IT & Security · August 1, 2026
The small business cybersecurity checklist: what a 5-person office can actually do
Small businesses get attacked because they are easier targets than big ones, not because they are less valuable. The good news is that a handful of unglamorous basics stops the majority of what actually hits a small office: multi-factor authentication, a password manager, protected email, current updates, tested backups, trained people, and a simple plan for the bad day. Here is the checklist, in the order to do it.
1. Turn on multi-factor authentication everywhere
Multi-factor authentication, MFA, means a stolen password alone cannot open your account, because logging in also requires a code or prompt on your phone. It is the single highest-value security move available to a small business, and it is usually free.
Start with email, since whoever controls your email can reset everything else. Then banking, Microsoft 365 or Google Workspace, payroll, and any system holding customer data. Use an authenticator app rather than text messages where you can, and do not grant exceptions for the boss. Owner accounts are the ones attackers want most.
2. Fix passwords with a password manager
The real password problem is reuse. When the same password covers a breached shopping site and your business email, that breach becomes your breach. A password manager fixes this by generating and remembering a different strong password for every account, so nobody has to.
Pick a reputable business password manager, roll it out to all five people, and protect the manager itself with MFA. While you are in there, hunt down the sticky notes and the shared spreadsheet of logins and retire them. Shared accounts should live in the manager's shared vault, not in a text thread.
3. Protect email, your biggest attack surface
Nearly every attack on a small office arrives by email: fake invoices, password reset lures, a message that looks like the owner asking for gift cards. Turn on the advanced phishing and malware filtering in Microsoft 365 or Google Workspace, since the strong protections are often not enabled by default.
Have your IT provider set up SPF, DKIM, and DMARC on your domain. In plain terms, these records make it much harder for criminals to send email that appears to come from your company, which protects both your inbox and your customers' trust in your name.
4. Keep everything updated, automatically
Most successful attacks exploit flaws that were already fixed in an update nobody installed. Turn on automatic updates for Windows and macOS, browsers, and phones, and schedule them so they actually complete instead of being postponed forever.
Do not forget the equipment that has no screen. Routers, firewalls, and WiFi access points run software too, and an office router that has never been updated is an open side door. If any computer runs an operating system past its end-of-support date, replacing it is a security expense, not a luxury.
5. Back up your data, then test the restore
Backups are your answer to ransomware, fire, theft, and honest mistakes. Follow the 3-2-1 idea: three copies of important data, on two different types of storage, with one copy off-site or in the cloud. Automate it, because a backup that depends on someone remembering will eventually depend on someone who forgot.
An untested backup is a hope, not a plan. Twice a year, pick a file and actually restore it, and time how long a full recovery would take. Also know that Microsoft 365 and Google Workspace are not automatically backed up in the way most owners assume, so a deleted mailbox or drive may be gone for good without a separate backup service.
6. Train your team to spot phishing
Your people are the last line of defense, and untrained people click. Training does not need to be elaborate: a short session twice a year covering what current scams look like, plus a standing rule that any request involving money, gift cards, or password changes gets verified by phone or in person before anyone acts.
Make it safe to report mistakes. An employee who clicks a bad link and says so within five minutes has contained an incident. An employee who is afraid to admit it has started one, and the delay is where the real damage happens.
7. Review access and write down the bad-day plan
Twice a year, list every account and who can reach it. Remove access former employees still have, trim anyone with more access than their job needs, and check for forgotten admin accounts. In a five-person office this review takes an hour, and it regularly turns up an ex-employee who can still read company email.
Then write a one-page incident plan: who to call first, including your IT provider's number on paper, how to disconnect an infected machine, where the backups live and how to reach your bank and insurer, and who talks to customers if data is involved. On the bad day nobody thinks clearly, and the page does the thinking.
If you want help working through this list, SIGIL Technologies does exactly that for small offices across Northwest Indiana, and the first consultation is free. Call (219) 200-4251.
Related services