Skip to content
Eudora Technology
Home  / Insights
Cybersecurity

The Small-Business Cybersecurity Checklist

U.S. Customs and Border Protection officers screen international passengers arriving at the Dulles International Airport in Dulles, Va., November 29, 2016. U.S. Customs and Border
Photo: 161129-Dulles-OFO-Ops-GF-005 by U.S. Customs and Border Protection, Public domain, via Wikimedia Commons

If you do four things, do these: require multi-factor authentication everywhere, keep one backup copy an attacker cannot delete, patch anything facing the internet within two weeks, and remove administrator rights from everyday accounts. Those four cover most of what actually happens to small businesses. The other eight items on this list are worth doing and none of them matters as much.

U.S. Customs and Border Protection officers screen international passengers arriving at the Dulles International Airport in Dulles, Va., November 29, 2016. U.S. Customs and Border
Nothing on this list requires a security team. Most of it requires an afternoon, a decision and somebody who will not quietly skip step three.Photo: 161129-Dulles-OFO-Ops-GF-010 by U.S. Customs and Border Protection, Public domain, via Wikimedia Commons

The twelve controls, in the order they pay off

Order matters more than completeness. A business that has done items one to four properly is in better shape than one that has done all twelve badly, so work down the list rather than across it.

  1. Multi-factor authentication on email, remote access, finance systems and the identity platform itself. Phishing-resistant methods on the accounts that can move money.
  2. One immutable or offline backup copy that a compromised administrator account cannot delete, plus a restore you have actually tested.
  3. A patching rule in writing: internet-facing kit within 48 hours, everything else within 14 days.
  4. No standing administrator rights on day-to-day accounts. Separate admin accounts, used only for admin work.
  5. Managed devices with disk encryption, automatic updates and the ability to wipe a lost laptop remotely.
  6. Endpoint protection that detects behaviour as well as files, reporting to somewhere a human looks.
  7. An asset list: every device, every cloud service, every domain, every thing that answers from the internet.
  8. Leavers process that disables accounts the same day and rotates shared credentials the same week.
  9. Email authentication: SPF, DKIM and DMARC at enforcement so nobody can spoof your domain.
  10. A reporting route for suspicious messages, with a named person who responds and never blames the reporter.
  11. A two-page incident response plan stored somewhere that is not the file share, and walked through once a year.
  12. Supplier review for anyone holding your data or holding keys to your systems, revisited annually.

Nothing here is novel. Both CIS and CISA publish lists that look much like it, and the fact that independent bodies keep converging on the same dozen items is the point. The hard part was never knowing what to do.

Basic hygiene is now a published standard

The Center for Internet Security maintains the CIS Critical Security Controls, currently 18 controls containing 153 individual safeguards. Rather than expecting a ten-person business to attempt all 153, CIS groups them. Implementation Group 1 is a foundational set of 56 safeguards, which CIS calls essential cyber hygiene and describes as an emerging minimum standard of information security for all enterprises.

The description of the target organisation is worth quoting because it is unusually honest about who it is for: CIS says an IG1 enterprise is typically small to medium-sized with limited IT and cybersecurity expertise available, and that IG1 should be implementable without specialist expertise and aimed at thwarting general, non-targeted attacks. The full control list is free to download.

CISA’s Cross-Sector Cybersecurity Performance Goals cover similar ground from a different angle, prioritised by cost, complexity and impact. If you need to show a client or an insurer that your checklist maps to something recognised, those two documents are the ones to cite.

Where small businesses actually are today

The UK Department for Science, Innovation and Technology surveys thousands of businesses and charities each year, which makes its Cyber Security Breaches Survey the best public picture of what organisations really have in place rather than what they say they intend. The 2025/2026 edition, published in April 2026, surveyed 2,112 businesses and 1,085 charities.

Technical rule or controlBusinessesCharities
Restricting administrator rights to specific users73%65%
Only allowing access via organisation-owned devices66%35%
Security controls on organisation-owned devices61%42%
An agreed process for fraudulent emails or websites58%36%
Rules for storing and moving personal data securely51%47%
Backing up data securely by means other than cloud48%38%
Any two-factor authentication for networks or applications47%38%
Separate Wi-Fi networks for staff and visitors38%25%
A VPN for staff connecting remotely36%17%
A policy to apply security updates within 14 days34%20%
Monitoring of user activity33%28%
Percentage with each control in place. Bases: 2,112 businesses and 1,085 charities. Source: UK Cyber Security Breaches Survey 2025/2026.

Read down that column and the picture is clear. Restricting admin rights is common. Two-factor authentication sits at 47%, and a written patching policy at 34%. Those two are the controls that stop the attacks in the data, and they are the two most organisations have not done. Cloud backup is the one bright spot, up from 71% to 74% of businesses.

