Small Business Cybersecurity Checklist: 30 Steps to Secure Your Company
small-businesscybersecurity-checklistsecurity-basicsransomwareemployee-training

Small Business Cybersecurity Checklist: 30 Steps to Secure Your Company

SSafely Insights Editorial Team
2026-08-07
7 min read

Use this 30-step small business cybersecurity checklist to secure accounts, devices, email, data, backups, employees, and vendor access.

This small business cybersecurity checklist gives you 30 practical steps for protecting accounts, devices, email, data, employees, backups, and vendor access. Use it as a working document: assign an owner to each item, record what is complete, and return to it whenever your tools, staff, or workflows change.

Overview

Cybersecurity for small business is less about buying every available tool and more about reducing predictable points of failure. A useful program starts with knowing what you have, limiting who can reach it, securing the systems employees use every day, and preparing for an interruption.

The order below is intentional. Begin with identity and access controls, then address devices, email, data, backups, training, and response planning. Some steps may require help from your technology provider or a qualified security professional, especially if your business handles sensitive personal information, financial records, health information, or regulated data.

Keep evidence of your work in one secure location. A simple spreadsheet can include the checklist item, responsible person, completion date, related system, and next review date. Do not store passwords, recovery codes, or confidential customer data in that spreadsheet.

Checklist by scenario

Accounts and access

  1. Inventory business accounts. List email, accounting, banking, payroll, customer relationship management, cloud storage, website, social media, and administrative accounts.
  2. Assign an owner to each account. Record the business purpose and the person responsible for reviewing access.
  3. Require unique passwords. Do not reuse a password across business systems or between personal and business accounts.
  4. Use a password manager for business. Choose a solution that supports shared vaults, individual accounts, secure recovery, and administrative control.
  5. Turn on multifactor authentication. Prioritize email, financial, administrator, remote-access, and cloud-storage accounts. This is a foundational MFA for small business measure.
  6. Remove unnecessary access. When someone changes roles or leaves, promptly disable accounts, revoke sessions, recover company devices, and remove shared credentials.

Devices and software

  1. List company-connected devices. Include laptops, desktops, phones, tablets, point-of-sale devices, network equipment, and home devices used for work.
  2. Enable automatic updates. Apply updates for operating systems, browsers, applications, routers, and security software where practical.
  3. Use endpoint protection. Install reputable endpoint security or antivirus software, keep it active, and confirm that alerts reach a responsible person.
  4. Encrypt business devices. Use the operating system’s available device encryption and protect recovery keys separately from the device.
  5. Lock screens automatically. Set a short inactivity timeout and require a password, PIN, or biometric check to resume work.
  6. Control local administrator rights. Employees should use standard accounts for routine work unless an administrator account is necessary and managed.

Email, phishing, and communications

  1. Protect business email. Enable available spam, malware, impersonation, and suspicious-link protections in your email platform.
  2. Verify unusual requests. Confirm payment changes, gift-card requests, urgent data transfers, and password-reset requests through a separate trusted channel.
  3. Make reporting easy. Give employees a clear process for forwarding suspicious messages or reporting a suspected mistake without fear of blame.
  4. Secure email domains. Ask your email administrator or provider to review domain authentication settings, including the controls appropriate for your platform.
  5. Train for business impersonation. Explain that familiar names, logos, or email addresses are not proof that a request is genuine.

Data, documents, and cloud services

  1. Identify sensitive data. Locate customer records, employee information, payment details, contracts, credentials, and confidential business files.
  2. Limit collection. Keep only the information your business needs for a defined purpose, and avoid placing sensitive data in unapproved tools.
  3. Set sharing rules. Use named accounts, least-privilege permissions, expiration dates, and access reviews for cloud files and folders.
  4. Secure document workflows. Use approved storage and secure document sharing for business records. Check recipient details before sending or signing.
  5. Review cloud administrator settings. Check login alerts, recovery methods, external sharing, audit logs, and administrator roles in Microsoft 365, Google Workspace, or comparable services. See the cloud security checklist for Microsoft 365 and Google Workspace for a dedicated review.
  6. Create a retention process. Define when routine records should be archived or securely deleted, while accounting for legitimate business, contractual, or legal requirements. Use this guide to create a data retention policy.

