Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Most small businesses should start by securing the accounts, devices, and services they already use—not by buying a large security bundle. Turn on multi-factor authentication (MFA), apply updates, change default passwords, train staff, and maintain protected backups that you have tested. If you want one physical security purchase, a compatible hardware security key can strengthen MFA for accounts that support it.

What should a small business buy first?

Buy only to close a specific security gap. Before shopping, check whether your business accounts and devices already include the controls you need. NIST describes cybersecurity as “a continuous process” and recommends measures such as MFA, software updates, backups, phishing awareness, and employee training in its Cybersecurity Basics.

  • For account protection: enable MFA on business email, cloud storage, remote access, administrator accounts, and other sensitive services. Prefer phishing-resistant MFA when the service supports it.
  • For recovery: set up routine backups, protect them from unauthorized access or ransomware, and test that you can restore files.
  • For devices and networks: update software and firmware, replace default passwords, and configure existing routers securely before considering replacement.
  • For people and operations: train staff to recognize phishing and ransomware, and plan how the business will respond to a breach and notify customers if necessary.

These are general U.S. federal recommendations, not a substitute for checking the laws, contracts, insurance terms, or regulated-data obligations that apply to your business.

Which purchases may be worth making?

Compare each purchase against the gap it addresses, its compatibility with your existing services and equipment, whether it receives updates, how it can be managed and recovered, and its ongoing cost and staff effort. The table summarizes sensible purchase cases; it does not imply that every business needs each item.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Purchase When it may help Check before buying
Hardware security key When an account supports stronger MFA and you want a physical authentication option, particularly for administrators or staff accessing sensitive data. Confirm the service supports the key’s authentication standard, the staff device has the right connector, and account recovery is workable. A key will not work with every account.
External backup drive When you need a separate copy of important business files. The FTC recommends making backups part of routine operations and describes storing copies separately from the network to aid recovery from ransomware. Plan how the drive and backup copies will be protected, kept separate or disconnected when feasible, and tested through restoration. A drive alone does not make backups reliable.
Router When existing equipment cannot receive security updates or cannot be configured to meet your needs. First check whether the current router supports secure administration, current firmware, WPA2 or WPA3, and a separate guest network.
Antivirus or security software When you need protection or management capabilities not provided by your current setup. NIST recommends keeping antivirus updated, and the FTC recommends security software. Official guidance does not name a vendor or establish that every small business needs to buy a new paid product. Check compatibility, update support, and management needs.
Staff training service When a structured program would help staff learn to recognize current phishing and ransomware tactics. Staff training is recommended, but paying a vendor is optional. No particular training provider is endorsed by the cited guidance.

How should you choose and set up a hardware security key?

A hardware key is a useful physical MFA option only when the accounts your business relies on support it. The FTC identifies a USB hardware token as one way to add an authentication factor, while CISA recommends using the strongest available MFA option, including phishing-resistant methods where possible.

  1. Identify the accounts: check the MFA settings for business email, cloud storage, remote access, and administrator accounts. Prioritize administrator accounts and employees handling sensitive data, as CISA advises.
  2. Verify support and fit: confirm that each service accepts the key’s authentication method and that the computers or phones used by staff have a compatible connector or connection option.
  3. Plan recovery: review each account’s recovery options before enabling the key. Keep recovery procedures available so a lost or damaged key does not lock the business out.
  4. Enroll and test: follow the service’s own security settings to register the key, then verify sign-in and recovery on the relevant accounts before relying on it.

Do not assume one key works with every service, or that any government agency endorses a particular brand.

Rank #2
Glovary Firewall Mini PC J3710 Quad Core, 4 x i225V 2.5GbE LAN Fanless OPNsense Appliance, 8GB RAM 128GB SSD, Micro Router Computer Hardware, AES-NI, HD+DP Dual Display, Console, 2USB3.0, SPK/MIC
  • Quad Core J3710 Processor: F3 firewall hardware with Pentium J3710 Processor, 4 Cores 4 Threads, 2M Cache, up to 2.64 GHz, TDP 6.5 W. Compatible with OPNsense, Linux, ESXi, Proxmox
  • 4 x i225V 2.5GbE LAN: J3710 mini pc with 4 x i225V 2500Mbps LAN, can monitor network data, improve network security, powerful and widely used
  • DDR3 RAM mSATA Slot: J3710 firewall pc with 1 x DDR3L SO-DIMM memory, 1 x mSATA SSD slot, 1 x SATA 3.0 slot(SATA Cable included), 1 x Mini-PCIe Slot
  • HD DP Dual Display: Micro firewall appliance J3710 integrated HD Graphics, HD + DP dual display interfaces improve work efficiency
  • Fanless Mini Size: Firewall appliance J3710 with aluminium alloy body, fanless quiet running without noise. Size only 11 x 10 x 3.5 cm

What can you secure without buying new hardware?

Configuration and maintenance often close basic gaps without replacing equipment. The FTC’s Cybersecurity for Small Business guidance covers router settings, encryption, secure remote access, training, and incident response.

  • Use unique, strong passwords; consider a password manager if staff need help creating and managing them.
  • Change manufacturer-default passwords on routers and other devices, and disable router remote management if it is not needed.
  • Use WPA2 or WPA3 Wi-Fi security and separate guest access from business devices where the router supports it.
  • Install software and firmware updates promptly, and keep antivirus or security software current.
  • Limit access to what each employee needs, and secure remote access to business systems.
  • Train staff regularly, refreshing guidance as phishing tactics change.

Replace a router only if it cannot support the updates or security settings your business needs; buying a new one is not a substitute for configuring it securely.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
FortiGate-40F Firewall Appliance plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) (FG-40F-BDL-950-12)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do you make backups useful against ransomware?

Back up important business files routinely, protect the copies, and test restoration. The FTC’s guidance recommends making backups part of routine business operations and describes storing them separately from the network to support recovery from ransomware.

  • Decide which files and business records must be recoverable.
  • Keep backup copies protected from unauthorized access and, where feasible, separate or disconnected from the network.
  • Test that files can actually be restored, rather than assuming a completed backup job means recovery will work.

Where should a small business start with a risk-based plan?

NIST’s NIST Cybersecurity Framework 2.0: Small Business Quick-Start Guide, published February 26, 2024, is intended for small and medium-sized businesses with modest or no existing cybersecurity plans. It supplements the Cybersecurity Framework 2.0 rather than replacing it. Use it to organize priorities around your business’s risks instead of treating a shopping list as a security plan.

As you consider each purchase, ask what risk it reduces, whether it works with your accounts and equipment, how it will be updated and managed, how recovery will work, and what it will cost in staff time as well as money. Official guidance here is general U.S. advice; obligations can differ by industry, jurisdiction, customer contract, or cyber-insurance policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.