This small business cybersecurity checklist closes that gap. In about 30-45 minutes, it walks you through 30 practical checks, in plain English, so you know where your company stands. It's built for businesses with 5 to 25 employees, too big for one shared login, too small for a security team. Mark each item, then use the worksheet and score below to decide what to fix first. Treat "Unknown" as a gap until it's verified.
This checklist is general educational information, not a formal cybersecurity audit, penetration test, compliance certification, or legal opinion. Requirements vary by industry and location, and no checklist guarantees protection against every incident.
Key takeaways
Use three statuses:
Verification beats installation. Backups shouldn't be marked "Complete" just because software is running, the real test is whether someone has restored a file and confirmed it's intact. That logic applies throughout.
Copy the worksheet below into a spreadsheet and assign an owner and target date to anything not Complete. CISA's Cyber Essentials guide is a useful companion resource.
Weak account security is one of the most common ways attackers get in a stolen password or unattended login can expose everything connected to it.
1. MFA is enabled on email, cloud apps, banking, accounting, VPNs, and admin accounts. Multi-factor authentication (MFA) requires a second identity check beyond a password. Enforce it, don't just offer it.
2. Every employee has a unique account. Shared logins hide who did what and can't be individually disabled.
3. Former employees' accounts are disabled promptly. Access should end the day someone leaves. Audit active accounts against your staff list today.
4. Administrator access is limited to people who need it. More admins mean more risk if one account is compromised.
5. Separate admin accounts are used for administrative work. Anyone with admin rights should use a normal account for email and browsing, so a phishing compromise doesn't hand over admin control too.
Small, practical password habits make a large difference in overall risk.
6. Business passwords are unique and not reused. One reused password exposes every account it touches if it leaks elsewhere.
7. A business password manager is available. It generates and stores strong, unique passwords so staff aren't tempted to reuse simple ones.
8. Shared passwords have been eliminated or replaced with delegated access. Shared logins can't be tracked or revoked individually.
9. Default passwords have been changed on routers, printers, cameras, and other devices. Defaults are publicly known and an easy foothold, printers and cameras are often overlooked.
10. Employees have access only to what their role requires ("least privilege"). Review shared drives and remove access to nobody's job needs.
Outdated or unmanaged devices are an easy entry point, since known software flaws are often public knowledge.
11. All computers and mobile devices are inventoried. You can't secure a device you don't know exists. Build a simple list of devices, owner, and OS.
12. Operating systems and applications are still supported. Past its end-of-life date, software never gets patched for new vulnerabilities.
13. Automatic security updates are enabled. Manual patching gets delayed; automatic updates close gaps faster.
14. Endpoint protection is installed, active, and updated. Antivirus/anti-malware is a basic safety net, though not a complete defense alone.
15. Full-disk encryption and automatic screen locking are enabled. An encrypted, locked laptop is far less likely to expose data if lost or stolen.
Email and phishing protection
Email remains one of the most common ways attackers reach small businesses often through convincing, targeted messages, not obvious spam.
16. Employees know how to report suspicious messages. Fast reporting can stop an attack before money moves.
17. Payment and bank account changes require independent verification. Confirm any change request through a separate channel like a call to a known number before acting. This is a top defense against business email compromise.
18. Email filtering is configured for spam, malicious links, and dangerous attachments. Heartland Computer's Cybersecurity Services can help configure this correctly.
19. SPF, DKIM, and DMARC are configured for your email domain. These records Sender Policy Framework, DomainKeys Identified Mail, and Domain-based Message Authentication, Reporting, and Conformance make your domain harder to impersonate. Getting them right usually needs IT support.
20. Employees receive recurring cybersecurity awareness training. Threats change, so one-time training isn't enough. Free resources are available from CISA.
The network is the foundation everything runs on, and remote work has made its edges harder to define.
21. Business Wi-Fi uses modern encryption and a strong admin password. Use WPA2/WPA3 and change the router's default admin login.
22. Guest Wi-Fi is separated from business systems. An isolated guest network keeps a compromised guest device from reaching internal resources.
23. Router, firewall, and access-point firmware are updated. Firmware can carry vulnerabilities like any software.
24. Remote access is protected by MFA and disabled when unnecessary. VPNs and remote-desktop tools are prime targets for attackers.
25. Employees use an approved secure connection for sensitive work away from the office. Document an approved method, like a company VPN. Heartland Computer's Network setup and support can help design this.
