Why this matters
Small organizations do not need hundreds of controls to make meaningful progress. They do need a short list of high-impact protections that are actually implemented and reviewed.
Before you begin
- Identify the person responsible for technology security.
- List the organization's core systems and data.
- Record current control status honestly as verified, partial, missing, or unknown.
- Do not mark a control complete simply because a policy says it should exist.
Step-by-step instructions
Step 1: Require MFA
Verify MFA for email, remote access, cloud platforms, and especially administrator accounts.
Why this step mattersMFA blocks many attacks that rely only on a stolen password.
What to look forTest a real sign-in rather than relying on an unchecked policy box.
Step 2: Separate privileged accounts
Ensure admins use separate privileged and standard identities where the platform supports it.
Why this step mattersThis reduces exposure of high-value credentials.
What to look forAdmin accounts should not be used for routine email and browsing.
Step 3: Patch supported systems
Confirm operating systems, browsers, applications, firewalls, and other managed systems receive security updates.
Why this step mattersKnown vulnerabilities remain a common entry path.
What to look forUnsupported systems should have a replacement or isolation plan.
Step 4: Protect endpoints
Verify managed anti-malware/endpoint security is active and reporting on business devices.
Why this step mattersA locally installed product that has stopped checking in is not a verified control.
What to look forManagement should show current status and recent communication.
Step 5: Maintain usable backups
Confirm important data has recoverable copies that are separate from simple synchronization.
Why this step mattersBackup value is proven by restoration, not by a green sync icon.
What to look forAt least one representative restore should be tested.
Step 6: Limit access
Remove accounts and permissions that are no longer required.
Why this step mattersLeast privilege reduces the amount of data and systems exposed by one compromised identity.
What to look forAccess reviews should result in actual removals when appropriate.
Step 7: Secure email and domains
Use anti-phishing controls, protect domain administration, and review mail forwarding/routing.
Why this step mattersEmail remains a major attack path and a common persistence mechanism.
What to look forUnexpected forwarding and administrator changes should be investigated.
Step 8: Document incident response
Make sure staff know who to contact and what not to destroy if a security incident occurs.
Why this step mattersFast escalation and evidence preservation matter during a real incident.
What to look forA short, usable contact-and-actions plan is better than an unread binder.
Step 9: Train staff
Teach users to recognize phishing, suspicious MFA prompts, and unusual requests for credentials or money.
Why this step mattersTechnical controls cannot eliminate every social-engineering attempt.
What to look forStaff should know how to report a suspicious message without interacting further.
Step 10: Review vendors and remote access
Identify outside parties with access and confirm remote access is protected and still needed.
Why this step mattersThird-party access can become forgotten privileged access.
What to look forEvery external access path should have an owner and review date.
Step 11: Track assets
Maintain current device and software inventories.
Why this step mattersUnknown assets are difficult to patch, protect, or retire.
What to look forThe inventory should reconcile with management tools.
Step 12: Schedule recurring review
Recheck these controls after major changes and on a routine schedule.
Why this step mattersSecurity posture changes as people, devices, vendors, and services change.
What to look forThe checklist should have dates, owners, and evidence.
What to look for when you are finished
A successful result should match the business purpose described above, use the smallest necessary access or configuration scope, and leave enough documentation that another authorized administrator can understand what was changed and why.
When to stop and contact IT
Secondary search questions this article answers
- small business cybersecurity checklist
- business cyber security basics
- SMB security checklist
- cybersecurity controls for small business
Authoritative references
Vendor interfaces and licensing can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.
- https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/require-multifactor-authentication
- https://www.cisa.gov/news-events/news/take-first-steps-towards-better-cybersecurity-these-four-goals
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/800-171r3/NIST.SP.800-171r3.html
Need help applying this safely?
J3 Systems Group helps small businesses and nonprofits organize, secure, document, and improve Microsoft 365, Google Workspace, devices, access, and business technology operations.
Contact J3 Systems Group