Author
Trawvid Sec
Published
Last reviewed
Review status
Current
Before you begin
Set up the work
Expected effort: Allow about 30 minutes for the first pass. Complete the highest-value changes over the next 30 days instead of trying to fix everything in one sitting.
Bring these inputs
- A business owner who can assign work and approve priorities.
- The people or providers who manage email, devices, cloud services, backups, banking, payroll, and customer systems.
- Current customer, contract, insurance, or regulatory requirements that may change the order of work.
Keep these outputs
- A short map of the activities and technology the business cannot afford to lose.
- Verified account, device, recovery, payment, and incident basics.
- No more than five prioritized actions with owners and dates.
Start here: the minimum path
A small business does not need to boil the ocean. It needs to close the gaps that make ordinary mistakes, account compromise, fraud, and downtime much harder to manage.
This guide is deliberately non-exhaustive. It focuses on the controls that usually reduce the most risk without requiring an enterprise security department.
If you do nothing else, do these six things:
- Name one person who owns security decisions and follow-up.
- Protect email, domain, banking, payroll, cloud administration, remote access, and backup administration with unique credentials and strong multifactor authentication.
- Remove former users, unknown accounts, shared administrator access, and remote tools nobody can explain.
- Confirm business computers are supported, updating, encrypted where appropriate, and covered by working endpoint protection.
- Restore one important file or system from backup and confirm the result is usable.
- Establish a separate verification rule for payment changes and a contact sheet that works without company email.
Use the Business Security Checklist first if you are unsure which of these is weakest. Unknown is a valid starting answer. Write it down and assign it rather than guessing.
Do not store passwords, recovery codes, private keys, customer records, or other secrets in this guide.
Step 1: Know what the business cannot afford to lose
Start with work, not technology. Ask what must happen for the business to bill customers, pay people, deliver its product or service, communicate, and meet important obligations.
Choose five to ten activities. For each one, name the systems, information, providers, and people it depends on. Record a realistic workaround.
| Critical activity | Business owner | Systems, accounts, or provider | Tolerable interruption | Workaround | Largest unknown |
|---|---|---|---|---|---|
Pay attention to single points of failure. One mailbox, one laptop, one provider, or one person should not quietly control the only recovery path for a critical process.
This map is complete enough when leadership can answer:
- What stops billing, payroll, delivery, or customer communication?
- Who owns each critical activity?
- Which account, device, provider, or person is a dangerous single dependency?
- What would the business do tomorrow if the primary system were unavailable?
Do not build a perfect asset inventory before moving forward. Record the critical items first and add detail as the business can maintain it.
Step 2: Protect the master keys
Some accounts can reset or influence nearly everything else. Start with email, domain registration, password management, remote access, accounting, payroll, banking, cloud administration, and backup administration.
For each critical account:
- Name the business owner and every administrator.
- Use a unique credential stored in an approved password manager.
- Enable strong multifactor authentication. Prefer passkeys or security keys for the highest-consequence accounts when practical.
- Store recovery codes outside the mailbox or device they are meant to recover.
- Replace personal recovery addresses and old phone numbers where practical.
- Remove former users, stale access, and unnecessary administrators.
- Use named administrator accounts instead of shared daily administration.
- Record how access is approved and removed for employees, contractors, bookkeepers, and providers.
NIST SP 800-63B supports password managers and stronger authentication. The practical priority is not forcing arbitrary password changes. It is removing reuse, shared access, weak recovery, and missing multifactor authentication.
Stop if nobody can regain control of the domain, email tenant, password manager, or backup administration without one provider or one unavailable employee. That ownership problem deserves attention before another tool purchase.
Step 3: Cover devices and prove recovery
Ask the person or provider responsible for business computers for a plain answer to four questions:
- Which computers are expected to be covered?
- Which are actually reporting as updated and protected?
- Which are missing, unsupported, or excepted?
- Who is fixing each exception?
