top of page

Small Business Cybersecurity: What Should You Actually Have in Place?

Apr 19, 2022
17 min read

Updated: Sep 1




Small business cybersecurity covering devices, Microsoft 365, MFA, network security, backups, email security and device management.

I originally wrote this article in 2022 as a fairly simple list of six things small businesses should be doing for IT security. At the time, the list focused heavily on updates, antivirus, passwords, backups and having some kind of plan. Those fundamentals still matter, but after spending the last several years working inside small business environments, reviewing Microsoft 365 tenants, responding to security issues, working through cyber insurance questionnaires, implementing device management and watching AI become part of everyday business operations, I would not write that article the same way today.


Cybersecurity for a small business is no longer just about whether the computers have antivirus installed or whether employees know they should use a strong password. A business may depend on Microsoft 365, Google Workspace, cloud accounting, payroll, a CRM, line of business applications, mobile devices, remote employees, a NAS, security cameras, multiple Internet connections and third party vendors. Employees may also be using AI platforms that the owner does not even know about yet.

The first question I ask today is much broader:

Do you understand the technology your business depends on, how it is being protected, who is responsible for it and what happens when something goes wrong?

That is where I think small business cybersecurity should start.


Updated August 2026: Why I Revisited This Article

Technology changes quickly, but cybersecurity guidance also changes because the way businesses operate changes. I do not think it makes sense to publish security advice once and leave it untouched for years.


One of the biggest changes since I originally wrote this article is how much of the average small business now operates outside the traditional office network. Email, identities, documents, applications and administrative controls may all live in cloud platforms. Employees work from laptops, phones and tablets outside the office. Vendors connect remotely. Microsoft 365 may control email, files, authentication and managed devices. AI platforms are becoming another place where company information can be stored, processed or accessed.


At the same time, cyber insurance applications have become another reason business owners are being asked detailed technical questions. They may be asked about MFA, endpoint protection, encryption, backups, patching, email security, administrative access, remote access and incident response. The problem is that the owner may have been told those protections exist without having any way to verify exactly how they are configured.

That is why I no longer think a useful cybersecurity conversation begins with, “Which security product should you buy?”


I want to start with the business and work outward from there.


What Cybersecurity Does a Small Business Actually Need?

There is no single technology stack that every small business needs. A five person accounting firm, a construction company with employees in the field, a veterinary office, a law firm, a medical practice and a government contractor can all have very different technology, information and regulatory requirements.


That does not mean there is no common foundation. There are several areas I want almost every business to understand, including its accounts, devices, cloud environments, network, important data, backups, administrative access, endpoint protection, employee practices and incident response.


Current cybersecurity frameworks take a similar risk based approach. NIST's Cybersecurity Framework 2.0 organizes cybersecurity around six broad functions: Govern, Identify, Protect, Detect, Respond and Recover. I like that concept for small businesses because it makes an important point. Cybersecurity is not simply about preventing an attacker from getting in. The business also needs to know what it has, understand who is responsible for it, detect when something is wrong, respond effectively and recover afterward.

A security product may help with one or more of those areas, but it does not replace them.


Start by Knowing What Technology You Actually Have

Before I can tell a business what needs to be protected, I need to know what exists. That sounds obvious, but it is one of the most common gaps I see.


A company may know how many employees it has but not how many computers are actually under management. It may know it uses Microsoft 365 but not who has Global Administrator access. The owner may know there is a firewall in the building but not who manages it, when it was last updated or where its configuration is documented. Someone may say the company has backups without knowing exactly which data is included.

Then there are the things that tend to accumulate quietly: old employee accounts, cloud applications purchased by individual departments, vendor logins, personal cloud storage accounts, old network equipment, phones and tablets, websites, DNS accounts, remote access tools and now AI platforms.


This is why I would actually start many businesses with my Small Business IT Checklist and Systems Inventory. It is designed to help an owner answer a much more basic question before diving deeply into cybersecurity: How well do you actually know your business's technology?

You cannot make good security decisions around systems nobody remembered existed.


Protect Identities, Not Just Passwords

Passwords still matter, but a strong password by itself is no longer where I want account security to stop.

Multi-factor authentication should be used wherever it is supported and appropriate, particularly for email, cloud applications, administrative access, remote access, financial systems and other important business accounts. I also want to understand which MFA method is being used because all methods do not provide the same level of protection.

