A small business cybersecurity checklist helps you reduce the most common risks by securing accounts, devices, backups, email, access and employee habits. For most SMEs, the fastest wins are turning on multi-factor authentication, using a password manager, keeping systems updated, backing up data properly and limiting admin access. If you want the bigger picture, start with this cybersecurity guide for small businesses.
This small business cybersecurity checklist covers the core controls most small teams should put in place: strong account security, protected devices, tested backups, phishing defences, access control and staff training. It is designed to be practical, not technical for the sake of it.
- Turn on multi-factor authentication for critical accounts
- Use a password manager and strong unique passwords
- Review who has access to business systems
- Remove old accounts and unused permissions
- Keep operating systems, apps and plugins updated
- Protect laptops and phones with encryption and screen locks
- Install endpoint protection on business devices
- Back up important data and test recovery
- Secure business email against phishing and spoofing
- Train staff to spot common cyber threats
- Limit admin access and use least privilege
- Secure Wi-Fi, routers and remote access
- Create a simple incident response plan
- Check vendors and cloud tools for security basics
- Review the checklist regularly
If you need a broader planning resource alongside this checklist, see this cybersecurity checklist for SMEs.
Small Business Cybersecurity Checklist at a Glance
1. Turn on multi-factor authentication for critical accounts
Enable multi-factor authentication on email, banking, cloud storage, accounting systems, admin dashboards and any remote access tools. MFA matters because passwords are frequently stolen through phishing, malware and password reuse. A second verification step can stop an attacker even if they know the password.
Prioritise business email first. If attackers take over email, they can often reset other accounts and impersonate staff.
2. Use a password manager and strong unique passwords
Every business account should have a unique password. Reusing passwords means one breach can unlock multiple systems. A password manager makes this realistic for small teams because staff do not need to memorise dozens of long passwords. If you are evaluating tools, review these password managers for business.
3. Review who has access to business systems
List all staff, contractors and service providers with access to email, shared drives, finance platforms, CRM systems, websites and admin tools. Many small businesses lose track of access as teams grow. That creates hidden risk because old or unnecessary access can be abused or misused.
4. Remove old accounts and unused permissions
Disable former employee accounts, close unused logins and reduce permissions that are no longer needed. Stale accounts are a common weakness because no one watches them closely. They can also bypass current security rules if they were set up years ago.
5. Keep operating systems, apps and plugins updated
Apply software updates quickly across laptops, desktops, phones, browsers, plugins and business applications. Updates often fix known security flaws. Delay gives attackers time to exploit issues that are already public.
6. Protect laptops and phones with encryption and screen locks
Turn on device encryption, require screen locks and enable remote wipe where available. This protects business data if a device is lost, stolen or left unattended. For mobile teams, this is one of the simplest ways to reduce data exposure.
7. Install endpoint protection on business devices
Use reputable endpoint security or antivirus on all company devices. This helps detect malware, suspicious behaviour and ransomware activity. It is not enough on its own, but it adds an important layer alongside updates, MFA and backups.
8. Back up important data and test recovery
Back up critical files, cloud exports, emails where needed, accounting data, customer records and website content. A backup strategy only works if you can recover from it, so test restores regularly. This is essential for ransomware protection and accidental deletion.
9. Secure business email against phishing and spoofing
Use MFA, spam filtering and domain protections offered by your email provider. Train staff to verify links, attachments and urgent payment requests. Email is still the easiest path into many small businesses because it targets people, not just systems.
10. Train staff to spot common cyber threats
Employee cybersecurity training should cover phishing, password hygiene, suspicious attachments, fake invoices, unsafe downloads and reporting procedures. Training works best when it is short, repeated and tied to real tasks staff perform.
11. Limit admin access and use least privilege
Only give administrative rights to people who truly need them. Least privilege reduces the damage a compromised account can cause. If a normal user account is breached, the attacker should not automatically gain full control over systems.
12. Secure Wi-Fi, routers and remote access
Change default router passwords, update router firmware, use strong Wi-Fi encryption and limit remote access to approved tools. If staff work remotely, require MFA and avoid exposing internal systems directly to the internet.
13. Create a simple incident response plan
Write down what to do if an account is compromised, a device is lost or malware is detected. Include who to contact, how to isolate devices, how to reset affected accounts and how to restore operations. In an incident, speed matters more than perfect documentation.