Business laptops and other devices holding sensitive information should use supported software, automatic updates where operationally safe, screen locks, encryption where appropriate, and working endpoint protection. Remote-access tools should be approved, strongly authenticated, and removable.
Do not accept a dashboard that says everything is green without asking what is excluded and when each device last checked in.
Then test recovery. Choose one file set or application the business cannot afford to lose. Restore a representative sample to a safe location and have the business owner confirm it is usable.
| Item restored | Backup source | Test date | Time required | Business owner confirmed usable? | Gap and owner |
|---|---|---|---|---|---|
Recovery is credible enough for this baseline when:
- The business knows what is and is not backed up.
- Backup administration is protected from ordinary account compromise or deletion where practical.
- A representative restore was completed.
- Failed instructions or missing data have an owner and date.
Synchronization and version history may help. Neither automatically replaces a tested backup.
Step 4: Put fraud and incident basics on one page
The business needs a way to react before it needs a full incident plan.
Write one rule for changed bank details, payroll changes, new payees, wire instructions, and urgent executive requests:
Verify the change through a known second channel. Do not use a phone number, email address, or link supplied only in the change request.
Make sure finance and payroll staff can repeat that rule without opening this guide.
Then record the contacts and authority needed during a serious problem:
| Need | Primary person or organization | Backup | Trusted contact method outside company email |
|---|---|---|---|
| Leadership decision | |||
| Technology or response help | |||
| Bank or payment fraud | |||
| Cyber insurer or broker, if applicable | |||
| Legal guidance, if needed |
Run one 20-minute scenario: an owner mailbox takeover, fraudulent payment request, unavailable shared files, lost laptop, malware alert, or provider incident. Ask who notices, who decides, what gets isolated, how work continues, and who must be called.
This step is complete enough when:
- The payment-change rule is understood by the people who can move money.
- The contact sheet is available without company email.
- Leadership and technical decision authority are clear.
- One realistic scenario exposed at least one assumption or gap.
Use Small Business Cyber Incident First Actions for the live first-hour path and preparation details. Do not duplicate that response plan inside this baseline.
Step 5: Choose five actions, not fifty
Review the unknowns and failures from the first four steps. Choose no more than five actions for the next 30 days. Put lower-consequence work into 60- or 90-day targets only when it still deserves attention.
| Priority action | Business reason | Owner | Target date | Evidence that closes it | 30, 60, or 90 days |
|---|---|---|---|---|---|
A useful action is specific enough to finish. "Improve security" is not an action. "Enable multifactor authentication on the payroll administrator account and store its recovery codes in the approved location by Friday" is.
The plan is ready when:
- Every immediate action has one owner and date.
- Leadership approved the order of work.
- Deferred risks include a reason and review date.
- The next check-up is scheduled.
Keep the work alive
A short monthly review is useful when the business can support it. Ask what changed, which open risk matters most, whether important backups and alerts still work, and what evidence shows the agreed work was completed.
If a monthly review is unrealistic, get a professional cybersecurity check-up at least once a year. Treat it like an annual health visit for the business. Review what changed, test the assumptions that matter, catch problems that are easy to miss internally, and leave with a prioritized plan.
Also schedule a check-up after a major provider change, rapid growth, acquisition, serious incident, new regulated or contract-sensitive work, or a material cyber-insurance change.
Trawvid Sec's Cyber Health Check is built for that practical minimum. It produces five priorities and a 30-, 60-, and 90-day plan without turning the review into an enterprise assessment.
If this guide exposes unclear ownership, missing records, or work that nobody can confidently prioritize, use the email and booking options on this page. Bring the unknowns and the business constraints. Do not send passwords, recovery codes, or sensitive customer information.
Keep working
Related resources
Practical next step
If ownership is unclear, priorities are disputed, or the work keeps stalling, use a focused review to identify five practical next actions.
Schedule a Cyber Health CheckReference baseline