CISA recommends moving toward phishing resistant MFA where possible. Microsoft also supports stronger authentication methods such as passkeys, Windows Hello for Business and FIDO2 security keys in Microsoft Entra environments. That does not mean every small business should immediately buy hardware security keys for every employee and every application. The appropriate implementation depends on the systems the business uses and what those systems support. It does mean I would rather see a business moving toward stronger authentication than assuming a text message code is the final version of its security strategy.


I also want unique accounts for individual users, limited administrative privileges, a process for removing access when someone leaves and a secure password manager rather than employees keeping passwords in spreadsheets, notebooks or reusing personal passwords.

For Microsoft 365 specifically, administrative access deserves additional attention. I want to know who has administrative privileges, why they have them and what happens if the normal administrative account cannot be used. Microsoft recommends maintaining emergency access accounts for situations where normal administrative access is unavailable.


The business should not discover during an account compromise that the compromised account was also its only way to administer the environment.


Is Someone Actually Managing Microsoft 365 or Google Workspace?

This has become one of the biggest differences between the cybersecurity article I wrote in 2022 and the one I would write today.

For many small businesses, Microsoft 365 or Google Workspace is part of the security perimeter.


Microsoft 365 may control email, user identities, SharePoint, OneDrive, Teams, device management and security capabilities. Simply paying for Microsoft licensing does not mean all of those capabilities have been appropriately configured or that someone is actively reviewing them.


I want to know who administers the tenant, what privileges they have, how MFA is enforced, what authentication methods are allowed, whether former employees still have access, whether third party applications are connected, how external sharing is configured, what security alerts are being reviewed and whether the business has appropriate administrative recovery options.


I discuss that distinction more deeply in Microsoft 365 for Small Businesses: Is Anyone Actually Managing Your Environment?. When I need to go deeper into the tenant itself, my Microsoft 365 Audit and Tenant Security Review looks at the actual configuration rather than assuming a particular security feature exists because it appears on a Microsoft licensing comparison chart.


Buying the license gives the business access to capabilities. Someone still has to configure, review and manage them.


Is Antivirus Enough for a Small Business?

No, but that does not mean endpoint protection stopped mattering.

I still want business computers protected. What has changed is how I think about the question.


Instead of asking whether antivirus is installed, I want to know whether every device that should be protected is actually covered, whether the software is centrally managed, whether it is currently checking in, who receives alerts, whether suspicious activity is being investigated and whether machines that quietly stop reporting are noticed.

The same applies to centralized device management. A company may use an RMM platform, Microsoft Intune or another management tool, but the important question is whether the devices that are supposed to be managed are actually enrolled and reporting.

If the business owns thirty computers and only twenty four appear in the management platform, saying “we have device management” does not tell me what happened to the other six.


Encryption also belongs in this conversation, particularly for laptops and mobile devices that leave the office. If a company laptop is stolen from an employee's vehicle, I want to know whether the device was encrypted, whether company access can be revoked and whether the business knows what information that device could access.

This is also where centralized device management becomes important. Depending on the device, operating system and management platform, a properly managed company laptop, tablet or phone may be able to be remotely wiped, retired or otherwise have company access removed when it is lost or stolen. With platforms such as Microsoft Intune, I can manage company devices centrally and take appropriate remote actions instead of relying on someone physically having the device in front of them. The exact options depend on how the device is enrolled and configured, which is another reason device management needs to be set up before something goes missing.


I think about these protections together. Encryption helps protect the information stored on the device if someone physically gets possession of it. Device management gives the business more control over what happens to that device and its company access afterward. Identity controls can then be used to revoke sessions, disable accounts or otherwise restrict access to company resources when necessary.

Cybersecurity becomes much easier to manage when the business can answer those questions before the laptop or tablet disappears.


Updates Include More Than Windows

One piece of the original article that absolutely still belongs here is patching and updates. What I would change is the scope.


Small businesses tend to think about Windows updates because those are the updates they see. The environment may also include browsers, Adobe applications, accounting software, firmware, firewalls, managed switches, wireless access points, printers, NAS appliances, cameras, remote access tools and other devices or applications that need attention.


Some updates can be automated. Others need to be tested or managed more deliberately depending on the environment and the application.


The important thing is having a process. Who is responsible for updates? Which devices are included? How are failures detected? Are third party applications being patched? Are firewalls and other network devices still supported by the manufacturer? Does anyone know when an operating system or piece of equipment is approaching end of support?

Installing equipment is not the end of managing it.


Email Security Needs Both Technology and Business Procedures

Email remains one of the areas I pay particularly close attention to because a security problem can quickly turn into a financial problem.


