Small Business Cybersecurity Checklist — 12 Controls
Most small-business breaches aren't sophisticated — they walk through unlocked doors: a password without MFA, a machine missing patches, a backup nobody tested. This checklist covers the twelve controls that close those doors, in priority order, with realistic market costs.
Here's the encouraging math: analyses from Verizon's DBIR, CISA, and cyber-insurance claims data consistently attribute the overwhelming majority of small-business incidents to a handful of preventable causes — stolen credentials, phishing, unpatched systems, and exposed remote access. The twelve controls below target exactly those paths. None require an enterprise budget; most are cheap, and four are nearly free.
The Checklist at a Glance
| # | Control | Typical market cost | Stops |
|---|---|---|---|
| 1 | MFA enforced everywhere | Free–$6/user/mo | Credential theft — the #1 breach vector |
| 2 | Monitored EDR on every device | $5–$15/device/mo | Ransomware, malware, intrusions |
| 3 | Tested, segregated backups | $3–$10/user/mo | Ransomware extortion leverage, data loss |
| 4 | Patch management | Bundled in managed IT | Exploitation of known vulnerabilities |
| 5 | Email security filtering | $2–$6/user/mo | Phishing, malicious attachments, spoofing |
| 6 | Password manager | $3–$8/user/mo | Reuse, weak passwords, sticky notes |
| 7 | Security awareness training | $1–$4/user/mo | The click that starts most incidents |
| 8 | Least-privilege access | Process, not product | Insider damage, lateral movement |
| 9 | Secured remote access (no open RDP) | Config + VPN/ZTNA | The classic ransomware entry point |
| 10 | Firewall & network hygiene | Existing gear, configured | Perimeter exposure |
| 11 | Offboarding discipline | Process | Ghost accounts and ex-employee access |
| 12 | Incident response plan | A written document | Panic, downtime, and improvised decisions |
Controls 1–4: The Ones That Do Most of the Work
1. Enforce MFA on everything. Email, Microsoft 365/Google Workspace, VPN, banking, line-of-business apps — everything, with zero executive exceptions. Stolen and phished credentials remain the top action in breach reports year after year, and MFA defeats the vast majority of those attempts at near-zero cost. "Enforced" is the key word: MFA that's available but optional protects whoever opted in and nobody else.
2. Put monitored EDR on every endpoint. EDR watches behavior — encryption sprees, credential dumping, persistence tricks — instead of matching known virus signatures. The "monitored" half matters as much as the software: an alert at 2 a.m. Saturday needs a responder, which is what MDR services and security-strong MSPs provide. Our cybersecurity services page details the stack.
3. Back up like ransomware is coming — because it is. Follow 3-2-1: three copies, two media, one offsite/immutable, covering servers and cloud data (Microsoft 365 retention is not backup). Then test restores on a schedule and document them. An untested backup is a hypothesis, and attackers specifically hunt and encrypt reachable backups first. See our backup and disaster recovery services for what tested actually means.
4. Patch on a schedule, with reporting. Most exploited vulnerabilities are old ones with patches available for months. Automate OS and third-party updates, and keep reporting so "are we patched?" has a documented answer — your insurer will eventually ask.
Controls 5–8: People and Access
5. Filter email beyond defaults. Phishing is the delivery mechanism for most of the above, and stock spam filtering isn't tuned for targeted lures or lookalike domains. Add SPF, DKIM, and DMARC so your own domain can't be trivially spoofed at your customers.
6. Deploy a password manager. It ends reuse — the mechanism that turns one breached website into your breached everything — and makes strong unique passwords the path of least resistance.
7. Train your people, then test them. Short recurring lessons plus simulated phishing beat annual slideshows. Measurable click-rate improvements within a quarter are the norm, and training is among the cheapest controls on the list.
8. Apply least privilege. Nobody works day-to-day as an admin; file access follows roles; admin credentials are separate accounts. This limits how far any single compromise — or disgruntled insider — can travel.
Want to know which of the twelve you're actually missing? Request a free IT assessment — we audit environments against this exact checklist and hand you the prioritized gap list.
Controls 9–12: Infrastructure and Readiness
9. Kill exposed remote access. Open RDP on the internet is the classic small-business ransomware story. Remote access goes through VPN or zero-trust tooling with MFA — no exceptions, no "temporary" port forwards that live forever.
10. Configure the firewall you already own. Current firmware, changed default credentials, closed unused ports, guest Wi-Fi separated from business, and IoT gadgets off the production network. Most small-business firewalls are fine hardware running abandoned configs — proper network management fixes that permanently.
11. Offboard like you mean it. A same-day checklist for departures: disable accounts, revoke sessions and app passwords, recover devices, rotate anything shared. Ghost accounts from ex-employees are a depressingly common finding in our assessments.
12. Write the incident response plan before the incident. One page: who to call (IT, insurer, attorney), what to isolate, what not to do (don't wipe machines, don't pay quietly), and where the plan lives when the file server is encrypted — printed. The first hour of a real incident is a terrible time for improvisation.
Why This Checklist Doubles as Your Insurance Application
Cyber-insurance carriers in 2026 condition coverage — and pricing — on essentially this list: MFA, EDR, segregated tested backups, patching, and training appear on nearly every application. Answering honestly with gaps means surcharges or declination; answering dishonestly risks claim denial when it matters most. Running the checklist first turns the application from an exam into paperwork, and if you're in a regulated industry, it's also the foundation layer for HIPAA, FTC Safeguards, and CMMC work.
We implement and monitor this full stack for small businesses across the Sacramento region — from Sacramento to Roseville and Rocklin — as part of managed service. Twelve controls, mostly cheap, covering the ways small businesses actually get hurt: that's the whole game, and it's very winnable.