Backups and incident readiness

  1. Back up essential data. Include accounting, customer, operational, website, and configuration data that the business would need to continue operating.
  2. Separate backups from everyday accounts. Protect backup administration with distinct credentials and multifactor authentication where available.
  3. Test restoration. Periodically restore selected files or systems to verify that backups are usable, complete, and understandable to someone other than the person who created them.
  4. Write an incident response plan. Record who should isolate a device, contact technology providers, preserve evidence, communicate internally, and evaluate notification obligations.
  5. Prepare an offline contact list. Include key employees, technology providers, insurers, legal contacts, banks, and critical vendors. Do not rely solely on a system that may be unavailable during an incident.
  6. Practice a realistic scenario. Walk through a stolen laptop, compromised email account, ransomware event, or cloud-service outage and note where decisions or contact details are missing.

For a more focused recovery exercise, compare your plan with this business continuity checklist for cyber incidents and SaaS outages.

What to double-check

Completion alone does not prove that a control works. During each review, double-check the following:

  • Former users: Search for inactive employees, contractors, temporary workers, and old shared accounts.
  • Privileged access: Confirm that administrator rights are limited, documented, and protected by MFA.
  • Recovery paths: Verify that recovery email addresses, phone numbers, backup codes, and encryption keys belong to the business and remain accessible.
  • Backups: Confirm that recent backups exist and that a test restoration has succeeded.
  • External sharing: Review public links, guest users, shared mailboxes, and folders containing sensitive information.
  • Vendor access: Check which vendors can access systems, what they can do, and whether access is still necessary. The access control checklist for small businesses can help structure this review.
  • Insurance and contracts: If you carry cyber insurance or have contractual security requirements, compare your actual settings with those obligations rather than assuming a policy or contract is satisfied.
  • Privacy practices: Make sure your privacy notice, internal data handling rules, retention process, and access controls describe how the business actually operates. This checklist is not legal advice and does not establish GDPR, CCPA, or other regulatory compliance by itself.

Common mistakes

  • Buying tools before fixing ownership. A security product is difficult to manage when no one receives alerts or checks its settings.
  • Using one shared administrator login. Individual accounts improve accountability and make departures easier to manage.
  • Treating training as a one-time event. Short, recurring reminders tied to real business scenarios are easier to apply than a single annual presentation.
  • Assuming cloud services are secure by default. Providers protect their platforms, but your settings, users, permissions, devices, and shared files still require review.
  • Ignoring paper and physical access. Printed customer records, unlocked offices, unattended devices, and discarded documents can expose the same information as a compromised account.
  • Never testing backups or response plans. A plan that has not been rehearsed may fail when time and information are limited.
  • Sending sensitive information through ordinary channels. Confirm whether a secure portal, restricted link, or approved e-signature workflow is more appropriate. Review what to compare in secure e-signature tools before selecting one.

When to revisit

Review this small business security checklist at least quarterly, and schedule a deeper review before seasonal planning cycles or other periods when staffing, sales volume, or business activity changes. Revisit it immediately after a security incident, office move, acquisition, major software change, new remote-work arrangement, or change in payment or customer-data workflows.

Use a simple status system: complete, in progress, not applicable, or needs specialist review. At each quarterly review, sample a few controls rather than only checking boxes: test a backup restoration, inspect a user’s access, review an alert, and verify that an employee knows how to report a suspicious message.

Start today with the highest-impact items: turn on MFA for critical accounts, remove unnecessary access, update and protect devices, confirm backups, and document who responds to an incident. Then assign dates and owners to the remaining steps. For planning costs and priorities, use the cybersecurity budget checklist for small business owners. A consistent review habit will make the checklist more useful than a one-time security project.

Related Topics

#small-business#cybersecurity-checklist#security-basics#ransomware#employee-training
S

Safely Insights Editorial Team

Cybersecurity and Privacy Editors

Senior editor and content strategist. Writing about technology, design, and the future of digital media. Follow along for deep dives into the industry's moving parts.