Business Email Compromise does not always look like an obvious hacker message. An attacker may spoof a legitimate business, create a similar looking domain, compromise an actual mailbox or gain enough knowledge of a legitimate conversation to make a fraudulent payment request look believable.


Technical controls matter. Depending on the environment, that can include MFA, email filtering, anti-phishing and impersonation protections, SPF, DKIM, DMARC, monitoring and appropriate sign in controls.


But I do not want the accounting department relying on email security technology as its only defense against payment fraud.


A business that sends significant payments should have a procedure for independently verifying new banking instructions, changes to vendor payment information and unusual payment requests. The FBI recommends independently verifying payment and account changes using trusted contact information rather than simply relying on the contact information contained in the message requesting the change.

That is a good example of where cybersecurity becomes a business process rather than simply an IT setting.


Your Network Still Matters Even If Everything Is in the Cloud

Moving email, files and applications into the cloud does not eliminate the network underneath the business. The firewall, wireless network, switches, Internet connection, remote access and devices still affect how employees reach those cloud systems.


I want guest WiFi separated appropriately from the internal business environment. I want remote access configured deliberately rather than leaving unnecessary services exposed. I want network equipment kept current and managed. I want to know what cameras, printers, phones, IoT devices and other equipment are connected and whether those devices actually need access to the same things employee computers do.


In some environments, VLANs and firewall rules can provide useful segmentation between different types of systems. That is not a universal requirement I would prescribe identically to every company. It depends on the business, its systems, risks and any applicable regulatory or contractual requirements.


The important point for the owner is simpler. Someone should be able to explain how the network is designed, why it is designed that way and who is responsible for managing it.


“We Have Backups” Is Not Enough

Backups are another area where I have changed how I talk with business owners.

I do not simply ask whether the business has backup software. I want to know what is being backed up, what is not being backed up, where the backup lives, who monitors it, who receives failure alerts, how long information is retained and how recovery would actually work.


I also want restores tested.


A successful backup job tells me that a backup process reported success. A successful restore tells me considerably more about whether we can actually get information back.

This becomes especially important with cloud platforms. Microsoft 365, SharePoint, OneDrive, Google Workspace and other cloud services may provide native retention, versioning and recovery capabilities, but the business still needs to make an intentional decision about its backup and recovery requirements rather than assuming “the cloud” automatically means everything is independently backed up forever.


CISA's ransomware guidance emphasizes maintaining protected backups and testing recovery. That distinction matters because ransomware and destructive attacks can affect far more than the computer where the problem was first noticed.

The recovery question is ultimately the important one:

If this system disappeared tomorrow, what would we need back, how quickly would we need it and do we know that we could restore it?

Employees Need to Know What to Do When Something Looks Wrong

Security awareness training should not be reduced to making employees sit through a video once a year and checking a box.

Employees are often the first people who notice that something is wrong.


Maybe an unexpected MFA prompt appears. A vendor suddenly sends new banking instructions. Outlook begins behaving strangely. A computer's mouse moves without the employee touching it. Someone receives a password reset they did not request. A message from the owner asks for something unusual.

The employee does not need to diagnose the incident. They need to recognize that something may be wrong and know exactly how to report it.


I would rather have an employee report something that turns out to be harmless than decide not to tell anyone because they were afraid they would get in trouble for clicking something.

That reporting process becomes part of the company's incident response planning.


What Happens If Your Small Business Gets Hacked?

This is where cybersecurity planning often falls apart. Businesses spend years thinking about how to prevent incidents but very little time deciding what happens when prevention fails.


Who does the employee call? What happens if that person does not answer? Who can authorize IT to isolate a computer or block an account? Where is the cyber insurance information? If company email is compromised, how will everyone communicate? Who contacts the bank if money is involved? Who determines whether legal counsel, a forensic specialist, law enforcement or another outside party needs to become involved?


Those decisions should not begin while everyone is already dealing with the incident.

I created a detailed Incident Response Plan for Small Business guide to explain how I approach that planning around the actual business instead of using a generic template.

For an easier starting point, the Small Business Incident Response Checklist includes a free fillable readiness workbook that helps owners document emergency contacts, IT responsibilities, Microsoft 365 administrative access, cyber insurance information, financial fraud procedures, recovery priorities and other information that should already be established.

And if you are reading this because something may already be happening, My Small Business Was Hacked. What Should I Do Right Now? focuses specifically on the immediate response.

