The Small Business Cybersecurity Checklist
The essentials, in priority order, mapped to NIST CSF 2.0
A plain-English checklist of the security controls that actually matter for a small or mid-sized business, ordered by impact and mapped to the six functions of the NIST Cybersecurity Framework 2.0.
What is the minimum cybersecurity a small business needs?
Five controls cover most of the real risk: multi-factor authentication (MFA) everywhere, tested backups (3-2-1), fast patching, short regular security-awareness training, and a one-page incident response plan. Together they stop or contain the large majority of attacks that hit small businesses, and none require a big budget.
Key Facts:
- MFA everywhere: blocks most credential attacks (the #1 entry point)
- Tested backups (3-2-1): your insurance against ransomware
- Patch fast: unpatched software is low-hanging fruit
- Regular short training: people are the most-targeted layer
- A one-page incident response plan: turn a crisis into a procedure
Why the basics matter (2025 data)
Sourced industry figures, not our own claims.
Global average cost of a data breach in 2025 (US average: $10.22M).
Source: IBM Cost of a Data Breach 2025Of small-business breaches involved ransomware, far higher than large enterprises.
Source: Verizon 2025 DBIROf breaches start with stolen credentials, the #1 initial-access vector. MFA is the fix.
Source: Verizon 2025 DBIRFunctions in NIST CSF 2.0 (2024): Govern, Identify, Protect, Detect, Respond, Recover.
Source: NIST Cybersecurity Framework 2.0The checklist, by NIST CSF 2.0 function
Work top to bottom. The Protect and Recover items are where most small businesses win or lose.
Govern
Write down who owns security, your basic policies (access, data handling, acceptable use), and how much you will spend. Governance is what makes the rest repeatable.
Identify
Know what you have and what matters: your devices, your key software, and where your sensitive data lives. You cannot protect what you have not inventoried.
Protect
MFA everywhere, a password manager, least-privilege access, encryption for sensitive data, patching, and regular short training. This is the bulk of the work and the biggest risk reducer.
Detect
Basic monitoring and logging so you find out about a problem before your customers do. Even lightweight alerting shortens the time to detect, which is what drives breach cost.
Respond
A short, documented incident response plan with named owners and a tested runbook. Improvising during an incident is slow and expensive.
Recover
Tested backups on a 3-2-1 strategy, and a recovery plan you have actually rehearsed. Untested backups are the reason ransomware is so costly.
Want to see where you actually stand?
Our free Security Scorecard scores you against these six functions and hands you your biggest gaps in priority order. Takes a few minutes.
Small business cybersecurity, FAQ
Common questions about getting the basics right.
Related Services
Explore our other technical consulting services
Tell us what you're building.
Bring us the problem you're solving. We'll tell you how we'd build it, what it takes, and how Simple Engineers can help your business scale its technology.
Get in Touch
hello@simpleengineers.com
We typically respond within 2-4 hours
Phone
+1 (888) 966-0773
Mon-Fri 9AM-6PM EST
Location
Global Remote Team
Serving clients worldwide
Response Time
Within 24 hours
Emergency support available
Why Partner with Simple Engineers?
- Senior engineers who build and ship, not just advise
- We stay on to run and grow what we build
- You own everything: your code, your cloud, your keys
- Scaling companies from startup to enterprise since 2016
Send Us a Message
Tell us about your project or goals and we'll get back to you within one business day.