Skip to main content
Guide

The Small Business Cybersecurity Checklist

The essentials, in priority order, mapped to NIST CSF 2.0

A plain-English checklist of the security controls that actually matter for a small or mid-sized business, ordered by impact and mapped to the six functions of the NIST Cybersecurity Framework 2.0.

Q

What is the minimum cybersecurity a small business needs?

Five controls cover most of the real risk: multi-factor authentication (MFA) everywhere, tested backups (3-2-1), fast patching, short regular security-awareness training, and a one-page incident response plan. Together they stop or contain the large majority of attacks that hit small businesses, and none require a big budget.

Key Facts:

  • MFA everywhere: blocks most credential attacks (the #1 entry point)
  • Tested backups (3-2-1): your insurance against ransomware
  • Patch fast: unpatched software is low-hanging fruit
  • Regular short training: people are the most-targeted layer
  • A one-page incident response plan: turn a crisis into a procedure

Why the basics matter (2025 data)

Sourced industry figures, not our own claims.

$4.44M

Global average cost of a data breach in 2025 (US average: $10.22M).

Source: IBM Cost of a Data Breach 2025
88%

Of small-business breaches involved ransomware, far higher than large enterprises.

Source: Verizon 2025 DBIR
22%

Of breaches start with stolen credentials, the #1 initial-access vector. MFA is the fix.

Source: Verizon 2025 DBIR
6

Functions in NIST CSF 2.0 (2024): Govern, Identify, Protect, Detect, Respond, Recover.

Source: NIST Cybersecurity Framework 2.0

The checklist, by NIST CSF 2.0 function

Work top to bottom. The Protect and Recover items are where most small businesses win or lose.

Govern

Write down who owns security, your basic policies (access, data handling, acceptable use), and how much you will spend. Governance is what makes the rest repeatable.

Identify

Know what you have and what matters: your devices, your key software, and where your sensitive data lives. You cannot protect what you have not inventoried.

Protect

MFA everywhere, a password manager, least-privilege access, encryption for sensitive data, patching, and regular short training. This is the bulk of the work and the biggest risk reducer.

Detect

Basic monitoring and logging so you find out about a problem before your customers do. Even lightweight alerting shortens the time to detect, which is what drives breach cost.

Respond

A short, documented incident response plan with named owners and a tested runbook. Improvising during an incident is slow and expensive.

Recover

Tested backups on a 3-2-1 strategy, and a recovery plan you have actually rehearsed. Untested backups are the reason ransomware is so costly.

Want to see where you actually stand?

Our free Security Scorecard scores you against these six functions and hands you your biggest gaps in priority order. Takes a few minutes.

Small business cybersecurity, FAQ

Common questions about getting the basics right.

Tell us what you're building.

Bring us the problem you're solving. We'll tell you how we'd build it, what it takes, and how Simple Engineers can help your business scale its technology.

Get in Touch

Email

hello@simpleengineers.com

We typically respond within 2-4 hours

Phone

+1 (888) 966-0773

Mon-Fri 9AM-6PM EST

Location

Global Remote Team

Serving clients worldwide

Response Time

Within 24 hours

Emergency support available

Why Partner with Simple Engineers?

  • Senior engineers who build and ship, not just advise
  • We stay on to run and grow what we build
  • You own everything: your code, your cloud, your keys
  • Scaling companies from startup to enterprise since 2016

Send Us a Message

Tell us about your project or goals and we'll get back to you within one business day.

Prefer email? Reach us at hello@simpleengineers.com