A Basic Cybersecurity Routine for a Small Business

A small business might rely on one email account to reach customers, one cloud service to book work and one shared device to access records. A lost password, departed employee or failed recovery process can interrupt all three. A basic routine makes responsibility and recovery visible, even if no one on the team is a full-time security specialist.

The NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide is intended for businesses with modest or no cybersecurity plan. CISA’s small-business resources cover practical actions including multifactor authentication, updates and backups. The routine below is a suggested starting point, not a certification or guarantee of security.

Identify what must keep working

List essential services: business email, booking or point of sale, payment access, customer records, the website and any specialist work system. For each, record a business owner, administrator, approved users, recovery contact and where the restoration instructions are kept. Store the list securely and keep recovery details separate from a publicly accessible checklist. Prioritize systems whose loss would stop customer service or prevent access to important records.

A repeatable four-part routine

  1. Review access: Once a month and whenever someone joins, changes role or leaves, compare actual users with the people who still need access. Remove old access promptly, use individual accounts where possible and check administrative permissions separately.
  2. Strengthen sign-in: Enable multifactor authentication on important accounts and use a secure method for unique passwords. Make sure account recovery does not depend entirely on one person’s phone.
  3. Check backups and recovery: Identify which records are backed up, how often, where copies are kept and who can restore them. Periodically restore a small, safe sample and record whether it worked. CISA’s ransomware guide emphasizes testing backup procedures and protecting copies from the same incident that affects the main system.
  4. Update and prepare: Check that supported devices and business software receive security updates. Maintain a short contact list for the person who can contain a problem, the service providers involved and the person authorized to communicate with customers.

Choose a cadence that matches risk and capacity; the monthly access check is an example, not a universal rule. An automatic backup notification is useful but does not show that a restore will succeed. Likewise, a software update marked “available” is different from one installed successfully. Record exceptions and assign someone to resolve them.

Test one part first

Illustrative example: A six-person design studio uses email, a shared file service and a booking tool. The owner starts with the shared file service. The account list shows eight users, including one former contractor; multifactor authentication is enabled for five, and nobody remembers testing a restore. The owner removes access that is no longer justified, enables or plans MFA for remaining users and asks the service provider how to recover one non-sensitive sample file.

A week later the owner records the number of access reviews completed out of three priority systems, whether the sample restore succeeded and how many important updates are overdue. These counts are hypothetical; they are a work list, not a measure of guaranteed safety. The studio then repeats the exercise for email and bookings. If the provider cannot explain restoration or ownership of the account, that is an issue to resolve rather than a box to tick.

What to do when something seems wrong

Agree in advance who takes the first call if an account behaves unexpectedly or a file cannot be accessed. Preserve relevant records, use trusted contact routes for service providers and obtain qualified help if compromise is suspected. Do not ask staff to improvise technical containment in a live incident. Reporting, privacy and customer-notification duties depend on location and the data involved; obtain local legal or specialist advice promptly where those duties may apply.

Common errors include relying on a single administrator, treating a backup setting as proof of recoverability, leaving ex-workers in shared systems, postponing updates indefinitely and keeping incident contacts only in the account that may be inaccessible. Review the routine after staff changes and significant system changes. For choosing performance measures alongside this protection work, see Five Numbers to Review Each Week.

Assign an owner to each check

A security task can remain undone when “everyone” is responsible. Put a person’s name or role beside access review, restore test and update review. Define what counts as complete: for access, compare the user list with current roles and record any removal; for recovery, successfully open a restored sample; for updates, confirm installation or note a reason for delay. A dated record makes gaps visible without creating a thick policy document.

Prioritize administrator and email accounts because they can affect access to other services. When an employee leaves, include digital access in the normal departure routine rather than waiting for the monthly review. Ask vendors how shared accounts, recovery contacts and backup exports work before relying on their default settings. A small business may need an IT provider to confirm that the proposed routine actually covers its systems.

Run a safe recovery rehearsal

Choose a non-sensitive sample that can be restored without overwriting live customer work. Confirm who can request recovery, what records are included and what the process would cost in time. Document the result, not just the fact that a test was scheduled. If you cannot restore the sample, investigate whether the backup failed, the wrong records were selected or permissions blocked access. Then retest the corrected process.

Recovery also depends on business communication. If booking data is temporarily unavailable, decide who can contact customers and where the necessary contact details can be accessed lawfully and securely. Do not create unprotected duplicate lists as a shortcut. A simple incident contact sheet stored through an approved alternate route can help when the main email account is inaccessible.

Use the results to choose the next improvement

At a monthly review, summarize: priority accounts reviewed out of total priority accounts, departures checked for access removal, sample restores completed and important update exceptions still open. These are activity and readiness indicators, not a prediction of the chance of an attack. If a system has no named owner or no tested recovery method, address that gap before adding more detailed measurements. Revisit the routine when a new service, employee or critical data type is added.

If you suspect an actual intrusion, move from the routine to an incident response with appropriate technical and legal help. Preserve relevant evidence and follow applicable local reporting duties. The appropriate professional response depends on the systems, location and customer information involved.

Next step: Select one essential account today. Identify its owner, review its users and set a date for a small restore or recovery check. Record what worked and what still needs help.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *