero-trust access, or remove them. Answering this question wrongly is close to disqualifying on a cyber insurance application.
Half a day · Read the guide
Find and decommission what nobody maintains
The old marketing server, the test environment holding real customer data, the appliance from a vendor that no longer exists.
2 hours to inventory
Turn on full-disk encryption on every laptop and phone
FileVault, BitLocker, or the default on modern phones. Turns a stolen laptop into a hardware loss instead of a data breach.
20 min per device
Stop everyone working as a local administrator day to day
Limits what a single bad click can do to the machine it happened on.
Half a day
5. People and process
The cheapest controls on this entire list, and the ones most often skipped because they do not feel like security.
Promise, out loud and in advance, that reporting a mistake carries no blame
The expensive incidents are not the ones where someone clicked. They are the ones where someone clicked, felt stupid, and said nothing for four days. Then keep the promise the first time it is tested.
One conversation · Read the guide
Spend 15 minutes at a team meeting on the three things that matter
How to check a suspicious request, the payment rule, and how to report. Not an e-learning course — a conversation.
15 min · Read the guide
Write the offboarding checklist before you need it
Suspend the account, revoke active sessions, rotate shared credentials, collect devices, remove payment authority. Applied identically to everyone, so it is never personal.
1 hour · Read the guide
Build a SaaS inventory from twelve months of card statements
Tool, what it holds, who administers it, how access is removed. A spreadsheet is fine. You cannot revoke access to systems you have forgotten exist.
2 hours · Read the guide
Put a quarterly access review in the calendar
Fifteen minutes across your five most important systems, looking for people who left, roles that changed, and accounts nobody recognises.
15 min per quarter · Read the guide
Assemble the trust packet before a customer asks for it
A public security page, your standard answers, subprocessor list, DPA template. Turns a stalled enterprise deal into a same-week reply.
Half a day · Read the guide
If you only do three things
- Enforce multi-factor authentication on company email and your domain registrar.
- Write the payment-verification rule, and tell your team that nobody — including you — can waive it.
- Restore something from a backup, and time how long it takes.
Those three cover the large majority of what actually happens to companies this size. The rest of the list is the difference between surviving an incident and not noticing one.
One email a week, and nothing else
One email a week: what changed in security, what it means for a company your size, and the one thing worth doing about it. No vendor pitches, no fear.
Weekly. Unsubscribe in one click. See the checklist first.