Even if you’re hesitant about creating a small business cybersecurity checklist, hackers won’t hesitate to target you and that can wreak havoc on your operation, wasting precious hours and draining funds.
According to the Federal Communications Commission, “theft of digital information has become the most commonly reported fraud, surpassing physical theft.” The department has created a tip sheet for small businesses.
It’s important to zero in on the areas where you can lower your risk with a practical checklist that gives you and your team a security routine, hardens your systems and secures your customer data.
Here’s a quick explainer on areas to assess and strengthen and a downloadable checklist to help you take necessary action.
- Initial Risk Assessment: Consider where you may be exposed to hackers – weak or reused passwords, unprotected remote desktop protocol (RDP), outdated software and passes, missing multi factor authentication (MFA) and former employees who may have access. Seek out suspicious activity red flags — unexpected new admin accounts, cleared security logs, unauthorized alteration of security software settings or strange domain searches. Secure your website by enabling HTTPS and regularly updating your CMS, themes and plugins. A web application firewall (WAF) is also essential.
- Review best practices: Take a free cue from some of the top minds in cybersecurity by reviewing advice online, such as Palo Alto Networks’ Small Business Cybersecurity Best Practices Guide, which offers a 5-minute Security Audit.
- Identity and access: Examine email, cloud apps, banking, databases and administrative accounts to be sure MFA is switched on everywhere. This includes any systems you or your team access remotely — like remote desktops, file-sharing tools or VPNs. Microsoft says that MFA can block more than 99% of automated attacks to compromise your accounts. Passkeys, Web Authentication and FIDO2 hardware keys like YubiKey, Titan or built-in platform keys are both strong and phishing resistant. Authenticator apps are also useful and widely available. The experts at Byteclarity suggest that SMS text codes should only be used when there are no stronger options.
- Passwords & Managers: the number one way small business systems are breached is through stolen and reused credentials. One unsecured access point can create a disastrous snowball effect. This includes laptops, smartphones, desktops and employee-owned devices. Use a business-grade password manager — such as 1Password, Bitwarden or Keeper — for all accounts and employees. As you enforce the use of strong, unique passwords, you’ll also disable the option to automatically save passwords within browsers.
- Phishing Training: Now that you’ve got MFAs and strong passwords, regularly train employees in how to spot, refuse and report suspicious phishing emails. You can even test your employees with fake phishing emails to maintain meaningful vigilance.
- Account Permissions: It’s important to regularly review user accounts and admin rights. Use that time to determine a hierarchy of access privilege. Give employees the minimum access they need to do their jobs and be certain to remove access as part of standard exit processes.
- Software updates and patches: enable automatic updates on all devices, be it for security software, operating systems or browsers. Practice regular digital housekeeping by removing old apps, switching off unused features and apply updates and patches.
- Data Backups: You’re likely backing up your most important data to a secure cloud or external device outside your network but don’t leave it on autopilot. Test restoration of backup data at least bi-annually so you’re not caught flat-footed during a real hacking incident.
- Make a Plan: Create a document with clear, step-by-step protocols for who to call in the event of a hacking incident or security breach. This should include IT providers, internal response leaders/chain-of-command, cyber insurer and attorney, if applicable. The goal is to have a clearly outlined plan to identify, isolate, and eliminate the incursion, then recover and create a way to review what happened. Each year, you should test this plan.
AFE members can read more about cybersecurity for small business by subscribing to the monthly newsletter. There are a host of reliable services and resources for creating your small business cybersecurity checklist, but they only help if you take the time to assess and complete this vital process to secure your business.
Article by
Shannon Severson
Content Writer and Researcher