Backups determine whether a bad day becomes a minor inconvenience or a business-ending event.
26. The business knows where sensitive data is stored. You can't protect data you don't know you have.
27. Critical data is backed up automatically. Manual backups get skipped when things are busy.
28. Backups follow an appropriate 3-2-1 strategy- 3 copies, 2 media types, 1 offsite. This protects against hardware failure, theft, and fire, unlike one drive next to the server.
29. Backups are protected from ransomware and unauthorized access. Attackers increasingly target backups directly, so keep at least one copy offline or immutable. Heartland Computer's Backup and Disaster recovery services are built around this exact problem.
30. A real file or system restoration has been tested and documented. Untested backups sometimes fail when needed most, installing backup software isn't the same as having a working one.
Maximum score: 60 points.
This score is educational only, not a formal risk rating, insurance assessment, compliance result, or guarantee of protection.
First 24 hours: Enable MFA on email and admin accounts. Remove former employees' access. Change reused or default passwords. Confirm backups are running. Update or isolate unsupported devices.
First 30 days: Complete an account and device inventory. Deploy a password manager. Review Wi-Fi and remote access. Train staff in phishing and payment verification. Test one file restoration.
Within 90 days: Fix SPF, DKIM, and DMARC. Document an incident-response plan. Review vendor and remote-access permissions. Build a patch-management process. Get a professional assessment if gaps remain.
Attack methods keep evolving, but these fundamentals still address what small businesses face today: AI-assisted phishing, fake AI apps disguising malware, business email compromise, deepfake voice scams, ransomware that targets backups directly, shadow AI (staff pasting sensitive data into unapproved tools), and cloud-account takeovers from stolen credentials. The FBI's Internet Crime Complaint Center has repeatedly flagged business email compromise as one of the costliest cybercrime categories.
Older threats haven't gone away- phishing, stolen credentials, weak passwords, and unpatched devices remain the most common causes of compromise. Review this checklist annually, ideally alongside fiscal-year planning.
Consider outside help if you can't verify your backups, manage accounts and devices, secure remote access, or respond confidently to a phishing or ransomware incident. An IT provider can help close these gaps and keep your security controls maintained.
Need ongoing IT support? Explore Heartland Computer's Services to find an option that fits your business.
Not sure how many items on this list your business has completed or verified? Heartland Computer works with small businesses in Omaha, Nebraska, and Council Bluffs, Iowa, to review accounts, devices, networks, backups, and security processes, then help prioritize what matters most.
Ready to see where your business stands?
Contact Heartland Computer for a free cybersecurity review →
1. What is a small-business cybersecurity checklist?
A structured list of security controls a company reviews to understand its protections and find gaps. It's a self-assessment tool, not a certification.
2. What are the most important cybersecurity steps for a small business?
CISA and NIST point to MFA, removing former employees' access, updated software, endpoint protection, and tested backups.
3. Does a small business really need MFA?
Yes. MFA significantly reduces account-takeover risk even if a password is stolen, and it's one of the lowest-cost, highest-impact controls available.
4. Is antivirus software enough to protect a business?
No. It's one layer, best paired with MFA, updated software, employee training, and tested backups.
5. How often should a small business review its cybersecurity?
At least annually, and after any major change, new software, new staff, or an incident.
6. How often should business backups be tested?
No universal rule, but many businesses aim for at least quarterly. Testing means restoring data, not just confirming backup jobs ran.
7. What should an employee do after clicking a suspicious link?
Disconnect the device from the network, if possible, avoid entering credentials, and report it to IT or security immediately.
8. What should a business do after a suspected ransomware attack?
Disconnect affected systems, avoid paying or negotiating without guidance, and contact a qualified IT professional right away.
9. Is this checklist a formal cybersecurity audit?
No. It's educational information for self-assessment, not a formal audit, penetration test, compliance certification, or legal opinion.
10. When should a small business hire an IT provider?
When you can't verify backups work, nobody owns account management, you've had an incident, or you're simply unsure where you stand.
Sources:
https://www.nist.gov/itl/smallbusinesscyber
https://www.cisa.gov/resources-tools/resources/cyber-essentials
https://www.ftc.gov/business-guidance/small-businesses/cybersecurity
Disclaimer: This checklist is general educational information. It is not a formal cybersecurity audit, penetration test, compliance certification, or legal opinion. Cybersecurity requirements vary by industry and location, and no checklist can guarantee protection against every cyber incident.

