A Small-Business Cybersecurity Checklist You Can Actually Verify

“Our IT person handles it” is not a useful answer when you cannot access your email, approve payroll, or recover a website. A better small-business cybersecurity checklist identifies what must work, who is responsible, and what evidence shows the protection is in place. Start with the services whose loss would stop the business, not with a shopping list of products.

The NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide is designed to help organizations begin managing cybersecurity risk. The practical checks below are a starting routine, not a certification, penetration test, or substitute for security advice tailored to your systems.

1. Know who controls the accounts that matter

List the business email system, domain registrar, website hosting, accounting software, payment services, payroll, and essential cloud storage. For each, record the business owner, administrator, recovery method, and support contact. Keep this inventory protected. Do not include passwords in a broadly shared spreadsheet.

A useful verification question is: if the usual administrator were unavailable tomorrow, could an authorized backup person regain access without borrowing that administrator’s identity? Test the recovery process carefully with your provider or IT professional. Do not lock out a working account in the name of testing it.

2. Improve sign-ins, starting with email and administrators

NIST’s multifactor-authentication guidance explains that an additional authentication factor reduces reliance on a password alone. It also distinguishes phishing-resistant approaches, including suitable FIDO/WebAuthn authenticators, from methods such as text-message codes that can still be phished. Use the strongest practical option your service supports, particularly for sensitive or administrative access.

Do not confuse “the service offers MFA” with “all relevant accounts require it.” Check enforcement and exceptions. Confirm that recovery codes are securely stored, obsolete phone numbers are removed, and the backup administrator has their own credentials. Record the date the control was checked without copying secret recovery material into the checklist.

3. Give people only the access their work needs

NIST’s same guidance recommends limiting sensitive access and administrative privileges, and removing access when needs change or people leave. Turn that principle into a short review: who can publish website content, change payment details, invite users, export customer records, or delete backups? Those are different responsibilities and need not all belong to every employee.

Use a hypothetical departure as a tabletop test. Walk through the accounts an employee or contractor would leave behind. Would revoking the main email also revoke the other services? Would shared links or separate application tokens remain active? Have your administrator verify the actual configuration; do not assume a single password reset disconnects everything.

4. Check updates and backups separately

The FTC’s small-business cybersecurity guidance recommends keeping software updated and backing up important information. An update reduces certain risks; a backup supports recovery. Neither is evidence that the other has happened. Ask for the most recent successful update check and backup result rather than accepting one general “all good” message.

For a website, agree on what the backup includes: files, database, uploads, and relevant configuration. For cloud business tools, determine what your subscription actually allows you to restore. Then arrange a controlled recovery test into an isolated location that cannot send real customer messages, take payments, or overwrite live records.

Write down what was restored, whether it opened correctly, and how long the test took. A backup-success email is useful evidence of one step; it is not a demonstration that your complete business workflow can be recovered. Keep access to recovery instructions available through an appropriate secure channel that does not depend solely on the system you are trying to restore.

5. Make sensitive changes harder to rush

Create a verification step for new payment instructions, bank-detail changes, unexpected document-sharing requests, and urgent login prompts. A practical rule is to confirm the request through a previously established contact method rather than a phone number or link supplied in the suspicious message. Document who can approve an exception and why.

Practice with an invented scenario: a familiar supplier’s email asks for payment to a new bank account. The exercise should end with independent verification, not a test transfer. Keep the training focused on the decision and escalation route. Do not use real customer data or embarrass an employee as part of the exercise.

6. Write a one-page incident plan

The FTC recommends having a response plan. Start with the people to contact, the systems that matter most, and how essential work would continue during disruption. Its Data Breach Response: A Guide for Business provides a broader response framework. Notification duties depend on the incident, contracts, and applicable law; do not invent a universal deadline.

Have qualified responders advise on containment and preserving evidence. The business checklist should make it easy to reach them, not encourage employees to improvise an investigation or delete material that may be needed. Keep your insurer’s and relevant service providers’ contact routes with the plan where appropriate.

What evidence should the checklist contain?

  • Accounts: a current inventory and named primary and backup owners.
  • Sign-ins: the date MFA enforcement and recovery settings were checked.
  • Access: a reviewed list of administrators and completed offboarding actions.
  • Recovery: the last backup result and a separate record of a restore test.
  • Response: verified contact details and a recorded tabletop exercise.

Assign one owner and a next-review date to each unresolved item. Start with the gap that could most directly stop the business, then work through the rest. Keep the results private rather than publishing details of your defenses. Good operations also support trust in a business, but no checklist or software product guarantees that an incident cannot happen.

General educational information, not an individualized security assessment or legal advice. Prepared with AI assistance; sources checked during preparation on September 27, 2026. Consult an appropriately qualified professional before making changes that could disrupt business systems.