Small-business cybersecurity is not a product you buy once. It is a set of decisions and operating habits covering people, accounts, devices, email, networks, cloud systems, vendors, backups, incidents, and recovery. CISA’s small-business resources emphasize phishing awareness, strong passwords, multifactor authentication, software updates, logging, backups, and encryption. NIST’s Cybersecurity Framework helps organizations organize those activities around governance, identification, protection, detection, response, and recovery.
This checklist turns that guidance into a practical starting sequence. The right order depends on your data, contractual requirements, industry, exposure, and current environment. Record exceptions and risk decisions instead of marking an item complete when the control is only partially deployed.
1. Assign cybersecurity ownership
- Name an executive decision-maker and technical owner.
- Identify legal, insurance, communications, privacy, and vendor contacts.
- Define how risks are accepted, funded, tracked, and reviewed.
- Keep policies short enough to follow and update them when systems change.
Security work stalls when every issue belongs vaguely to “IT.” Leadership owns business risk; technical teams implement and report controls.
2. Inventory systems, data, accounts, and vendors
List devices, servers, network equipment, cloud tenants, domains, applications, administrative accounts, service accounts, sensitive information, backups, internet connections, remote-access methods, and third parties. Mark business owners, technical owners, support status, and criticality. You cannot reliably protect or recover an unknown dependency.
3. Strengthen identity and privileged access
- Give every person a unique account and prohibit shared administrator use.
- Require MFA for email, cloud services, remote access, and privileged systems.
- Prefer phishing-resistant authentication where it is supported and practical.
- Separate administrator accounts from normal email and web activity.
- Use least privilege and review administrators, guests, and stale accounts.
- Store recovery methods securely and test emergency access.
4. Maintain supported and updated technology
Set schedules for operating systems, browsers, applications, firmware, firewalls, switches, access points, and internet-facing services. Prioritize actively exploited vulnerabilities and exposed systems. Replace unsupported equipment and software or document compensating controls and a removal plan.
5. Defend email and payment workflows
Use anti-phishing and anti-malware controls, external sender indicators, domain email authentication, safer attachment and link handling, and a simple reporting process. Require a second-channel verification for bank changes, payroll changes, gift cards, credential requests, and other unusual transactions. Review forwarding rules and mailbox delegates after suspected compromise.
6. Protect computers and mobile devices
- Use centrally managed endpoint protection where possible.
- Enable disk encryption on portable devices that handle business information.
- Remove unnecessary local administrator rights.
- Enforce screen locks, update policies, and supported configurations.
- Define rules for personal devices and remote work.
- Maintain a process for lost, stolen, replaced, and retired devices.
7. Secure networks and remote access
Change default credentials, keep network equipment supported, restrict management access, separate guests and untrusted devices from business systems, and review firewall rules. The FTC recommends secure remote connections, WPA2 or WPA3 for wireless networks, device security standards, MFA for sensitive access, and security terms in vendor contracts.
8. Build backups around recovery
Identify every critical data source, including cloud services and application data. Define recovery point and recovery time objectives, retention, protected or separated copies, monitoring, and ownership. Test representative restores and a broader recovery sequence. A successful backup job does not prove people can resume operations.
9. Collect useful logs and alerts
Enable appropriate logging for identity, email, endpoints, firewalls, cloud systems, and critical applications. Decide who reviews alerts, how severity is assigned, what evidence is retained, and when outside help is called. Logging without an owner is storage, not detection.
10. Train employees and make reporting easy
Teach staff to recognize phishing, impersonation, unusual payment requests, unsafe remote-support calls, lost-device procedures, and the organization’s reporting channel. Include security in new-hire orientation, repeat training, and use realistic exercises. Reward fast reporting; hidden mistakes create more damage than quickly escalated ones.
11. Control vendor risk and access
- Inventory vendors with access to systems or sensitive information.
- Document security, notification, retention, deletion, and exit requirements.
- Limit access to the systems and time necessary for the work.
- Require unique accounts and strong authentication.
- Remove access when projects or relationships end.
- Confirm critical vendors’ recovery and incident contacts.
12. Prepare and exercise incident response
Create a short plan with contacts, authority, initial containment considerations, evidence preservation, insurance notification, legal and regulatory coordination, communications, vendor roles, and recovery priorities. Exercise scenarios such as email takeover, ransomware, lost equipment, vendor compromise, and unavailable cloud services.
13. Measure the controls that matter
Track coverage and exceptions: MFA enrollment, administrator count, supported devices, patch status, endpoint protection, backup success and restore tests, training completion, stale accounts, external guests, unresolved high-risk findings, and incident lessons. Trends help leadership see whether risk is improving or simply moving.
Turn the checklist into a 30-60-90 day roadmap
First 30 days
Assign owners, inventory critical systems and admins, protect privileged access, require MFA, address exposed unsupported systems, verify backup coverage, and publish incident contacts.
Days 31–60
Strengthen email and device controls, review remote and vendor access, separate guest traffic, test selected restores, implement logging priorities, and begin employee training.
Days 61–90
Exercise incident and recovery procedures, close documentation gaps, review remaining risks with leadership, assign budgets and dates, and establish a recurring review cycle.
Odyssey provides Houston business IT support, managed technology services, and practical cybersecurity coordination. No checklist or single tool guarantees security; the value comes from implemented controls, accountable owners, testing, and continuous improvement.
Authoritative guidance
- CISA: Small and Medium-Sized Business Resources
- NIST: CSF 2.0 Small Business Quick-Start Guide
- FTC: Cybersecurity for Small Business
- Microsoft: Security Best Practices for Microsoft 365 Business
This is general cybersecurity guidance, not legal, regulatory, insurance, or incident-response advice. Requirements vary by organization and data.