Identified a cyber breach or attack in the last 12 months, by business size
Micro businesses42%
Small businesses46%
Medium businesses65%
Large businesses69%
Overall figure for businesses was 43%. Source: UK Cyber Security Breaches Survey 2025/2026.

Smaller organisations report fewer incidents, and it is worth being careful about what that means. Part of it is a genuinely smaller attack surface. Part of it is that detecting an incident takes capability you need to pay for, and the organisations least likely to have monitoring are the least likely to know. Verizon’s 2026 DBIR, looking at cases where organisation size was known, found roughly 96% of ransomware victims were small and medium businesses. The attacks are landing.

43%
of UK businesses had a breach or attack
47%
require any two-factor authentication
34%
have a 14-day patching policy
25%
have a formal incident response plan
Source: UK Cyber Security Breaches Survey 2025/2026.
U.S. Customs and Border Protection officers screen international passengers arriving at the Dulles International Airport in Du;lles, Va., November 29, 2016. U.S. Customs and Border
Biometrics and badge readers are the visible part of access control. The part that matters is which accounts hold administrator rights at 3am.Photo: 161129-Dulles-OFO-Ops-GF-098 by U.S. Customs and Border Protection, Public domain, via Wikimedia Commons

Identity and access: items one to four

Start with multi-factor authentication, because it removes the cheapest attack. Cover email first, then remote access, then the finance systems, then your identity platform’s own administrator accounts. Then come back and upgrade the accounts that can move money to something phishing-resistant, because a relayed code is a solved problem for attackers.

Then backups. The question is not whether you have them but whether one copy survives someone holding every credential you own. Immutable object storage or disconnected media; pick one and test a restore quarterly. Then the patching rule, written down with dates, because the DBIR found the median organisation took 43 days to fully patch a known-exploited vulnerability after detecting it.

Fourth is standing administrator rights. The pattern is simple: a normal account for normal work, a separate account for administration, and no local admin on laptops unless there is a documented reason. This is the control that turns a single compromised laptop into a contained problem rather than a company-wide one. Our notes on current password rules cover the credential side of the same job.

Devices and patching: items five to eight

Managed devices come next, and this is where remote and hybrid teams complicate matters. Full disk encryption on, automatic updates on, remote wipe available, screen lock enforced. If people use personal machines, decide explicitly whether that is allowed and what the conditions are rather than letting it happen by default. The guidance for remote and hybrid teams goes into the device question properly.

Endpoint protection should detect behaviour, not just match files, and it should report somewhere a human will look. An alert nobody reads is a licence cost. Among UK large businesses, 93% have up-to-date malware protection and 93% have network firewalls, which suggests the tooling is rarely the gap. The monitoring is.

Then the asset list and the leavers process, which are both boring and both load-bearing. You cannot patch a server you have forgotten, and the account of someone who left in March is the quietest way into a business. Write both down; review the asset list every quarter and the leavers checklist every time it is used.

The asset list questions people get wrong
  • Which domains do you own, and who holds the registrar login?
  • What is still running at your old hosting provider?
  • Which cloud services did a department sign up for without telling anyone?
  • What hardware answers from the internet, including printers and cameras?

Backups, monitoring and the plan: items nine to twelve

Email authentication is a configuration job with an outsized payoff. SPF, DKIM and DMARC at an enforcing policy stops anyone sending mail that claims to come from your exact domain. It protects your clients and your suppliers as much as it protects you, and it takes an afternoon plus a fortnight of monitoring.

A reporting route matters more than people expect. Only 58% of UK businesses have an agreed process for staff to follow when they encounter a fraudulent email or website. The difference between a click reported in ten minutes and one reported in ten days is usually the entire difference in outcome.

Then the plan. Two pages: who decides, who calls the insurer and the lawyer, which systems come back first, and the phone numbers written as numbers. The UK survey found 25% of businesses have a formal incident response plan, and the gradient by size is steep.

Organisations with a formal incident response plan
Micro businesses21%
All businesses25%
Medium businesses57%
Large businesses76%
Source: UK Cyber Security Breaches Survey 2025/2026.

Finally, supplier review. The DBIR found breaches involving a third party have risen 60% and now account for 48% of all breaches. For a small business the practical version is one page per significant supplier: what data they hold, what access they have, what happens if they are breached, and who you call. If you handle personal data, this overlaps with your data protection obligations, and the processor contracts that go with them.

Half of all breaches now involve somebody else’s systems. Your checklist stops at your perimeter; your risk does not.

