A small-business cyber resilience plan sets out how to manage cyber risk, keep essential work going during a disruption, respond to an incident, and restore services and data. Build it around the systems and people your business depends on, assign clear owners, and practise the steps. NIST’s voluntary Cybersecurity Framework 2.0 and its small-business quick-start guide offer a practical structure; they are starting points, not guarantees of security.
1. Set the plan’s scope and name who owns it
Choose decision-makers
Name one person accountable for keeping the plan usable and a backup decision-maker who can act if that person is unavailable. They do not need to be cybersecurity specialists, but they should know whom to contact for technical, legal, insurance, and operational advice.
For each important action in the plan, identify a role or named person responsible for carrying it out. Include who can approve shutting down a service, contacting outside help, restoring data, and communicating with customers or staff. Avoid relying on a single employee’s memory or personal contact list.
Map essential operations and dependencies
List the work that must continue or be restored first: for example, taking orders, delivering services, processing payments, handling payroll, or supporting customers. For each essential activity, record the systems and information it depends on, the person who administers them, and any outside provider with access.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Include key devices and accounts, email and cloud services, sensitive data, network equipment, payment or booking systems, and vendors that can access business systems. Ask what would happen if email were unavailable, a key account were locked, or files could not be opened. This is a working inventory, not a demand to document every technical detail.
Check which rules and agreements apply
Requirements can depend on the business’s location, industry, information, contracts, and the facts of an incident. Review applicable legal and regulatory duties, insurance conditions, and customer or vendor agreements with qualified advisers where needed. Do not assume that one notification deadline or one regulatory rule applies to every small business.
The FTC’s Cybersecurity for Small Business guidance tells businesses to understand their own legal, regulatory, and contractual requirements. Its separate FTC Safeguards Rule: What Your Business Needs to Know guidance concerns financial institutions covered by that rule; it should not be treated as a universal requirement for small businesses.
2. Organize the work with NIST CSF 2.0
NIST Cybersecurity Framework 2.0 groups cybersecurity risk management into six complementary functions. NIST Special Publication 1300, the Cybersecurity Framework 2.0: Small Business Quick-Start Guide, was published in February 2024 for small and medium-sized businesses with modest or no existing cybersecurity plans. The framework is flexible and voluntary; use it to organize priorities rather than as a certification or promise that incidents cannot happen.
| Function | How it guides a small-business plan |
|---|---|
| Govern | Set ownership, priorities, policies, and an understanding of relevant obligations and dependencies. |
| Identify | Know which systems, data, people, and providers support essential work and where cyber risks could disrupt it. |
| Protect | Put safeguards in place, such as access controls, multifactor authentication, updates, and staff guidance. |
| Detect | Decide how staff will recognize and report suspicious activity or service disruption, and who will assess it. |
| Respond | Coordinate decisions, containment, investigation, communications, and steps to keep essential work operating. |
| Recover | Restore affected systems and data, resume business activities, and improve the plan using lessons learned. |
Use the free NIST SP 1300 quick-start guide to turn these functions into a first set of priorities. A useful first pass is to mark each essential area as already addressed, partly addressed, or needing attention, then choose the gaps that could most interrupt critical work. Give each chosen task an owner and a target date that fits the business’s capacity.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
3. Put routine safeguards in place
Secure accounts and limit access
- Require multifactor authentication (MFA) wherever important business accounts support it, especially email, financial, administrative, and remote-access accounts.
- Use unique passwords for each account. A password manager can help staff avoid reusing credentials.
- Give each person only the access needed for their job, and remove or change access when responsibilities change or someone leaves.
- Review vendor and contractor access, especially remote access. Keep it limited to the work and period required, and know who can disable it.
- Protect sensitive information with encryption where appropriate for the systems and data involved.
The FTC lists authenticator apps, USB hardware tokens, and PIV cards as possible additional login factors. Before choosing a hardware security key or another MFA method, confirm that the business’s accounts and devices support it and establish a workable way to recover access if a factor is lost.
Maintain devices, networks, and staff awareness
- Turn on automatic updates where practical, or schedule updates and assign someone to check that they are applied to business software and devices.
- Use secure Wi-Fi settings and protect network administration credentials. Separate guest access from business resources where the network setup supports it.