14. Check vendors and cloud tools for security basics
Before adopting software or service providers, check whether they support MFA, role-based access, activity logs, backups and secure account recovery. Third-party tools can become a weak link if they are poorly managed.
15. Review the checklist regularly
Security changes as your business changes. Review this checklist at least annually and whenever you add new staff, systems, devices, vendors or remote work arrangements.
Why Small Businesses Need a Cybersecurity Checklist
Common risks for small teams
Small teams often move fast, share tools informally and rely on a few key people to manage everything. That creates common gaps such as shared logins, missing MFA, weak offboarding, outdated software and untested backups. Attackers know this. They do not only target large enterprises with dedicated IT teams.
Another issue is limited time. Many owners know security matters but need a clear order of actions. A business cybersecurity checklist turns a broad problem into a manageable set of tasks.
What this checklist helps prevent
This checklist helps reduce account takeover, phishing losses, ransomware impact, accidental data exposure, unauthorised access and downtime caused by device loss or poor recovery planning. It does not eliminate every risk, but it greatly improves your baseline security posture.
For standards-based guidance, see resources from CISA, NIST and the NCSC.
Account Security Checklist
MFA for email, banking, cloud storage and admin tools
Start with accounts that can unlock other systems or move money. That usually means email, banking, accounting, password managers, cloud storage, website hosting, domain registrars and remote access tools. Use app-based authentication or hardware keys where possible. SMS-based MFA is better than no MFA, but stronger methods are preferable when available.
Password policies that are realistic for small teams
A realistic small business security checklist should not rely on staff creating and remembering complex passwords without help. Use a password manager, require unique passwords and protect the manager itself with MFA. Focus on long, unique credentials rather than forcing frequent password changes unless there is evidence of compromise.
If you want to compare options, see this password manager comparison.
Shared account risks and how to reduce them
Shared accounts make it hard to know who did what and nearly impossible to remove access cleanly when someone leaves. Where possible, give each person an individual login. If a system forces shared access, store the credentials in a shared vault, restrict who can use them and change the password whenever team responsibilities change.
Device Security Checklist
Update policies for laptops, desktops and phones
Turn on automatic updates where practical. Keep an inventory of business devices so you know what must be patched. Include laptops, office desktops, company phones, tablets, routers and any business-critical apps. Patch management matters because attackers often exploit older, known vulnerabilities rather than sophisticated zero-day flaws.
Antivirus or endpoint protection basics
Every business device should have endpoint security enabled and monitored. Basic antivirus is better than nothing, but endpoint security with central management can be more suitable once your team grows. The key is consistency: all devices, all users, no exceptions for senior staff.
Encryption, screen locks and lost-device protection
Use full-disk encryption on laptops and phones. Require strong screen locks and short auto-lock times. Enable device location or remote wipe features if your platform supports them. These controls reduce the impact of theft and simple human error, which is still one of the most common ways data is exposed.
Backup and Recovery Checklist
What business data should be backed up
Back up customer records, financial data, contracts, shared documents, website files, configuration data and anything your business would struggle to rebuild quickly. For cloud tools, do not assume the provider covers every recovery need. Many platforms protect availability, not your ability to undo user error or malicious deletion.
How often backups should run
Backup frequency depends on how much data you can afford to lose. A business that updates records all day may need daily or more frequent backups. A business with slower change cycles may not. The right schedule is based on operational impact, not guesswork.
Why recovery testing matters
Untested backups create false confidence. Test file restores and, where relevant, system recovery. Even a simple quarterly test can reveal missing permissions, corrupted files or incomplete backup coverage before an emergency happens.
Access Control Checklist
Least-privilege access for staff and contractors
Give people access only to the systems and data they need for their role. A salesperson does not need server administration. A contractor does not need permanent access after a project ends. Least privilege reduces both insider risk and the damage from stolen credentials.
Offboarding checklist for former employees
When someone leaves, disable accounts immediately, revoke MFA devices, remove access from shared platforms, collect company devices and rotate passwords to any shared systems they used. Offboarding should be a written checklist, not an informal memory-based task.
Admin account separation
Users who need admin rights should have separate admin accounts for privileged tasks and standard accounts for everyday work such as email and browsing. This limits exposure because risky activities happen under lower-privilege accounts.
