Skip to content
All resources
CybersecurityMay 12, 2026·4 min read

A Practical Cybersecurity Checklist for Small Businesses

Cyber threats don't skip small businesses. They target them. Here are the ten essential security controls every SMB should have in place, in plain English.

By Cohesive Security

If you run a small or mid-sized business, it’s tempting to assume cybercriminals are only after the big names. They aren’t. Attackers go after smaller organizations precisely because the data is still worth taking and the defenses are usually thinner. Most attacks are not targeted at you personally either; they are automated, and they find whoever left the door open.

The good news: a handful of foundational controls block the overwhelming majority of them.

Here’s the checklist we walk every new client through.

Key takeaways:

  • Multi-factor authentication (MFA) and consistent patching stop the majority of real-world attacks on their own.
  • Modern endpoint protection (EDR) and tested backups following the 3-2-1 rule turn a potential disaster into an inconvenience.
  • Your team is part of the defense, and short, regular training works better than an annual lecture nobody remembers.
  • Security is ongoing, not one-time. Someone, in-house or a managed partner, must own it.

1. Turn on multi-factor authentication (MFA) everywhere

A stolen password is only dangerous if it’s all an attacker needs. MFA adds a second step (a code, a prompt, a hardware key) that stops the vast majority of account-takeover attempts. Enable it on email, banking, remote access, and every business-critical application. No exceptions.

Two follow-ups worth knowing. Not all MFA is equal, and the kind where someone types a code can still be phished. And it is worth checking whether the passwords underneath have already leaked, which our breached password checker does without sending the password anywhere.

2. Keep everything patched

Most successful breaches exploit vulnerabilities that already had a fix available. Automated patch management for operating systems, browsers, and applications closes those doors before attackers walk through them.

The part businesses miss is everything that isn’t Windows: browsers, PDF readers, the accounting package, and the firewall or router firmware nobody has logged into since it was installed. Set a standard for how quickly critical updates go on, and know which machines are too old to receive them at all.

3. Use modern endpoint protection

Traditional antivirus isn’t enough anymore. Modern endpoint detection and response (EDR) watches for suspicious behavior, not just known malware signatures, and can isolate a compromised device in seconds.

That automatic isolation is the part that matters at 3 a.m. The software contains the problem on its own, and a person reviews it in the morning.

4. Back up your data (and test the restore)

A backup you’ve never restored is just a hope. Follow the 3-2-1 rule: three copies of your data, on two types of media, with one stored offsite or in immutable cloud storage. Then test recovery on a schedule. The ways this quietly fails are worth reading in full: do your backups actually work.

5. Train your team

Your people are both your largest attack surface and your best line of defense. Short, regular training beats an annual session, and realistic phishing simulations are what turn “I know about phishing” into actually pausing over a suspicious message. Our Spot the Phish quiz is a free, no-signup way to see how your team does right now.

6. Lock down email

Email is the number-one entry point for attacks. Layer on spam filtering, anti-phishing, and protections against spoofing (SPF, DKIM, and DMARC) so malicious messages never reach the inbox. Those last three also stop someone sending email that looks like it came from you; our email security checker grades your domain in a few seconds.

7. Apply least privilege

Not everyone needs admin rights. Give each person only the access they need to do their job, and review those permissions regularly. It limits how far an attacker can move if they do get in.

Two habits carry most of the value: administrators should use an ordinary account for everyday email and browsing, and access should be removed the day someone leaves rather than the month after.

8. Secure your network

A properly configured firewall, segmented network, and secured Wi-Fi keep unauthorized traffic out and contain problems when they arise.

9. Have an incident response plan

When something goes wrong at 2 a.m., you don’t want to be improvising. A simple, documented plan (who to call, what to do, how to communicate) turns a crisis into a managed event. Our walkthrough of a ransomware attack covers what the first hour should look like.

10. Get expert eyes on it

Security isn’t a one-time project; it’s an ongoing discipline. The controls above drift: software changes, people join and leave, and a setting someone turned on last year gets turned off during troubleshooting. Whether in-house or through a managed partner, someone has to own monitoring, maintenance, and improvement over time. That ownership is most of what managed IT and our cybersecurity work actually are.

Most of these controls are inexpensive. What’s expensive is skipping them: downtime, data loss, regulatory fines, lost trust.

If you’d like a no-pressure review of where your business stands against this checklist, reach out for a free assessment. We’ll show you exactly where you’re strong and where the quick wins are.

#cybersecurity#small business#best practices#MFA

Enjoyed this article?

Get more like it by email. Short, practical security tips for business owners. No jargon, no spam, unsubscribe anytime.

We only use your email to send the tips. Nothing else, and never shared.

Want help putting this into practice?

Our team can assess your environment and handle the heavy lifting. Start with a free, no-pressure conversation.