Small Business Cybersecurity Checklist: 15 Essential Steps

Small businesses face the same kinds of attacks as large enterprises, but with fewer resources to defend against them. The good news: a small set of high-impact controls addresses most of the risk. This checklist covers 15 essential steps organized into four phases, with guidance on prioritization and a 90-day implementation timeline.

Why SMBs Are Targeted

Attackers rarely pick specific victims. Most attacks are automated: criminals scan the internet for unpatched software, weak logins, and misconfigured services, then exploit whatever they find. Small businesses are attractive targets not because attackers have a grudge against them, but because automation makes low-cost attacks profitable at scale.

An SMB holds the same valuable assets as a large company — customer records, invoices, banking credentials, and email accounts that can be used to launch further fraud — but often with fewer defensive layers. Business email compromise, invoice fraud, and ransomware attempts are common precisely because they work often enough to be worth trying.

None of this means your business is doomed. It means a handful of consistent, low-cost practices will eliminate most of your exposure. The checklist below focuses on those practices.

The 15-Step Checklist

Phase 1: Foundations (Steps 1–4)

These steps build the base everything else depends on. All four are inexpensive and can be completed within a month.

  1. Inventory your assets. Make a list of devices, user accounts, cloud services, domains, and websites your business depends on. You can't protect what you can't see.
  2. Enable automatic updates for operating systems, browsers, office software, routers and firewalls, and any CMS or plugins you run. Outdated software is the most common entry point for automated attacks.
  3. Set up automated backups using the 3-2-1 rule: three copies of your data, on two different types of media, with one copy offsite or in the cloud. Test a restore quarterly — a backup you have never restored from is a hope, not a backup.
  4. Deploy endpoint protection on every device, including phones and tablets. Modern versions of Windows and macOS include decent built-in protection; make sure it is enabled and kept up to date.

Phase 2: Access Control (Steps 5–8)

  1. Require multi-factor authentication (MFA) on email and every service that supports it. Start with email and financial accounts — they offer the highest leverage for attackers.
  2. Use a password manager to generate and store a unique password for every account, so one breached site never exposes others. See our password security guide for details.
  3. Apply least privilege. Nobody does daily work as an administrator. Create separate admin accounts used only for administration, and grant employees access only to what their role requires.
  4. Offboard promptly. Revoke access on the day someone leaves the company. Keep a simple offboarding checklist covering email, shared drives, SaaS tools, and devices. Former-employee account access is a recurring cause of incidents.

Phase 3: Email & Web (Steps 9–12)

  1. Set up SPF, DKIM, and DMARC for your domain so attackers can't easily send spoofed email that appears to come from your business.
  2. Enable email filtering and phishing protection in your email platform, and consider adding an external-email banner so employees notice messages from outside the organization.
  3. Secure your website: HTTPS everywhere with a valid certificate, security headers, and regular CMS and plugin updates. Run a free scan to see where you stand.
  4. Lock down infrastructure admin accounts: your domain registrar, DNS provider, hosting control panel, and domain-related email. Each needs a unique password and MFA, because whoever controls these controls your online identity.

Phase 4: Recovery (Steps 13–15)

  1. Write a simple incident response plan. One page is enough: who to call (bank, IT provider, web host, registrar, insurer), how to disconnect affected systems, and whom to notify. A plan written calmly today beats improvisation during a crisis.
  2. Review cyber insurance or your existing business policy. Understand what is covered, what is excluded, and whether the insurer expects you to maintain specific controls.
  3. Run regular employee training. Short, periodic reminders and phishing simulations keep security awareness current far better than a single annual session.

Prioritizing When Resources Are Limited

Nobody implements all fifteen steps in a weekend. If you can only do four things this month, do these: turn on MFA for email, enable automatic updates, set up automated offsite backups, and publish SPF, DKIM, and DMARC for your domain. These four controls address the most common causes of SMB incidents — stolen credentials, unpatched software, data loss, and spoofed email — and each takes under an hour with modern tooling.

After that, invest in the access-control phase: password managers and least-privilege accounts prevent single points of failure. Everything else on the list compounds on this foundation, so completing the foundations first makes each later step more effective.

Implementation Timeline (30/60/90 Days)

  • First 30 days: Complete the Foundations phase (steps 1–4) plus MFA and the password manager (steps 5–6).
  • Days 30–60: Complete the access-control and email/web phases: least privilege, offboarding, email authentication, filtering, website hardening, and infrastructure account lockdown (steps 7–12).
  • Days 60–90: Complete the recovery phase: incident response plan, insurance review, and training (steps 13–15). Then re-run your security assessments and schedule quarterly reviews.
Tip: MFA and backups matter more than any other single item on this list. If you do nothing else this week, enable both — they neutralize two of the most damaging failure modes an SMB can experience.

Summary

Start with four high-impact controls — MFA on email, automatic updates, offsite backups, and SPF/DKIM/DMARC — then work through access control, email and web hardening, and recovery planning on a 30/60/90-day schedule. Small, consistent effort beats a one-time overhaul.

Conclusion

Cybersecurity for small businesses is a process, not a project. The organizations that handle attacks best are rarely the ones with the biggest budgets — they are the ones that consistently apply a small set of good practices. Start with the four priorities today, schedule the rest on the 90-day timeline, and revisit the checklist quarterly. That routine alone will put you ahead of most of the attackers who target businesses your size.

Take the Next Step

Find out how your website scores against current security standards, then track your improvements over time.

Scan your website free →

Related Articles

Advertisement