Email and Phishing Protection Checklist
Staff habits that reduce phishing risk
Teach staff to pause before acting on urgency, check sender addresses carefully, avoid logging in through unexpected email links and verify unusual payment or bank detail changes through a separate channel. Good habits matter because many phishing attacks succeed through pressure and distraction, not technical sophistication.
Attachment, link and invoice verification steps
Create simple verification rules. For example, confirm invoice changes by phone using a known number, not contact details in the email. Review links before clicking. Treat unexpected attachments cautiously, especially compressed files, password-protected documents or prompts to enable macros.
Email security settings worth checking
At a minimum, review spam filtering, MFA, forwarding rules, mailbox access permissions and domain protections supported by your email platform. Also check whether former staff still have delegated mailbox access. These settings help reduce spoofing, compromise and silent misuse of email accounts.
Staff Cybersecurity Practices Checklist
Security awareness training topics
Focus training on the risks staff actually face: phishing, fake login pages, unsafe file sharing, password reuse, handling customer data, lost devices and reporting suspicious activity. Keep sessions simple and repeat them. One long annual session is usually less effective than shorter reminders throughout the year.
Reporting suspicious activity quickly
Staff should know exactly how to report a suspicious email, a lost phone, unexpected MFA prompts or a possible breach. Fast reporting helps contain incidents before they spread. If employees fear blame, they may stay silent, which increases damage.
Creating simple repeatable security habits
Good security habits should fit normal work. Examples include locking screens when stepping away, storing credentials in an approved vault, checking unusual requests verbally and using approved file-sharing tools instead of personal apps. Simple routines are easier to sustain than complex rules no one follows.
How to Prioritise This Checklist if You Have Limited Time or Budget
Start with highest-risk, lowest-cost actions
If resources are tight, prioritise controls that prevent common attacks quickly. For most small businesses, that means MFA, a password manager, software updates, device encryption, endpoint protection, admin access reduction and reliable backups. These steps usually provide more immediate risk reduction than advanced tools you may not be ready to manage.
What to do in the first 30 days
In the first month, you can make major progress by following this order:
- Turn on MFA for email, banking, cloud storage and admin tools
- Adopt a password manager and remove password reuse
- Review user access and disable old accounts
- Update all business devices and critical apps
- Enable encryption and strong screen locks
- Install or verify endpoint security on all devices
- Set up backups and test one restore
- Brief staff on phishing, invoice fraud and reporting steps
- Document a simple incident response plan
If you want more foundational reading after this checklist, visit our broader cybersecurity guide.
When to Review and Update Your Cybersecurity Checklist
Annual review triggers
Review your small business cyber security checklist at least once a year. Confirm that MFA is still enabled, staff access still matches roles, backup coverage still fits the business and device protection still covers all active systems. Annual review is the minimum, not the ideal, for fast-changing teams.
Events that require an immediate review
Do not wait for the annual cycle if your business changes. Review the checklist immediately when you hire or lose key staff, add new software, move to a new email or cloud provider, increase remote work, suffer a phishing incident, merge with another company or expand the use of contractors.
FAQ
What is a small business cybersecurity checklist?
A small business cybersecurity checklist is a practical list of security actions used to reduce common cyber risks across accounts, devices, backups, email, access and employee behaviour.
What are the most important cybersecurity steps for a small business?
The most important steps are enabling multi-factor authentication, using a password manager, updating software, backing up critical data, limiting admin access and training staff to recognise phishing.
How often should a small business review its cybersecurity checklist?
Review it at least annually, and sooner whenever there is a security incident or a major change in staff, systems, vendors or work arrangements.
Do small businesses need multi-factor authentication for all accounts?
At minimum, use MFA for email, banking, cloud storage, admin tools and remote access. Ideally, enable it for all business systems that support it.
What should be included in a small business backup plan?
A backup plan should cover critical business data, backup frequency, secure storage, retention, restore responsibilities and regular recovery testing.
How can employees help improve small business cybersecurity?
Employees improve security by using approved password tools, following phishing checks, locking devices, reporting suspicious activity quickly and handling business data carefully.
What is the easiest way for a small business to reduce phishing risk?
The easiest high-impact step is to combine MFA with simple staff training on how to verify links, attachments and urgent requests before taking action.
A good SME cybersecurity checklist is not about doing everything at once. It is about putting the most effective controls in place first, then reviewing them as the business changes. If your team starts with account security, device protection, backups, email safety and repeatable staff habits, you will already be reducing the most common and costly risks.





