Primary search intentsmall business cyber security checklist

Why this matters

Small organizations do not need hundreds of controls to make meaningful progress. They do need a short list of high-impact protections that are actually implemented and reviewed.

Before you begin

  • Identify the person responsible for technology security.
  • List the organization's core systems and data.
  • Record current control status honestly as verified, partial, missing, or unknown.
  • Do not mark a control complete simply because a policy says it should exist.

Step-by-step instructions

Step 1: Require MFA

Verify MFA for email, remote access, cloud platforms, and especially administrator accounts.

Why this step matters

MFA blocks many attacks that rely only on a stolen password.

What to look for

Test a real sign-in rather than relying on an unchecked policy box.

Step 2: Separate privileged accounts

Ensure admins use separate privileged and standard identities where the platform supports it.

Why this step matters

This reduces exposure of high-value credentials.

What to look for

Admin accounts should not be used for routine email and browsing.

Step 3: Patch supported systems

Confirm operating systems, browsers, applications, firewalls, and other managed systems receive security updates.

Why this step matters

Known vulnerabilities remain a common entry path.

What to look for

Unsupported systems should have a replacement or isolation plan.

Step 4: Protect endpoints

Verify managed anti-malware/endpoint security is active and reporting on business devices.

Why this step matters

A locally installed product that has stopped checking in is not a verified control.

What to look for

Management should show current status and recent communication.

Step 5: Maintain usable backups

Confirm important data has recoverable copies that are separate from simple synchronization.

Why this step matters

Backup value is proven by restoration, not by a green sync icon.

What to look for

At least one representative restore should be tested.

Step 6: Limit access

Remove accounts and permissions that are no longer required.

Why this step matters

Least privilege reduces the amount of data and systems exposed by one compromised identity.

What to look for

Access reviews should result in actual removals when appropriate.

Step 7: Secure email and domains

Use anti-phishing controls, protect domain administration, and review mail forwarding/routing.

Why this step matters

Email remains a major attack path and a common persistence mechanism.

What to look for

Unexpected forwarding and administrator changes should be investigated.

Step 8: Document incident response

Make sure staff know who to contact and what not to destroy if a security incident occurs.

Why this step matters

Fast escalation and evidence preservation matter during a real incident.

What to look for

A short, usable contact-and-actions plan is better than an unread binder.

Step 9: Train staff

Teach users to recognize phishing, suspicious MFA prompts, and unusual requests for credentials or money.

Why this step matters

Technical controls cannot eliminate every social-engineering attempt.

What to look for

Staff should know how to report a suspicious message without interacting further.

Step 10: Review vendors and remote access

Identify outside parties with access and confirm remote access is protected and still needed.

Why this step matters

Third-party access can become forgotten privileged access.

What to look for

Every external access path should have an owner and review date.

Step 11: Track assets

Maintain current device and software inventories.

Why this step matters

Unknown assets are difficult to patch, protect, or retire.

What to look for

The inventory should reconcile with management tools.

Step 12: Schedule recurring review

Recheck these controls after major changes and on a routine schedule.

Why this step matters

Security posture changes as people, devices, vendors, and services change.

What to look for

The checklist should have dates, owners, and evidence.

What to look for when you are finished

A successful result should match the business purpose described above, use the smallest necessary access or configuration scope, and leave enough documentation that another authorized administrator can understand what was changed and why.

When to stop and contact IT

Stop conditionIf the checklist reveals active compromise indicators, unexpected administrator accounts, ransomware, suspicious forwarding, or data exposure, stop routine hardening and escalate through the incident-response process.

Secondary search questions this article answers

  • small business cybersecurity checklist
  • business cyber security basics
  • SMB security checklist
  • cybersecurity controls for small business

Authoritative references

Vendor interfaces and licensing can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.

Need help applying this safely?

J3 Systems Group helps small businesses and nonprofits organize, secure, document, and improve Microsoft 365, Google Workspace, devices, access, and business technology operations.

Contact J3 Systems Group
KB-07.014 · Primary query: small business cyber security checklist · Last reviewed 2026-08-21