Small Business Cybersecurity Checklist — 12 Controls

Most small-business breaches aren't sophisticated — they walk through unlocked doors: a password without MFA, a machine missing patches, a backup nobody tested. This checklist covers the twelve controls that close those doors, in priority order, with realistic market costs.

Here's the encouraging math: analyses from Verizon's DBIR, CISA, and cyber-insurance claims data consistently attribute the overwhelming majority of small-business incidents to a handful of preventable causes — stolen credentials, phishing, unpatched systems, and exposed remote access. The twelve controls below target exactly those paths. None require an enterprise budget; most are cheap, and four are nearly free.

The Checklist at a Glance

# Control Typical market cost Stops
1 MFA enforced everywhere Free–$6/user/mo Credential theft — the #1 breach vector
2 Monitored EDR on every device $5–$15/device/mo Ransomware, malware, intrusions
3 Tested, segregated backups $3–$10/user/mo Ransomware extortion leverage, data loss
4 Patch management Bundled in managed IT Exploitation of known vulnerabilities
5 Email security filtering $2–$6/user/mo Phishing, malicious attachments, spoofing
6 Password manager $3–$8/user/mo Reuse, weak passwords, sticky notes
7 Security awareness training $1–$4/user/mo The click that starts most incidents
8 Least-privilege access Process, not product Insider damage, lateral movement
9 Secured remote access (no open RDP) Config + VPN/ZTNA The classic ransomware entry point
10 Firewall & network hygiene Existing gear, configured Perimeter exposure
11 Offboarding discipline Process Ghost accounts and ex-employee access
12 Incident response plan A written document Panic, downtime, and improvised decisions

Controls 1–4: The Ones That Do Most of the Work

1. Enforce MFA on everything. Email, Microsoft 365/Google Workspace, VPN, banking, line-of-business apps — everything, with zero executive exceptions. Stolen and phished credentials remain the top action in breach reports year after year, and MFA defeats the vast majority of those attempts at near-zero cost. "Enforced" is the key word: MFA that's available but optional protects whoever opted in and nobody else.

2. Put monitored EDR on every endpoint. EDR watches behavior — encryption sprees, credential dumping, persistence tricks — instead of matching known virus signatures. The "monitored" half matters as much as the software: an alert at 2 a.m. Saturday needs a responder, which is what MDR services and security-strong MSPs provide. Our cybersecurity services page details the stack.

3. Back up like ransomware is coming — because it is. Follow 3-2-1: three copies, two media, one offsite/immutable, covering servers and cloud data (Microsoft 365 retention is not backup). Then test restores on a schedule and document them. An untested backup is a hypothesis, and attackers specifically hunt and encrypt reachable backups first. See our backup and disaster recovery services for what tested actually means.

4. Patch on a schedule, with reporting. Most exploited vulnerabilities are old ones with patches available for months. Automate OS and third-party updates, and keep reporting so "are we patched?" has a documented answer — your insurer will eventually ask.

Controls 5–8: People and Access

5. Filter email beyond defaults. Phishing is the delivery mechanism for most of the above, and stock spam filtering isn't tuned for targeted lures or lookalike domains. Add SPF, DKIM, and DMARC so your own domain can't be trivially spoofed at your customers.

6. Deploy a password manager. It ends reuse — the mechanism that turns one breached website into your breached everything — and makes strong unique passwords the path of least resistance.

7. Train your people, then test them. Short recurring lessons plus simulated phishing beat annual slideshows. Measurable click-rate improvements within a quarter are the norm, and training is among the cheapest controls on the list.

8. Apply least privilege. Nobody works day-to-day as an admin; file access follows roles; admin credentials are separate accounts. This limits how far any single compromise — or disgruntled insider — can travel.

Want to know which of the twelve you're actually missing? Request a free IT assessment — we audit environments against this exact checklist and hand you the prioritized gap list.

Controls 9–12: Infrastructure and Readiness

9. Kill exposed remote access. Open RDP on the internet is the classic small-business ransomware story. Remote access goes through VPN or zero-trust tooling with MFA — no exceptions, no "temporary" port forwards that live forever.

10. Configure the firewall you already own. Current firmware, changed default credentials, closed unused ports, guest Wi-Fi separated from business, and IoT gadgets off the production network. Most small-business firewalls are fine hardware running abandoned configs — proper network management fixes that permanently.

11. Offboard like you mean it. A same-day checklist for departures: disable accounts, revoke sessions and app passwords, recover devices, rotate anything shared. Ghost accounts from ex-employees are a depressingly common finding in our assessments.

12. Write the incident response plan before the incident. One page: who to call (IT, insurer, attorney), what to isolate, what not to do (don't wipe machines, don't pay quietly), and where the plan lives when the file server is encrypted — printed. The first hour of a real incident is a terrible time for improvisation.

Why This Checklist Doubles as Your Insurance Application

Cyber-insurance carriers in 2026 condition coverage — and pricing — on essentially this list: MFA, EDR, segregated tested backups, patching, and training appear on nearly every application. Answering honestly with gaps means surcharges or declination; answering dishonestly risks claim denial when it matters most. Running the checklist first turns the application from an exam into paperwork, and if you're in a regulated industry, it's also the foundation layer for HIPAA, FTC Safeguards, and CMMC work.

We implement and monitor this full stack for small businesses across the Sacramento region — from Sacramento to Roseville and Rocklin — as part of managed service. Twelve controls, mostly cheap, covering the ways small businesses actually get hurt: that's the whole game, and it's very winnable.

Frequently asked questions

What are the most important cybersecurity controls for a small business?
Four controls carry most of the weight — enforced MFA on every account, monitored EDR on every device, tested offsite backups, and consistent patching. Industry breach analyses (Verizon DBIR, CISA guidance, insurer claims data) repeatedly show that the bulk of successful small-business attacks exploit the absence of exactly these basics, not sophisticated zero-days.
How much does small business cybersecurity cost?
The core stack is cheaper than its reputation. At market rates, EDR runs roughly $5–$15 per device monthly, email security $2–$6 per user, backup a few dollars per user for cloud data, and security awareness training $1–$4 per user. Bundled through a managed provider, comprehensive protection is typically built into per-user fees of $150–$250 per month at the security-inclusive tier.
Is antivirus enough anymore?
No. Traditional signature-based antivirus misses modern attacks that use stolen credentials, legitimate admin tools, and fileless techniques. The current baseline is EDR (endpoint detection and response), which watches behavior rather than matching known malware — and it needs someone monitoring its alerts, because an unwatched alarm protects nobody.
What do cyber insurance companies require in 2026?
Nearly every carrier now conditions coverage on MFA everywhere, EDR on endpoints, tested and segregated backups, patching discipline, and security awareness training — the same core controls in this checklist. Misrepresenting these on an application is grounds for claim denial, so the checklist doubles as your insurability audit.
How do most small businesses actually get breached?
Overwhelmingly through people and hygiene, not exotic hacking — phishing emails that harvest credentials, accounts without MFA, unpatched internet-facing systems, and remote access left exposed. That's good news in one sense: the defenses against the dominant attack paths are known, affordable, and on this list.
Where should we start if we have none of this?
In order — turn on MFA everywhere today (it's free and stops the top attack vector), verify you have a backup that actually restores, then deploy EDR and email filtering, then work down the rest of the checklist over a quarter. Or have a provider run the whole checklist against your environment at once via a security assessment.

Find out what your IT should be doing for you

Get a free, no-obligation IT assessment — a plain-English report on your security, backups, and support gaps.

Get Your Free IT Assessment