Basic Cybersecurity Checklist for Small Businesses

Small businesses are common targets for scams and cyberattacks, often because criminals expect weaker protection. The good news: a handful of basic habits block most attacks, and none of them need an IT department. Use this checklist to cover the essentials.

Quick answer: the 5 most important steps

  1. Turn on two-step verification for email, banking and admin accounts.
  2. Use a password manager and a different password for every account.
  3. Keep devices and software updated automatically.
  4. Have automatic backups, with one copy stored separately.
  5. Train everyone to spot phishing emails and messages.

The full checklist

Accounts and passwords

  • ☐ Two-step verification (2FA) is on for email, banking, cloud storage, social media and your website admin.
  • ☐ Everyone uses a password manager; no passwords on sticky notes or shared spreadsheets.
  • ☐ Each person has their own account. No shared logins for important systems.
  • ☐ Default passwords on routers, printers and cameras have been changed.
  • ☐ When someone leaves, their access is removed the same day.

Email and phishing

  • ☐ Staff know the warning signs: urgency, unexpected attachments, requests to pay or change bank details, slightly wrong sender addresses.
  • ☐ Any request to change payment details is confirmed by phone, using a number you already have.
  • ☐ Your email domain has SPF, DKIM and DMARC records set up. See our business email guide.
  • ☐ Staff know how to report a suspicious email and feel safe doing it, even if they already clicked.

Devices

  • ☐ Automatic updates are on for Windows, macOS, phones, browsers and apps.
  • ☐ Built-in protection is on: Microsoft Defender on Windows, and macOS security features on Mac.
  • ☐ Laptops have disk encryption turned on (BitLocker on Windows, FileVault on Mac).
  • ☐ Every device locks automatically with a PIN, password or fingerprint.
  • ☐ Lost or stolen devices can be located and wiped remotely.
  • ☐ Staff do not use admin accounts for everyday work.

Backups

  • ☐ Important files are backed up automatically.
  • ☐ You follow the 3-2-1 rule: 3 copies of important data, on 2 different types of storage, with 1 copy kept off-site or in the cloud.
  • ☐ At least one backup cannot be changed by ransomware (an offline copy or a versioned cloud backup).
  • ☐ You have tested restoring a file in the last 3 months.
  • ☐ Your website has its own backups (for WordPress, a plugin such as UpdraftPlus).

Network and Wi-Fi

  • ☐ Office Wi-Fi uses WPA2 or WPA3 with a strong password.
  • ☐ Guests use a separate guest network.
  • ☐ The router’s admin password is changed and its firmware is updated.
  • ☐ Staff avoid logging in to sensitive accounts on public Wi-Fi, or use a trusted VPN.

Access and data

  • ☐ People only have access to the files and systems they need.
  • ☐ Important business files live in shared company storage, not in one person’s personal account. See how to organise Google Drive.
  • ☐ You know where customer personal data is stored and who can see it.
  • ☐ Old accounts, apps and plugins you no longer use are removed.

Website

  • ☐ HTTPS (SSL) is on.
  • ☐ WordPress, theme and plugins are updated regularly.
  • ☐ A security plugin or firewall is active (for example Wordfence).
  • ☐ Admin usernames are not “admin”, and admin accounts use 2FA.

If something goes wrong

  1. Do not panic, and do not hide it. Fast action limits damage.
  2. Disconnect the affected device from the network (Wi-Fi off, cable out).
  3. Change passwords for affected accounts from a different, clean device, and sign out of all sessions.
  4. Call your bank immediately if money or payment details are involved.
  5. Restore from backup once the device is clean.
  6. Report it to your national cybercrime or cybersecurity authority and, where required, to affected customers.

FAQ

Do small businesses really get targeted?
Yes. Many attacks are automated and hit anyone with weak passwords or unpatched software, regardless of size.

Do I need paid antivirus?
For most small offices, the protection built into modern Windows and macOS, kept up to date, plus the habits above, covers the basics. Larger teams may want managed security tools.

How often should we review this checklist?
Every 6 months, and whenever someone joins or leaves the business.

Next steps

Leave a Comment