A small-business cybersecurity baseline should answer a simple question: which protections are operating today, who owns them, and what evidence proves it?
Buying a security product is not the same as maintaining a control. Multifactor authentication can exclude important accounts. Backups can fail quietly. Updates can be configured without reaching every device. A policy can exist without changing how access is approved.
The following baseline is intentionally practical. It does not replace obligations that apply to a regulated industry, contract, insurance policy, or legal requirement.
Begin with ownership and an inventory
Name a business decision-maker and a technical owner. The business owner decides acceptable risk, budget, and operational priorities. The technical owner implements, verifies, and documents controls. Those roles can involve the same people, but the decisions should remain visible.
Maintain a current inventory of:
- Employees, contractors, privileged administrators, and shared identities
- Company computers, mobile devices, servers, network equipment, and important connected devices
- Microsoft 365, Google Workspace, financial, CRM, backup, password-manager, and line-of-business services
- Internet, software, copier, phone, security, and other technology vendors
- Important data and the business process it supports
If the organization cannot identify what it owns and where critical information lives, it cannot reliably protect or recover it.
Protect identity first
Require multifactor authentication for email, cloud files, remote access, finance, administrator accounts, and other important services. Prefer phishing-resistant methods where supported, such as passkeys or hardware-backed security keys; use strong app-based methods when that is the practical interim choice.
Keep administrator accounts separate from everyday work. Do not share named user accounts. Review recovery phone numbers, email addresses, trusted devices, emergency accounts, and vendor access.
Most importantly, create repeatable onboarding and offboarding steps. Access that is protected well but never removed remains an access problem.
Maintain devices and software
Use supported operating systems and applications. Enable timely security updates, encrypt portable computers, protect endpoints, and maintain a reliable screen-lock standard.
Track exceptions. A machine that cannot update because of one legacy application may need isolation, an upgrade project, or a replacement deadline. “Do not touch that computer” is not a durable security plan.
For personally owned devices, define what business information they may access, what controls are required, and what the company can or cannot manage. Avoid quietly treating personal equipment as fully managed company assets.
Make backups a recovery process
Define which systems and data must be recovered, how recent the restored information must be, and how quickly the business needs it. Keep protection appropriate to the risk, including a copy or control path that is not exposed to the same credentials and failure as the production system.
Review backup status and failures. Then perform representative restores. A green dashboard proves that a job reported success; a tested restore proves that useful data can return.
Document who may authorize recovery and how the backup system itself is accessed if the normal administrator account is unavailable.
Reduce access and sharing drift
Use groups and roles tied to real responsibilities. Give people the access needed for their work and review high-impact exceptions. Remove former vendors, dormant guest users, unknown administrator roles, and old sharing links after the appropriate owner confirms they are no longer required.
For Microsoft 365, include SharePoint, OneDrive, Teams, mailbox delegation, applications, and privileged Entra roles—not only the list of active users. Our SharePoint guest-access audit describes one focused review.
Secure the network without confusing it for the boundary
Document the firewall, switches, access points, administrator access, configuration backup, internet provider, and physical locations. Separate guest access and untrusted connected devices from business systems where appropriate. Remove unnecessary remote administration and unsupported equipment.
The network still matters, but cloud identities and managed devices travel beyond it. Do not assume that everyone inside the office is trusted or that work outside the office is automatically unsafe.
Prepare a short incident plan
Write down who to call and what authority they have. Include business leadership, IT, cyber insurance, legal counsel, financial institutions, critical vendors, and communications ownership as appropriate.
The first actions should preserve options. If ransomware or active compromise is suspected, isolate affected systems from networks when safe, avoid deleting evidence, use known-clean communications, and involve the authorized response team. Do not promise customers, restore systems, pay anyone, or make legal conclusions from an improvised checklist.
Practice one scenario annually: a compromised Microsoft 365 account, lost laptop, unavailable file system, fraudulent payment request, or failed internet circuit. Record what the exercise reveals.
Review the baseline quarterly
Quarterly does not mean rebuilding the security program. Review meaningful changes: people, devices, administrators, key vendors, backups, failed updates, sharing, incidents, insurance requirements, and upcoming replacements.
NIST’s Cybersecurity Framework 2.0 small-business resources organize risk work around Govern, Identify, Protect, Detect, Respond, and Recover. That is a useful reminder that security includes business decisions and recovery—not only prevention tools.
Tyler’s Tech Company provides small-business cybersecurity support and managed IT services across Greater Boston, with a focus on supportable controls and honest evidence.