Small and mid-sized businesses do not need a miniature version of a Fortune 500 security department. They need the right controls, applied consistently, with someone accountable for keeping them working.
Small and mid-sized businesses often operate with limited internal IT resources while depending heavily on cloud applications, email, online banking and connected systems.
CISA provides cybersecurity guidance specifically for small and medium businesses.
A practical security program starts with the systems most likely to affect the organization if they fail or are compromised.
Start With Inventory
Document computers, servers, software, cloud systems, network devices and user accounts.
You cannot consistently patch, secure or retire technology that is not inventoried.
Use Multi-Factor Authentication
MFA adds an additional authentication factor beyond a password.
Prioritize email, cloud applications, remote access and privileged accounts.
Patch Systems
Maintain a process for operating-system, application, firewall and network-device updates.
Prioritize actively exploited and internet-facing vulnerabilities.
Secure Endpoints
Business computers should be centrally managed.
Use appropriate endpoint protection, disk encryption, secure configurations and controlled administrative access.
Secure Email
Use technical email protections and train users to identify suspicious requests involving credentials, payments and sensitive information.
Protect Backups
Keep backups protected from the same credentials and systems used in daily operations when possible.
Test restoration.
Secure the Network
Use a business firewall, secure wireless and appropriate network segmentation.
Remove unnecessary internet exposure.
Manage User Access
Give users only the access required for their roles.
Disable access promptly when employees leave.
Monitor Security
Security logging and monitoring improve the ability to detect compromised accounts, malware and suspicious activity.
Prepare for an Incident
Document contacts for management, IT, legal counsel, cyber insurance and key vendors.
Define how compromised systems will be isolated and how the company will continue operating.
Use a Framework
The CIS Critical Security Controls provide a practical, prioritized security framework.
IG1 is designed as a starting point for essential cyber hygiene.
Common questions
Is cybersecurity expensive?
Costs vary, but many foundational controls are process and configuration improvements rather than large capital projects. Organizations should prioritize controls according to business risk.
Do small companies really get attacked?
Attackers routinely target organizations of all sizes. CISA publishes dedicated cybersecurity guidance for small and medium businesses because these organizations face meaningful cyber risk.
Where should a company begin?
Start with inventory, strong authentication, patching, endpoint security, email protection, backups and incident planning.
Sources and further reading
This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.
