Small Business Cybersecurity Checklist
18 items · Cybersecurity · Hard difficulty · 2 hours
Essential cybersecurity steps for small businesses to reduce breach risk.
-
Identify and map critical assets
List systems that store or process sensitive data and their owners.
-
Create and maintain an asset inventory
Record hostnames, OS, location, owner, and criticality in one place.
-
Configure firewall rules and network segmentation
Use a default-deny approach and separate trust zones.
-
Block unused inbound ports
Close ports at the firewall; allow only required services.
-
Segment networks to separate users and servers
Use VLANs or subnets to limit lateral movement and risk.
-
Enable automatic OS and application patching
Apply critical patches automatically or on a scheduled window.
-
Deploy endpoint detection and response (EDR) on all endpoints
Ensure EDR is centrally managed and alerts are triaged promptly.
-
Enforce multi-factor authentication (MFA) for all accounts
Require MFA for admin and user logins; prefer phishing-resistant methods.
-
Apply least privilege: review and remove unnecessary admin rights
Audit privileges quarterly and adjust roles to minimum required.
-
Secure remote access: enforce VPN and disable direct admin RDP
Use MFA, restrict access by IP, and require jump hosts for admin tasks.
-
Implement automated encrypted backups for critical data
Store backups offsite and encrypt in transit and at rest.
-
Verify backups by performing scheduled restore tests
Test restores quarterly and document recovery time objectives.
-
Implement email protections: SPF, DKIM, DMARC, and inbound filtering
Enable anti-spam, attachment sandboxing, and URL rewriting.
-
Configure centralized logging and alerting; retain logs 90 days
Collect firewall, EDR, and server logs into a central store or SIEM.
-
Create an incident response plan and offline contact list
Document roles, escalation paths, and recovery steps; keep offline copy.
-
Run a tabletop incident response exercise annually
Simulate ransomware or data breach scenarios with stakeholders.
-
Train staff on phishing and secure data handling
Provide regular training and clear steps to report suspicious activity.
-
Run phishing simulations and remediate users with failures
Track repeat offenders and provide targeted coaching.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.