BD Brynton DurantJournal

Security

The Small-Business Cybersecurity Baseline: 12 Controls That Matter

By Brynton Durant

Cybersecurity is not a software purchase. It is the ongoing practice of knowing what the business depends on, reducing avoidable access, preparing for failure, and recovering without improvisation.

Small organizations do not need to copy an enterprise security department. They need a defensible baseline. The following twelve controls translate widely accepted guidance into an operating checklist a business owner can understand and maintain.

1. Inventory critical accounts and systems

List the domain registrar, email, website, payment processor, bank, accounting platform, customer records, file storage, social profiles, advertising accounts, and essential devices. Record the owner, administrator, recovery method, and business consequence of losing each one.

Security begins with knowing what exists.

2. Require multifactor authentication

Turn on multifactor authentication for every important account, especially email, domains, finance, hosting, cloud storage, and administrator access. Prefer phishing-resistant methods such as security keys or passkeys when supported.

3. Use a password manager

Every account should have a unique password. Shared access should use delegated roles or a business password manager instead of passwords copied through email and text messages.

4. Separate administrator access

Do everyday work with ordinary permissions. Reserve administrator accounts for changes that require them. Contractors should receive their own limited access, not the owner's credentials.

5. Update devices and software

Enable automatic security updates where practical. Remove unsupported applications, abandoned plugins, unused browser extensions, and old devices that can no longer receive patches.

6. Back up essential data

Maintain copies that are separate from the systems being backed up. Include databases, uploaded files, financial records, customer information, contracts, and source files. Test a real restoration; successful backup notifications do not prove that recovery works.

7. Protect email and domains

Email is often the recovery channel for every other account. Secure it accordingly. Protect the domain registrar, enable renewal safeguards, review DNS changes, and configure appropriate email authentication records with qualified help when needed.

8. Train for phishing and payment fraud

Create a simple verification rule: changes to payment instructions, bank details, credentials, or sensitive access must be confirmed through a second trusted channel. Urgency should increase verification, not bypass it.

9. Limit and review vendors

Record which providers and contractors can access business data or systems. Review permissions when a project ends. Ask how vendors protect data, report incidents, support export, and delete records.

10. Secure the website and integrations

Use HTTPS, server-side authorization, validated inputs, protected secrets, security headers, dependable updates, and minimal third-party scripts. Public visitors should never be able to reach administrative or internal routes simply because they know the URL.

11. Create an incident checklist

Write the first actions before an incident occurs: isolate the affected device, preserve evidence, change exposed credentials, contact relevant providers, determine notification obligations, restore from known-good backups, and document decisions.

Include current contact information for insurance, legal, technical, financial, and communications support as appropriate.

12. Review the baseline quarterly

Businesses change. New contractors, tools, domains, payment accounts, automations, and devices create new dependencies. Review the inventory, access list, backup evidence, and recovery contacts at least quarterly.

The NIST Cybersecurity Framework 2.0 small-business guidance treats cybersecurity as continuous risk management. That is the right mental model: the baseline is not completed once; it is maintained.

Put the controls in order

If everything is currently informal, begin with email, domains, banking, payments, and backups. Enable strong authentication, document recovery, remove unnecessary access, then expand to vendors, training, and incident response.

This article is educational and not legal, insurance, or incident-response advice. Requirements vary by industry, location, contracts, and the information a business holds. Use the checklist to identify gaps and obtain qualified help where the consequences are significant.