Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a small business building a security baseline, start with multifactor authentication (MFA) on email, file storage, remote access, and administrator accounts; keep software updated; use unique passwords; train staff to spot and report phishing; and maintain isolated backups that you can restore. Add logging, encryption, and a written incident response plan as part of the same operating baseline. These are practical priorities, not a universal ranking: the right controls depend on your business, systems, and obligations.

Where should a small business start?

Start with the accounts and systems that could expose or disrupt the most: business email, shared files, remote access, and administrator accounts. Then reduce routine weaknesses by updating software, managing passwords, training staff, and making sure critical data can be recovered. CISA’s small-business cybersecurity resources present these as practical business measures and include free guidance and tools, including vulnerability-scanning and cloud-configuration resources.

  1. Secure key accounts with MFA. Begin with administrators and people who handle sensitive information, then cover email, file storage, and remote access.
  2. Patch and update. Keep operating systems, business applications, and security tools current, prioritizing internet-facing and business-critical systems.
  3. Make recovery possible. Back up critical data and system configurations, isolate backups from the organizational network, and ensure they can be retrieved and restored.
  4. Reduce phishing and password risk. Teach staff to recognize and report suspicious messages, and use strong, unique passwords.
  5. Prepare to detect and respond. Use logging and encryption where appropriate, and document who makes technical, customer, legal, and continuity decisions during an incident.

How should a business choose an MFA method?

Use the strongest method that works across the business’s identity provider, accounts, and devices. CISA’s MFA guidance ranks physical security keys as its strongest listed option, followed by number matching and authenticator-app one-time codes. Text-message and email codes are weaker fallbacks.

Method How to use it Trade-off
FIDO-compatible physical security key Prefer it where supported for important accounts. CISA gives YubiKey as an example; compatibility varies by service and device. Strong phishing resistance, but check support across email, identity provider, and devices before deployment.
Number-matching authenticator prompt Use when supported, especially if phishing-resistant MFA is not yet available. An interim option; support depends on the service.
Authenticator-app one-time code Use when stronger methods are unavailable and the service supports app codes. Less preferred than phishing-resistant methods.
SMS or email code Reserve as a fallback when stronger methods cannot be used. CISA identifies these as the weakest options in its comparison.

CISA explains that FIDO can block a phishing login attempt when an attacker directs a user to a fake website. Its guidance encourages organizations that cannot yet use phishing-resistant MFA to consider number matching as an interim measure. Before rollout, verify that the chosen method works for the accounts and devices employees actually use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do you keep software from becoming an easy entry point?

Install security updates promptly on operating systems, business applications, and security tools. Prioritize software exposed to the internet and systems central to daily operations. If a device or application no longer receives security support, plan to replace it; it cannot be kept securely patched indefinitely. CISA identifies software updates as a core small-business practice in its SMB guidance.

What makes a backup useful during an incident?

A backup matters only if the business can retrieve and restore it. CISA’s joint guidance for small businesses and managed service providers recommends automatic, continuous backups of critical data and system configurations, kept isolated from the organizational network. Decide where copies are stored, who can access them, and how restoration will be carried out. Check restores periodically; a completed backup job by itself does not establish that recovery will work.

The guidance does not prescribe one recovery-time or recovery-point target for every small business. Set recovery expectations around the data and services your business needs to resume operations.

How should staff handle phishing and password risk?

Give employees a clear way to report suspicious messages, and reinforce that unexpected requests involving credentials or payments should be verified through a known channel—not by replying to the message or using its contact details. Pair awareness with strong, unique passwords; a password manager can reduce the burden of remembering them. CISA includes phishing avoidance and passwords in its small-business essentials and provides password-manager education.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What visibility and response planning should come next?

Enable useful logging on business systems so activity can be reviewed, and encrypt sensitive stored data where appropriate. Write down the first actions to take if an incident occurs and name the people responsible for technical response, customer communication, legal decisions, and business continuity. CISA’s small-business resources identify logging and encryption as next-level practices and point to incident response planning.

Businesses without in-house IT staff can ask an IT or cybersecurity provider to help configure these controls and prepare a response plan. CISA’s guidance also directs businesses to their IT team or provider; it does not endorse a specific vendor.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does this baseline cover every small business?

No. This is general U.S. agency guidance, not a legal compliance checklist or a universal ranking for every industry and threat model. Businesses handling regulated or especially sensitive data may need additional sector-specific controls and advice. Use the baseline to establish priorities, then check applicable obligations and the risks created by your own systems and operations.

Best Value
Sale
HAUTOCO Hardcover Accounting Ledger Book for Small Business Bookkeeping Horizontal Money Expense Tracker Notebook with 2 Storage Pouch, Personal Columnar Log Journal 10.78 x 8'', Black
  • Easy To Track Your Finances: HAUTOCO horizontal accounting ledger book keeps you on top of your expenses and income! Help you keep your money organized, spend well, and set and achieve financial goals
  • Practical Design: The accounting book is PU leather hardcover, with double-wire spiral binding that allows it to lay flat 360°; 100gsm thick paper, comes with an elastic band, pen loop, bookmarks, and 2 large pockets for storing loose notes
  • Plenty of Space: The expense tracking notebook measures 10.78 x 8'' and has 120 pages with 3000 lines of entries giving you enough space to record each of your transactions
  • Manage Your Finances Effectively: Undated accounting books with number, date, description, account, payment or deposit amount, and total balance. You will be able to easily analyze your financial activities and quickly prepare accurate financial statements
  • Ideal For Small Business or Personal Use: An accounting log journal can track your business or personal financial status. With a clear record of transactions, you can find unnecessary expenses or fraudulent charges

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.