Most successful attacks on small businesses exploit the absence of a handful of basic controls, not exotic hacking. This checklist is those controls, ordered roughly by impact per effort. It is also, not coincidentally, close to what cyber insurance carriers now require on their applications. Work down the list honestly and you will know exactly where you stand.
The checklist
- Multi-factor authentication everywhere. MFA on email, VPN, banking, and anything remote-accessible. It is the single highest-impact control on this list, and most account takeovers die right here. Weekend fix or project? Weekend fix.
- Endpoint detection and response (EDR). The modern replacement for traditional antivirus, watching how programs behave instead of matching known signatures. Insurance carriers increasingly require it by name. Weekend fix or project? Project, a small one.
- Tested backups, with offline or immutable copies. A backup you have never restored is a hope, not a control. Ransomware crews target backups first, so at least one copy must be beyond their reach. Weekend fix or project? Project.
- Email security beyond the default filter. Advanced phishing and account-takeover protection layered on top of the Microsoft 365 or Google Workspace defaults. Most attacks still arrive by email, so this is where the volume gets stopped. Weekend fix or project? Weekend fix to buy, ongoing to tune.
- Patching that actually happens. A schedule with evidence, covering operating systems, browsers, and the applications attackers love. If nobody can show you when the last patch cycle ran, it is not happening. Weekend fix or project? Project if manual, weekend fix if automated.
- Security awareness training with phishing simulation. Short, regular, and measured, so you can watch the click rate fall. Your people stop being the easiest way in. Weekend fix or project? Weekend fix to start.
- An incident response plan on one page. Who is called, in what order, and who can authorize shutting things down at 2 AM. Write it before you need it, because you will not write it well during the incident. Weekend fix or project? Weekend fix.
- Least-privilege access and offboarding discipline. Nobody has admin rights they do not need, and departed employees lose access the day they leave. Both failures show up in incident reports constantly. Weekend fix or project? Weekend fix to audit, discipline to keep.
- A hardware and software inventory. You cannot protect what you do not know you have. That includes the forgotten server under someone's desk and the free tool a department signed up for two years ago. Weekend fix or project? Project, a small one.
- Logging you can actually look at. Centralized logs from your critical systems, retained long enough to investigate an incident, which means weeks, not days. Without them, the answer to "what happened" is a shrug. Weekend fix or project? Project.
- Vendor and cloud account review. Who has access to your data from outside, and what happens if they are breached. An annual review with an actual list beats a vague sense that it is probably fine. Weekend fix or project? Weekend fix, annually.
- Cyber insurance that matches reality. Read the application questions as a checklist, because answering one dishonestly is how claims get denied. Align the policy with the controls above. Weekend fix or project? Weekend fix to read, project to align.
Where most small businesses actually stand
In our assessment work, the same pattern repeats: MFA partially deployed, backups running but never tested, no EDR, and no written plan. That is not a criticism. It is a resourcing reality, because these controls add up to a part-time job that nobody was ever actually given. The gap between "we have IT support" and "someone owns security" is exactly where incidents happen.
Doing this with help
Every control on this list is included in a managed security program, which is how most small businesses close the whole list at once for a predictable monthly cost instead of running twelve separate projects. NetStandard runs that program for businesses across Kansas City, Des Moines, Omaha, and the surrounding region.
Frequently asked questions
Q: What are the most important cyber security controls for a small business?
A: If you only do three: multi-factor authentication everywhere, endpoint detection and response, and tested offline backups. Those three break the most common attack chains: account takeover, malware, and ransomware extortion.
Q: What do cyber insurance companies require?
A: Applications now commonly ask for MFA, EDR, tested backups, security training, and an incident response plan. Answering yes without having them is worse than not having insurance, because misrepresentation is grounds for claim denial.
Q: How much does it cost a small business to implement this checklist?
A: Several items are configuration effort rather than purchases. The purchased items (EDR, email security, backup, training) are per-user monthly subscriptions that, bundled through a managed security program, cost a predictable monthly amount rather than twelve invoices.
Want the honest version of where you stand?
A security assessment walks this exact list against your environment and hands you the prioritized result. Call (913) 428-4200 or schedule it.