Recommended Free Tools
Protect your organization by securing accounts, keeping systems updated, protecting and testing backups, and preparing to detect and respond to incidents. No checklist can guarantee that an attack will not happen; these steps help reduce risk and limit disruption. Tailor them to your organization’s size, sector, systems, data, and resources.
For a way to organize the work, CISA’s voluntary Cross-Sector Cybersecurity Performance Goals (CPGs) identify prioritized baseline actions. NIST’s Cybersecurity Framework 2.0: Small Business Quick-Start Guide, published in February 2024, is designed especially for smaller organizations with modest or no existing cybersecurity plans. It supplements the framework rather than replacing it.
1. Identify the systems, accounts, and data that matter most
Start with a practical inventory—not just computers in the office. Include important user and administrator accounts, devices, business data, externally hosted services, and the operations that depend on them. Assign a person or team to own each important system and understand what would stop working if it became unavailable or compromised.
- List the systems and services your organization relies on, including those hosted or managed by outside providers.
- Identify where sensitive or business-critical data is stored and who needs access to it.
- Record dependencies between systems and essential business operations.
- Review the inventory when technology, suppliers, data, or business processes change.
CISA organizes its CPGs around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Use them or NIST’s CSF 2.0 to structure the work, then prioritize based on your own risks and ability to maintain the controls.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
2. Secure accounts and remote access
Stolen or misused credentials can expose email, business systems, and sensitive data. Apply account protections first to administrator accounts, remote access, email, and staff who handle sensitive information.
- Require multifactor authentication (MFA) wherever it is available, prioritizing the accounts above.
- Prefer phishing-resistant MFA where your identity provider and applications support it. CISA identifies hardware-based FIDO or Public Key Infrastructure (PKI) tokens as strong options.
- Use strong, unique passwords for accounts, and replace manufacturer default passwords.
- Consider a password manager to help staff maintain unique credentials.
- Before deploying a hardware security key, check that the relevant systems support it and establish how users can recover access if a key is lost.
CISA says any MFA is better than none while recommending phishing-resistant forms. Compare available MFA methods against phishing resistance, compatibility with your identity provider and applications, account-recovery options, and the effort required to deploy and support them. A FIDO2 security key is an option only where the organization’s systems support it.
3. Keep software and devices maintained
Security controls need upkeep. Install operating-system and software updates when they become available, and maintain updated antivirus protection on relevant devices.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Establish who is responsible for applying updates and maintaining endpoint protection.
- Remove accounts and services that are no longer needed, or secure them if they must remain.
- Include systems managed by outside providers in your maintenance responsibilities and follow up on who handles updates and protection for them.
NIST’s Cybersecurity Basics calls for updating and patching software when new versions are available. The right operating process depends on the systems you use, but an update that is forgotten or an unused account left active can undermine other protections.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
4. Make phishing easier to report and harder to exploit
Train employees on basic security hygiene, how to recognize phishing and ransomware, and what to do when something looks suspicious. Give staff a clear, quick way to report suspicious messages so someone can assess them promptly.
- Explain where and how to report a suspicious message or unexpected account activity.
- Make sure reports reach a person or team responsible for reviewing them.
- Pair training with MFA and other account protections; do not rely on training alone.
CISA and NIST include awareness and phishing guidance in their small-business resources. Training is most useful when staff know how to act and the organization has a process for handling reports.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
5. Protect backups and prove you can restore them
Back up business data regularly, protect backup copies against unauthorized access or alteration, and test restoration. A backup is not a dependable recovery option until you know you can use it to restore the data and systems you need.
- Decide how much data the organization can afford to lose and how quickly essential operations must resume.
- Use those organization-specific targets to set backup frequency and retention.
- Restrict access to backup copies and protect them from unauthorized changes.
- Test restoration, and include the recovery steps in exercises or planned reviews.
The appropriate backup schedule and retention period depend on your organization’s needs; there is no single frequency that fits every business.
6. Prepare to detect, respond, and recover
Prevention is only part of cybersecurity. Decide how your organization will notice a problem, contain it, make decisions, and restore operations. Enable and review appropriate logs for business systems so someone can assess alerts and investigate suspicious activity.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Assign responsibility for reviewing alerts and deciding whether an incident needs action.
- Decide who can isolate an affected account or device and how that action will be taken.
- Identify who must be contacted, as applicable: leadership, IT providers, legal counsel, insurers, regulators, or law enforcement.
- Maintain an incident response plan and exercise response and recovery steps.
CISA’s guidance includes Detect, Respond, and Recover alongside Govern, Identify, and Protect. That structure helps keep the plan focused on more than stopping attacks before they begin.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.7. Review the checklist as your organization changes
Cybersecurity is ongoing risk management, not a one-time setup. Revisit the checklist after significant business or technology changes, after an incident, and during planned reviews. NIST describes cybersecurity as continuous improvement because businesses, technologies, regulations, and threats change.
When deciding what to implement next, compare expected risk reduction, fit with existing systems, implementation effort, ongoing maintainability, and whether you can verify that the control works. CISA says its CPGs are selected for significant risk reduction, clear actionability, and reasonable implementability, while allowing organizations to tailor actions to their maturity, technology, risks, and sector.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteBest Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What this checklist does—and does not—establish
CISA’s CPGs are voluntary prioritization guidance; using them does not by itself establish compliance with the NIST Cybersecurity Framework or any law. This general checklist is not a sector-specific implementation plan or legal compliance opinion. Organizations in regulated or critical-infrastructure sectors may have additional requirements depending on jurisdiction, industry, contracts, and the data they handle.
Sources for this guidance include CISA’s Cross-Sector Cybersecurity Performance Goals, CPG FAQ, small-business resources, MFA guidance, and Take the First Steps Towards Better Cybersecurity With These Four Goals; and NIST’s Cybersecurity Framework 2.0: Small Business Quick-Start Guide and Cybersecurity Basics. NIST lists Cybersecurity Basics as updated August 26, 2026.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

