Resources

Small Business Cybersecurity Guide

A practical cybersecurity guide for small and mid-sized businesses covering assets, MFA, patching, endpoint security, backups, email, networks and incident response.

Small and mid-sized businesses do not need a miniature version of a Fortune 500 security department. They need the right controls, applied consistently, with someone accountable for keeping them working.

Small and mid-sized businesses often operate with limited internal IT resources while depending heavily on cloud applications, email, online banking and connected systems.

CISA provides cybersecurity guidance specifically for small and medium businesses.

A practical security program starts with the systems most likely to affect the organization if they fail or are compromised.

Start With Inventory

Document computers, servers, software, cloud systems, network devices and user accounts.

You cannot consistently patch, secure or retire technology that is not inventoried.

Use Multi-Factor Authentication

MFA adds an additional authentication factor beyond a password.

Prioritize email, cloud applications, remote access and privileged accounts.

Patch Systems

Maintain a process for operating-system, application, firewall and network-device updates.

Prioritize actively exploited and internet-facing vulnerabilities.

Secure Endpoints

Business computers should be centrally managed.

Use appropriate endpoint protection, disk encryption, secure configurations and controlled administrative access.

Secure Email

Use technical email protections and train users to identify suspicious requests involving credentials, payments and sensitive information.

Protect Backups

Keep backups protected from the same credentials and systems used in daily operations when possible.

Test restoration.

Secure the Network

Use a business firewall, secure wireless and appropriate network segmentation.

Remove unnecessary internet exposure.

Manage User Access

Give users only the access required for their roles.

Disable access promptly when employees leave.

Monitor Security

Security logging and monitoring improve the ability to detect compromised accounts, malware and suspicious activity.

Prepare for an Incident

Document contacts for management, IT, legal counsel, cyber insurance and key vendors.

Define how compromised systems will be isolated and how the company will continue operating.

Use a Framework

The CIS Critical Security Controls provide a practical, prioritized security framework.

IG1 is designed as a starting point for essential cyber hygiene.

Common questions

Is cybersecurity expensive?

Costs vary, but many foundational controls are process and configuration improvements rather than large capital projects. Organizations should prioritize controls according to business risk.

Do small companies really get attacked?

Attackers routinely target organizations of all sizes. CISA publishes dedicated cybersecurity guidance for small and medium businesses because these organizations face meaningful cyber risk.

Where should a company begin?

Start with inventory, strong authentication, patching, endpoint security, email protection, backups and incident planning.

Sources and further reading

This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.

Ready to move forward?

Want help applying this to your business?

We can look at your current environment and tell you which parts of this guide matter most for you.

Talk With Huff Data