
Most security checklists list forty items of equal weight and get postponed. This one is ordered by protection per unit of effort, so stopping a third of the way down still helps.
Security checklists tend to fail small businesses in the same way: they list forty items of equal apparent weight, the first three are expensive, and the whole thing gets postponed. What follows is ordered by the ratio of protection to effort, so if you stop a third of the way down you will still have addressed the scenarios that actually happen.
Nothing here requires a security team. Most of it requires an afternoon and a decision.
Tier one: do these before anything else
These four cover the majority of realistic incidents affecting small businesses. If your budget or attention runs out after this section, you have still meaningfully reduced your risk.
1. Multi-factor authentication on every account
Not just administrators, and not just email. Every account that can be reached from the internet — email, file storage, accounting, VPN, remote access, your website's admin, your domain registrar.
Stolen and reused passwords are among the most common ways in. Multi-factor authentication makes a stolen password insufficient on its own, which converts most credential attacks into a failed login. Prefer an authenticator app or hardware key over SMS, which can be intercepted through SIM-swap attacks. Our guide to two-factor authentication covers the differences.
Do not forget the domain registrar. Losing control of your domain means losing your website and your email simultaneously, and recovery is slow.
2. A backup the network cannot reach
Three copies, two types of storage, one out of reach. The last part is the one that matters: a permanently connected drive or a sync folder will be encrypted alongside everything else. Immutable cloud storage, a rotated offline disk, or a backup account with separate credentials all qualify.
Then restore something. A backup that has never been restored is an assumption. Time a substantial restore annually so you know how long recovery actually takes rather than estimating it during an incident.
3. Remove standing administrator rights
Malware runs with the privileges of whoever ran it. If everyday accounts have local administrator rights, an attacker inherits them immediately. Make daily accounts standard users, with a separate administrative credential used only when required.
This is free, takes an afternoon, and limits the damage of most incidents more effectively than any product you could buy.
4. Patch what faces the internet
Comprehensive patching is unrealistic for most small teams. Prioritised patching is achievable. Anything reachable from outside — firewall, VPN, remote access, mail server, website and its plugins — should be patched promptly. Internal machines can follow a slower cycle with automatic updates enabled. Keeping that cycle running is the kind of routine work our IT support team takes on when nobody internally owns it.
Tier two: worth doing this quarter
5. A password manager, and the end of shared logins
Reused passwords mean one breached service compromises several of yours. A business password manager makes unique credentials practical and, more importantly, gives you a way to revoke access when someone leaves.
Shared logins should be replaced with individual accounts wherever the platform allows, because a shared login makes it impossible to know who did what — which matters both for investigation and for accountability.
6. Know who has access to what
Most small businesses accumulate access rather than manage it. Someone gets added to a system for a project and is never removed. A contractor still has a login two years later.
Once a quarter, list your systems and who can reach each one. Remove anything not currently justified. Pay particular attention to former staff, former contractors, and accounts belonging to people who changed roles.
7. Endpoint protection you have actually configured
Business endpoint protection is standard, but its useful features are frequently left off. Enable mass-file-modification alerts, ensure alerts go somewhere a human reads, and confirm every device is actually enrolled — the unmanaged laptop is the one that causes the problem.
8. Separate your networks
Guest wi-fi should not share a network with business machines. Cameras, printers, smart displays and building systems — which often receive infrequent security updates — should sit apart from the devices holding your data. On most business routers this is configuration, not new hardware.
9. Encrypt devices
Full-disk encryption is built into current operating systems and often just needs switching on. It turns a stolen laptop from a data breach with notification obligations into a hardware loss. Verify it is actually enabled rather than assuming.
Tier three: important, less urgent
10. Email authentication for your domain
SPF, DKIM and DMARC records make it harder for anyone to send email that appears to come from your domain. This protects your customers and suppliers from being defrauded in your name, and improves your legitimate email's deliverability. Start DMARC in monitoring mode before enforcing, so you can see what is actually sending as you.
11. A written incident plan
Two pages is enough: who to call, in what order, including your insurer and your IT support; how to isolate a machine; where the backups are and who can restore them; and your regulatory notification obligations and deadlines.
Keep a copy accessible when your systems are not. A plan stored only on the encrypted file server is unavailable exactly when it is needed.
12. Verification habits for money and credentials
Rather than general awareness training, teach a specific rule for a small number of actions: any change to bank details, any unexpected payment request, and any prompt to re-enter credentials after clicking a link gets verified through a channel you already had — a known phone number, not one supplied in the message.
This single habit blocks most invoice fraud and a large share of credential phishing. We cover the behavioural side in more depth in our post on cybersecurity practices for employees.
13. Review third-party access
Accountants, agencies, developers and integrations frequently hold access to your systems. Each is a route in. List them, confirm each is still needed, and remove the ones that are not.
What to be sceptical about
A few things are sold heavily to small businesses and deliver less than their price suggests. Advanced threat platforms that nobody has time to monitor produce alerts into an empty room. Annual penetration tests are valuable for mature environments and premature if you have not yet enabled multi-factor authentication. Cyber insurance is worth having, but read the conditions — policies increasingly require specific controls, and a claim is a poor moment to discover you did not meet them.
Spend on the basics until the basics are genuinely done. They are unglamorous and they are what stops the incidents that actually occur.
Frequently asked questions
Are small businesses actually targeted?
Most attacks are not targeted at all. They begin with automated scanning for exposed services and credential reuse, which finds whoever is vulnerable. Smaller organisations are frequently compromised as a route into a larger customer or supplier.
How much should we spend on security?
The highest-value items on this list — multi-factor authentication, removing administrator rights, network separation, device encryption, access reviews — cost time rather than money. Get through those before evaluating products, because they will outperform most purchases.
Do we need a security certification?
It is worth pursuing if customers or contracts require it. Whichever scheme applies in your market, working through one is a reasonable exercise regardless, since these frameworks map closely to the controls above. Treat it as a framework rather than the objective. Our IT consultancy team can map your current position against it before you commit to certification.
What is the single most common way in?
Credentials, whether phished, reused from another breach, or guessed on a service exposed to the internet. This is why multi-factor authentication is first on the list and why nothing else on it comes close in value.
How often should we review this?
Quarterly for access, monthly for patching and backup success, and annually for a timed restore test and a review of whether your setup still matches how the business operates.
Start at the top
If you do nothing else this month: multi-factor authentication everywhere, one backup the network cannot reach, and daily accounts that are not administrators. Those three address the majority of what actually happens to businesses of your size.
Our web security team reviews these controls and tells you which gaps genuinely matter for your setup rather than selling a package. Get in touch for a straightforward assessment.



