Story CIO Landing Family Hobbies News Blog Certifications Contact
IT & MSP

Cybersecurity for Small Business: A Practical Checklist Beyond the Basics

September 24, 2026
Cybersecurity for Small Business: A Practical Checklist Beyond the Basics

Search “cybersecurity for small business” and you get the same list everywhere: use strong passwords, back up your data, train your employees, install a firewall. The FTC and FCC both publish versions of this list, and none of it is wrong. The FCC’s guidance to small businesses starts with training employees on security principles and covers firewalls, mobile device policies, and backups as core steps (FCC). The FTC’s guidance adds encryption, password length requirements, and physical security of devices and paper files (FTC).

The trouble with these lists is the assumption behind them. They read like a compliance checklist for a company that already has an I.T. department to execute them. If you’re an office manager who got handed “cybersecurity” as a responsibility on top of payroll, vendor management, and facilities, a 20-item list with no priority order doesn’t tell you what to do Monday morning.

This is a shorter list, ranked by how much risk each item removes relative to the effort it takes. It assumes you have no internal I.T. department, a limited budget, and other job duties. If that sounds like your situation, you’re not alone. A lot of companies in Chicagoland run this way.

Start here: the four things to fix this month

If you do nothing else this quarter, do these four things. They cover the openings attackers use most often against small businesses with no dedicated security staff.

1. Turn on multi-factor authentication everywhere it’s available. Email, banking, payroll, cloud file storage, remote access: all of it. A stolen or guessed password stops being useful to an attacker the moment a second factor is required. This is also the first thing a cyber insurance underwriter or auditor asks about now, and the requirements around it have gotten specific.

2. Get true backups, separate from synced files. A folder synced to OneDrive or Google Drive won’t save you from ransomware. If ransomware encrypts your files, it encrypts the synced copy too. You need backups that are separated from your main network: offline, in a separate cloud account, or with version history that lets you roll back to a point before an infection. Test that you can restore from them. An untested backup is a guess.

3. Patch and update on a fixed schedule. Both the FTC and FCC list this first for a reason: outdated software is the easiest door in. Turn on automatic updates for operating systems, browsers, and business applications instead of relying on someone to remember. If a piece of software is too old to update, that’s a sign it needs to be replaced.

4. Write down who to call and what to do in the first hour of an incident. Most small businesses have no written plan for the moment someone reports a suspicious email, a locked file, or a wire transfer that looks wrong. Even a one-page document (who gets called, what gets disconnected, who has authority to shut down a system) cuts confusion and cuts the time before outside support arrives.

The next tier: what to fix once the first four are done

Once MFA, backups, patching, and an incident contact list are in place, move to these:

What this costs, and why “cheap” is the wrong question

There’s no single number for what cybersecurity costs a small business. It depends on headcount, industry, compliance requirements, and how much is already in place. What’s consistent is the shape of the tradeoff: doing these things costs money and staff time every month, and skipping them costs money unpredictably, usually at the worst possible time, in the form of downtime, ransom, breach notification, and lost customer trust.

A more useful budgeting question: what risk are we carrying if we skip this, and does that match what we’re willing to lose? For most companies without an I.T. department, the practical path is a managed provider who handles patching, backups, MFA enforcement, and monitoring as a standing service rather than a project.

Do small businesses need this, or is it overkill?

Yes, they need it. Small businesses are targeted specifically because they tend to have weaker defenses than larger companies with dedicated security teams, while still holding the same customer data, bank credentials, and vendor access that make an attack profitable. The FTC and FCC both direct specific small business guidance at this gap, which wouldn’t exist if the risk applied mainly to large enterprises.

The checklist above targets the handful of openings that cause most incidents: no second factor on logins, backups that fail to restore, software that hasn’t been patched in months, and no plan for the first hour after something goes wrong.

When it’s time to stop managing this yourself

An office manager can implement the first tier of this list (MFA, true backups, patch schedules, an incident contact sheet) with a weekend and some patience. Monitoring for threats in real time, keeping up with a changing patch cadence across every device, managing a password manager rollout, vetting vendors, and responding to an incident at 2 a.m. is a different job.

That’s the point where most companies without an internal I.T. department bring in a managed provider or an outsourced CIO relationship: someone accountable for the whole list, including the parts that don’t fit around other job duties. At CIO Landing, that’s the work we take on for companies in the north suburbs that don’t have anyone in-house to own it.

FAQ

Do small businesses need cybersecurity? Yes. Small businesses are frequent targets because they typically have fewer defenses than large enterprises but still hold valuable data: customer records, bank credentials, vendor access. Federal agencies including the FTC and FCC publish dedicated small business cybersecurity guidance because of this gap.

How much does cybersecurity cost for a small business? There’s no fixed number. Cost depends on headcount, industry, and what’s already in place. Rather than searching for the cheapest option, the more useful question is what risk you’re carrying without these protections, since incident costs (downtime, ransom, notification, lost trust) tend to be far higher and less predictable than the cost of prevention.

What is the 80/20 rule in cybersecurity? Applied to small business security, it means a small number of actions (enforcing MFA, maintaining tested backups, patching on schedule, and having an incident response contact list) remove most of the common risk, even before addressing every item on a full compliance checklist.

Is cybersecurity a dying field? No. Demand for security expertise continues to grow as threats evolve, which is part of why small businesses without internal I.T. staff increasingly rely on managed providers rather than trying to keep pace with the field alone.

← Back to all articles