- Train employees to recognize suspicious messages and unexpected requests, and make it clear how to report them promptly without fear of blame.
- Make sure staff know how to contact the person responsible for cyber issues if they cannot access normal communication channels.
These are ongoing practices, not one-time setup tasks. The FTC’s small-business cybersecurity guidance covers updates, MFA, access controls, backups, and employee training as basic parts of a cybersecurity program.
4. Make backups and recovery usable
Choose what to copy and where
Identify the data and systems needed to resume essential services, then decide how often they need to be backed up based on how much recent work the business could tolerate losing. The FTC identifies cloud storage and external hard drives as possible backup destinations and recommends keeping backups off the network. Whichever approach you use, avoid a setup in which an attacker who can reach the business network can automatically reach and alter every backup copy.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Record who is responsible for making sure copies run, who is allowed to access them, and how the business would retrieve them if ordinary systems were unavailable. For an external drive, include when it is connected for backup and where it is kept when disconnected. For a cloud service, understand how authorized staff regain access if normal sign-in or business email is disrupted.
Test restoration, not just backup completion
- Select a small but important set of files or a system needed for an essential business activity.
- Have the assigned person restore it using the documented recovery method.
- Check that the restored information opens and is usable for the intended work.
- Record what worked, what access or instructions were missing, and who will fix any gap.
A drive purchase or a dashboard showing that copies ran does not by itself establish that the business can recover. The recovery plan should also say who can restore information and how essential work will continue while restoration is underway.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
5. Write incident and continuity actions people can follow
Prepare the first actions and contacts
Keep a short response sheet that employees and decision-makers can find even if business email or shared files are unavailable. Include the internal contacts, technical support details, key vendor contacts, and any relevant insurer or adviser contacts. Store a copy somewhere accessible without relying on the affected systems.
Write down how to report a suspected incident and who decides what to do next. Depending on the situation, a response may include disconnecting an affected device from the network, disabling a compromised account, or asking a technical specialist to assess the issue. Make clear who is authorized to take these actions; indiscriminately shutting down systems can disrupt operations or complicate investigation.
Keep essential work moving and communicate deliberately
For each critical activity, identify a practical fallback if its usual system is unavailable. Specify how long the fallback can operate, who approves its use, and how any work completed during the disruption will be reconciled afterward. Do not put sensitive customer or business information into an improvised channel without considering its security.
Assign who will communicate with employees, customers, vendors, and authorities as appropriate. Prepare a way to keep those groups informed, but do not make promises about what happened or when systems will return before the facts are known. Applicable communication duties depend on the business and incident; seek qualified advice when needed rather than relying on a universal deadline.
Know when to bring in outside help
If the business lacks experienced IT or cybersecurity staff, plan how to reach qualified technical help before an incident occurs. The FTC says a business may use experienced IT staff or a third-party cybersecurity firm to investigate and mitigate an attack. When evaluating support, clarify the provider’s scope, availability during an incident, relevant experience, recovery assistance, and contractual terms. The cited guidance does not endorse a particular provider.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
6. Practise the plan and keep it current
Run a short scenario exercise
Walk through a realistic disruption with the people assigned roles. For example, assume email is unavailable or important files cannot be opened. Without changing live systems, ask participants to use the response sheet and explain:
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches- Who is the decision-maker and who is the backup?
- How would staff report the problem and reach technical help?
- What action could limit further harm, and who is authorized to take it?
- Which essential work can continue, and by what method?
- Who can restore the needed information, and how will its usability be checked?
- Who will communicate with affected groups, and what facts still need to be confirmed?
Note where a contact is missing, instructions are unclear, access is unavailable, or a recovery step takes longer than the business can accept. Assign someone to fix each gap and update the written plan.
Review after meaningful changes
Revisit the inventory, contacts, access arrangements, and recovery instructions when key systems, staff, vendors, or business processes change. Update the plan after an incident or exercise when it reveals a gap. For businesses covered by the FTC Safeguards Rule, the FTC’s guidance describes additional incident-response plan requirements, including post-event review; coverage should be assessed for the specific business.
The CISA Small and Medium-Sized Business Resources collection is another official place to find security and response resources suited to smaller organizations.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