U.S. Customs and Border Protection officers screen international passengers arriving at the Dulles International Airport in Du;lles, Va., November 29, 2016. U.S. Customs and Border
Testing finds the gaps a questionnaire cannot. It also finds the three services nobody remembered signing up for.Photo: 161129-Dulles-OFO-Ops-GF-111 by U.S. Customs and Border Protection, Public domain, via Wikimedia Commons

Is certification worth the money?

Certification is worth it for two reasons, and neither is the certificate. First, the question set forces you to find out what you actually have. Second, clients and insurers increasingly ask, and having an answer shortens procurement. The UK’s Cyber Essentials scheme is the cheapest credible option, and IASME publishes its fees openly.

Organisation sizeCyber Essentials feeIn USDIn EUR
Micro, 0 to 9 employeesGBP 320 + VAT460400
Small, 10 to 49 employeesGBP 440 + VAT630550
Medium, 50 to 249 employeesGBP 500 + VAT710620
Large, 250 or more employeesGBP 600 + VAT850740
Published certification fees from IASME, retrieved 1 October 2026. Currency conversions are IASME’s own. Cyber Essentials Plus adds an independent technical audit and is quoted separately.

The self-assessment question set is free to download before you apply, which is the part worth doing even if you never certify. Work through it, write down what you cannot answer, and you have a prioritised list of your own gaps for the cost of an afternoon. The NCSC’s overview of the scheme explains what the five control areas cover.

For businesses outside the UK the same logic applies to whichever baseline your clients recognise, whether that is CIS IG1 as a self-assessment, SOC 2 for North American enterprise buyers, or ISO 27001 where a formal management system is expected. Pick the one your buyers ask about, not the one with the best marketing.

What to do in your first week

You can make real progress in five working days, and the sequence below is the one we actually use with clients. It front-loads the irreversible wins.

  1. Monday. List every account that can move money, change DNS, administer email or access the backups. This list is the whole project in miniature.
  2. Tuesday. Turn on MFA for every account on that list, and register a second factor for each so nobody gets locked out.
  3. Wednesday. Check whether your backup can be deleted by the account that runs it. If it can, create one copy that cannot, today.
  4. Thursday. Write the patching rule and the leavers checklist. Two paragraphs each. Circulate them.
  5. Friday. Restore something. A file, a mailbox, a virtual machine. Time it and write the number down.

That is not a security programme and it is not meant to be. It is the part that stops the incidents in the published data. IBM’s 2026 Cost of a Data Breach Report puts the global average at USD 4.99 million and notes that detection and escalation plus lost business make up 63% of the total. Both shrink when somebody notices early and the restore works.

Frequently asked questions

We are five people. Is any of this proportionate?

The first four items are, and they take days rather than months. CIS designed IG1 for exactly your situation: 56 safeguards meant to be implementable without specialist expertise. Skip the asset management software and the monitoring platform. Do MFA, a backup copy nobody can delete, patching and admin rights, and you have covered most of what the attack data shows.

Do we need cyber insurance as well?

Often yes, and the application form is useful on its own because it asks the questions you should be asking. Read the conditions: cover commonly depends on MFA being enforced, backups being tested and patching being current. An insurer that declines a claim because a control was not in place is worse than no insurer.

How much should a small business spend on security?

Less than most vendors suggest, and more of it on time than on licences. For a 25-person business the entire list above is achievable with your existing Microsoft 365 or Google Workspace subscription, a password manager at a few dollars per user per month, a handful of hardware keys and an immutable backup target. The expensive items are the ones you buy instead of doing the basics.

Should we hire someone or use a provider?

Below roughly 50 people a dedicated hire is hard to justify and hard to keep busy. A provider on a defined scope usually works better: they have seen the failure modes and they do not go on holiday. What you should keep in-house is ownership of the decisions, the asset list and the supplier relationships.

How often should we revisit the checklist?

Quarterly for the asset list and a restore test, annually for the plan rehearsal and the supplier review, and immediately whenever something structural changes: a new office, a new cloud platform, an acquisition, or a departure from a role with broad access.

We work through this checklist remotely with clients worldwide as part of our cybersecurity services, starting with the account inventory and the backup test rather than with a proposal for new tooling. Get in touch with Eudora Technology to talk about your project.

Sources

  1. CIS Critical Security Controls Implementation Group 1 Center for Internet Security · retrieved October 2026
  2. Cyber Security Breaches Survey 2025/2026 UK Department for Science, Innovation and Technology · April 2026
  3. 2026 Data Breach Investigations Report (19th edition) Verizon Business · 19 May 2026
  4. Cyber Essentials frequently asked questions and fees IASME Consortium · retrieved 1 October 2026
  5. Cost of a Data Breach Report 2026 IBM X-Force · July 2026
  6. Cross-Sector Cybersecurity Performance Goals CISA · retrieved October 2026
Keep reading

Related insights