Attackers automate. They don't pick you — they scan everyone and hit whoever left a door open. The good news: the controls that stop them are mostly free and mostly about process, not products. Work down this list and you're both safer and ready for the security questionnaire a bigger client will eventually send you.
Accounts & access
- Enforce 2FA on email, finance, and any admin account. This one control blocks the majority of account takeovers.
- Least privilege: people get access to what their job needs, nothing more. Remove access the day someone leaves.
- A password manager for the team, so credentials aren't in spreadsheets or sticky notes.
Devices & data
- Keep every device patched and running current, supported software.
- Turn on disk encryption and antivirus/endpoint protection on all company machines.
- Back up critical data with the 3-2-1 rule (three copies, two media, one offsite) and actually test a restore.
People & process
- Train staff to spot phishing — it's how most breaches start, and a 15-minute briefing measurably helps.
- Write a one-page incident plan: who to call, what to shut off, how to communicate, so a bad day doesn't become a bad week.
- Keep a simple asset list — you can't protect what you don't know you have.
Get the full toolkit, ready to hand to an auditor
The SMB Cybersecurity & IT Compliance Toolkit turns this into ready-to-use policies, checklists, and a compliance-review pack — everything a small business needs to lock down security and pass a review without hiring a consultant. Instant download.
Get the toolkit →