Cybersecurity

A Practical Cybersecurity Checklist for Small Businesses

Reduce common cyber risks with a clear checklist for accounts, devices, backups, Wi-Fi, payments and incident response.

Protect the accounts that unlock everything else

Email, cloud administration, banking and domain accounts are high-value targets because access to one can help an attacker reset many others. Give each person their own account, remove access promptly when roles change and avoid sharing administrator passwords over chat.

Use long, unique passwords stored in a reputable password manager. Turn on multi-factor authentication, preferably with an authenticator app, passkey or security key. SMS verification is still better than password-only access where stronger methods are unavailable.

  • List every business-critical account and its owner.
  • Protect recovery email addresses and phone numbers too.
  • Store emergency recovery codes offline in a controlled location.
  • Use a separate administrator account for administrative work.

Keep devices and software supportable

Enable automatic security updates for operating systems, browsers, office software, routers and business apps. Replace devices that no longer receive security fixes, especially those used for payments, email or customer information.

Use full-disk encryption, screen locks and remote-locate or remote-wipe features on laptops and phones. Standard users should not have permission to install any software without approval. Remove unused apps and browser extensions because every unnecessary component expands the attack surface.

Build backups that survive an attack

A synced folder is convenient, but it is not always a complete backup—ransomware or accidental deletion can synchronise damage. Use the 3-2-1 principle: keep three copies of important data, on two different types of storage, with one copy offline or isolated.

Automate backups, encrypt them and test restoration. A backup is only useful when someone knows how to recover the files and systems within the time the business can tolerate being offline.

Secure Wi-Fi and remote access

Change the router’s default administrator password, install firmware updates and use WPA2 or WPA3 encryption. Put visitors and untrusted smart devices on a guest network that cannot reach office computers, cameras or storage.

Do not expose remote desktop, camera recorders or router administration directly to the internet. Use a properly configured VPN or trusted managed remote-access service with multi-factor authentication and logging.

Prepare people for fraud attempts

Many incidents begin with a believable message rather than advanced malware. Train staff to verify payment-detail changes, urgent executive requests and unusual login prompts through a separate trusted channel. No employee should be punished for pausing a suspicious transaction.

Create a short incident plan with contact details, decision owners and steps for isolating a device, changing credentials, preserving evidence, contacting the bank and assessing notification duties. Practise the plan before a real incident creates pressure.