What should every small business protect first?

Start with the accounts, devices, data and services that would stop operations or create serious harm if compromised. Assign one accountable owner even when outside providers perform the technical work.

What is the minimum identity baseline?

Require multi-factor authentication for email, finance, administration, remote access and other critical systems. Use separate administrator accounts, remove former users promptly and review outside-provider access.

  • Use phishing-resistant authentication where supported
  • Use a password manager and unique passwords
  • Disable legacy sign-in methods when practical
  • Document account-recovery methods and trusted contacts

What is the minimum device and network baseline?

Keep supported operating systems, applications, firewalls and network equipment updated. Use secure remote access, separate business systems from guest and untrusted devices, and protect laptops and mobile devices with encryption and screen locks.

What is the minimum recovery baseline?

Maintain protected backups for critical data and configurations, keep at least one recovery copy isolated from ordinary administrator access and test restoration. Record recovery priorities so the team knows what must return first.

What should the business monitor?

Centralize important security and administrative alerts where someone will review them. Watch for unusual sign-ins, forwarding rules, privilege changes, disabled protection, backup failures and unexpected network or endpoint activity.

What should be written down before an incident?

Keep an offline-accessible contact list and first-action plan for account takeover, ransomware, lost equipment and provider outages. Include insurance, legal, technical and communications contacts plus evidence-preservation instructions.