The important distinction is that a checklist is not the same thing as a completed incident response plan.

The checklist identifies the questions. Your plan needs your business's answers.


Cyber Insurance Has Made Verification More Important

Cyber insurance is another reason I think business owners need more visibility into their technology.

Applications and renewals may ask detailed questions about MFA, endpoint protection, encryption, backups, email security, remote access, administrative accounts, incident response and other controls. Those questions vary by carrier and policy, so I do not treat a generic online cybersecurity checklist as a substitute for reading the business's actual application.


From my side of the work, the important issue is whether the business can answer the technical questions accurately.


If the application asks whether MFA is enforced, I want to verify how it is enforced and which accounts are included. If it asks about backups, I want to understand exactly what is backed up and how recovery works. If it asks about endpoint protection, I want to know which devices are actually reporting into the platform.

That is the difference between believing a security control exists and being able to substantiate it.


I go into that process in more detail in Cyber Insurance Requirements for Small Businesses.

Cyber insurance is not a cybersecurity program, but the application often exposes cybersecurity questions a business should have been able to answer anyway.


AI Belongs in the Cybersecurity Conversation Now

This obviously was not part of the article I wrote in 2022. Today, I think it has to be.

Employees do not need the company to officially implement AI Governance before AI becomes part of the business. Someone may already be using ChatGPT, Claude, Copilot, Gemini, Perplexity or another platform to draft emails, summarize documents, research problems or work with company information.


That means I now want to know which AI tools are being used, whether employees are using personal or company managed accounts, what information they are entering, what business systems those tools can access and whether anyone has established rules around their use.


I do not treat all AI platforms or account types as though they handle company information the same way. The product, plan, configuration, connected systems and terms all matter.

The larger security issue is AI governance. Does the business know what employees are doing? Has it decided which tools are approved? Do employees know what company information is appropriate to use? Who approves a new AI platform or connector? What happens when an employee leaves?


I cover those questions more deeply in AI Governance for Small Business.

AI did not replace the need for good cybersecurity. It added another place where good identity, permissions, data management and governance matter.


Vendors and Third Party Applications Need Attention Too

A small business may secure its own computers reasonably well and still give a vendor broad remote access into the environment.

That is why vendor access and third party applications belong in the security conversation.

Who has remote access? Why do they need it? Is it still required? Does the vendor use an individual account or a shared credential? Is MFA available? What permissions have applications been granted inside Microsoft 365 or Google Workspace? Does anyone review those integrations after the original project is finished?


The same questions apply to the vendor itself. If another company can access sensitive business or customer information, I want the business to understand what that vendor can access and what expectations exist around protecting it.

Convenience tends to accumulate.

So does access.

Both need periodic review.


How Often Should a Small Business Review Cybersecurity?

I do not think cybersecurity should be reviewed once and then considered finished.

How often particular controls need review depends on the business and the technology involved. Some things are continuous or automated. Others may be reviewed monthly, quarterly, annually or when something meaningful changes.

The more important point is that the environment is not static.


Employees are hired and leave. Computers are replaced. New cloud applications are purchased. Microsoft changes features. New AI platforms appear. Vendors change. Insurance renews. A second office opens. A firewall is replaced. Someone adds a new administrator. The business begins handling a different kind of information.

The cybersecurity environment needs to change with the business.


That is one reason I like maintaining current documentation and reviewing the environment as a whole instead of treating security as a collection of unrelated projects.


What Should a Small Business Owner Be Able to Answer?

A business owner does not need to become a cybersecurity engineer. But I do think someone in the organization should be able to get reliable answers to these questions:

Area

Question I Would Want Answered

Technology inventory

Do we know which devices, systems, cloud services and applications the business depends on?

Ownership

Does the business control its domain, Microsoft 365 or Google Workspace, website and other critical accounts?

Administrative access

Do we know who has administrative privileges and why?

Authentication

Is MFA actually enforced where it should be, and what methods are being used?

Devices

Are business computers, tablets and other company devices centrally managed, protected and reporting?

Lost or stolen devices

Can we revoke company access and take appropriate remote management actions if a device disappears?

Encryption

Are portable devices and sensitive data encrypted where appropriate or required?

Patching

Who is responsible for operating system, application and firmware updates?

Email

What protections and financial verification procedures exist for phishing, spoofing and payment fraud?

Network

Who manages the firewall, WiFi, remote access and other network equipment?

Backups

What is backed up, where is it stored, who monitors it and when was recovery last tested?

