Back
🛡️
Small Business Cybersecurity Checklist
Hard
18 items
·
2 hours
testuser
Published 4 weeks ago
A practical checklist to help small businesses secure networks, endpoints, and data. Ideal for small IT teams, managed service providers, and business owners who want a prioritized, actionable roadmap to reduce cyber risk.
Progress
0 / 18
- Identify and map critical assets — List systems that store or process sensitive data and their owners.
- Create and maintain an asset inventory — Record hostnames, OS, location, owner, and criticality in one place.
- Configure firewall rules and network segmentation — Use a default-deny approach and separate trust zones.
- Block unused inbound ports — Close ports at the firewall; allow only required services.
- Segment networks to separate users and servers — Use VLANs or subnets to limit lateral movement and risk.
- Enable automatic OS and application patching — Apply critical patches automatically or on a scheduled window.
- Deploy endpoint detection and response (EDR) on all endpoints — Ensure EDR is centrally managed and alerts are triaged promptly.
- Enforce multi-factor authentication (MFA) for all accounts — Require MFA for admin and user logins; prefer phishing-resistant methods.
- Apply least privilege: review and remove unnecessary admin rights — Audit privileges quarterly and adjust roles to minimum required.
- Secure remote access: enforce VPN and disable direct admin RDP — Use MFA, restrict access by IP, and require jump hosts for admin tasks.
- Implement automated encrypted backups for critical data — Store backups offsite and encrypt in transit and at rest.
- Verify backups by performing scheduled restore tests — Test restores quarterly and document recovery time objectives.
- Implement email protections: SPF, DKIM, DMARC, and inbound filtering — Enable anti-spam, attachment sandboxing, and URL rewriting.
- Configure centralized logging and alerting; retain logs 90 days — Collect firewall, EDR, and server logs into a central store or SIEM.
- Create an incident response plan and offline contact list — Document roles, escalation paths, and recovery steps; keep offline copy.
- Run a tabletop incident response exercise annually — Simulate ransomware or data breach scenarios with stakeholders.
- Train staff on phishing and secure data handling — Provide regular training and clear steps to report suspicious activity.
- Run phishing simulations and remediate users with failures — Track repeat offenders and provide targeted coaching.
Your Stats
🏆
0
Completed
📅
—
Last Done
⏱️
—
Last Time
Completion Rate
Items checked per run
⚡
—
Fastest Run
🔥
0
Streak
🚫
—
Most Skipped Step
🔄
0
Resets
📝 My Notes