Employees

Do employees know how to recognize and report suspicious activity?

Vendors

Who has outside access to business systems and is that access still appropriate?

AI

Which AI platforms are employees using and what company information can they access?

Cyber insurance

Can we substantiate the technical answers on our current application or renewal?

Incident response

Does everyone know who to call, who has authority and what happens when something goes wrong?

Recovery

Do we know which systems need to come back first and how the business would continue operating?

Documentation

Could another qualified IT professional understand the environment if the current provider were unavailable?

If several answers are “I don't know,” I would not treat that as failure.

I would treat it as the beginning of the assessment.


Small Business Cybersecurity Is Really About Knowing and Managing the Environment

When I wrote the original version of this article, cybersecurity advice for a small business felt much easier to reduce to six things.

Today I think that oversimplifies the problem.


Strong passwords still matter. MFA matters. Updates matter. Endpoint protection matters. Backups absolutely matter. But I have seen enough real environments to know that simply owning those technologies does not tell me whether the business is well protected.


I want to know whether the controls are actually configured, whether all of the appropriate devices and accounts are covered, whether alerts are being reviewed, whether backups can be restored, whether access is removed when employees leave, whether someone understands the Microsoft 365 environment, whether employees know what to do when something looks wrong and whether the business can recover when prevention does not work.


I also want the business to understand its own technology.


That is why the Small Business IT Checklist and Systems Inventory is such a useful starting point. Before we can decide what needs to be improved, we need to know what exists, what the company depends on and who is responsible for it.

From there, some businesses may need a deeper Microsoft 365 review. Others may discover that backups or device management deserve attention. A cyber insurance renewal may uncover questions that need to be verified. AI use may expose a governance issue. Another company may realize it has good preventive security but no usable incident response plan.

The answer will not be identical for every small business.

That is exactly why I think the starting point should be understanding the business rather than buying another security product.

Technology changes. Threats change. Businesses change.

Your cybersecurity plan needs to be able to change with them.


ADDITIONAL RESOURCES

National Institute of Standards and Technology: NIST Cybersecurity Framework 2.0 Small Business Quick Start Guide

NIST's small business guide provides a practical framework for managing cybersecurity risk through Govern, Identify, Protect, Detect, Respond and Recover.https://www.nist.gov/publications/nist-cybersecurity-framework-20-small-business-quick-start-guide


NIST Small Business Cybersecurity Corner

Cybersecurity resources developed by NIST specifically for small and medium sized businesses.https://www.nist.gov/itl/smallbusinesscyber


Cybersecurity and Infrastructure Security Agency: Small and Medium Sized Business Resources

CISA resources covering foundational cybersecurity practices for small and medium sized businesses.https://www.cisa.gov/small-and-medium-sized-business-resources


CISA: Require Multifactor Authentication

Guidance on implementing MFA and moving toward phishing resistant authentication where practical.https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/require-multifactor-authentication


CISA: StopRansomware Guide

Current ransomware prevention, response, backup and recovery guidance.https://www.cisa.gov/stopransomware/ransomware-guide


Federal Trade Commission: Cybersecurity for Small Business

FTC guidance covering cybersecurity fundamentals, data protection, authentication, updates, backups, vendor security and common cyber threats.https://www.ftc.gov/business-guidance/small-businesses/cybersecurity


Microsoft Learn: Microsoft Entra Authentication Overview

Microsoft guidance covering authentication methods and stronger phishing resistant authentication options.https://learn.microsoft.com/en-us/entra/identity/authentication/overview-authentication


Microsoft Learn: Manage Emergency Access Admin Accounts in Microsoft Entra ID

Microsoft guidance for maintaining emergency administrative access to Microsoft Entra environments.https://learn.microsoft.com/en-us/entra/identity/role-based-access-


Microsoft Learn: Microsoft Intune Device Actions

Current Microsoft documentation covering remote management actions available for supported enrolled devices, including Wipe, Retire, Remote Lock and other actions depending on platform and configuration.https://learn.microsoft.com/en-us/intune/device-management/actions/


Microsoft Learn: Protect Data and Devices with Microsoft Intune

Microsoft guidance covering device security, encryption and remote security actions for managed devices.https://learn.microsoft.com/en-us/intune/device-security/overview


Federal Bureau of Investigation: Business Email Compromise

FBI guidance on Business Email Compromise, payment fraud and independently verifying changes to payment information.https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise

Comments


bottom of page