Executive summary

Most small businesses do not need every cybersecurity product. They need a 90-day plan that establishes a small number of capabilities that work together:

  1. clear ownership and an inventory of critical assets, data, and providers;
  2. strong identity and email security;
  3. securely configured and maintained endpoints and cloud services;
  4. tested backups and recovery procedures;
  5. monitoring with a named person or provider responsible for alerts;
  6. a practiced incident-response process; and
  7. independent validation of external exposure and priority risks.

Use the checklist below to establish the first controls in days 1–30, make them repeatable in days 31–60, and test them in days 61–90. Do not begin with an enterprise tool stack, a penetration test, or a compliance platform unless the business problem actually calls for it.

The right cybersecurity plan depends on what the company does, which information it handles, how it makes money, what customers require, and what would stop operations. This guide provides a practical sequence for small and midsized businesses that need meaningful protection without enterprise waste. It is a starting point, not a substitute for a risk assessment tailored to the company. Assign an owner and retain evidence as each item is completed; an unchecked task list is not an operating security program.

Start with risk and operations—not a shopping list

Cybersecurity purchases often begin after an insurer, customer, board member, or alarming headline creates urgency. That urgency can lead to disconnected products: endpoint software from one provider, backups from another, an email add-on, an annual scan, and no one accountable for whether the pieces work together.

NIST created the Cybersecurity Framework 2.0 Small Business Quick-Start Guide for small and medium-sized businesses with modest or no cybersecurity plan. It organizes outcomes into six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

That sequence is a useful antidote to tool-first buying. A small business should understand responsibility, critical operations, assets, sensitive data, suppliers, and risk before deciding which technology or service is justified.

The seven cybersecurity services most small businesses need

1. Security ownership and risk-based planning

Someone must be accountable for the security roadmap, even when technical work is outsourced. This may be an owner, operations leader, IT director, cybersecurity consultant, or vCISO—but authority and escalation cannot remain ambiguous.

The work should include:

  • identifying critical business services and sensitive information;
  • documenting legal, regulatory, contractual, and insurance requirements;
  • assigning risk and system owners;
  • maintaining a short risk register;
  • establishing policies that match actual operations; and
  • reviewing progress with leadership on a defined cadence.

This is the Govern layer. Without it, providers can complete tickets while important business risks remain unowned.

2. Asset, software, data, and vendor inventory

You cannot protect what no one knows exists. The company should maintain a usable inventory of:

  • laptops, desktops, mobile devices, servers, and network equipment;
  • cloud services and business applications;
  • employee, administrator, service, and vendor accounts;
  • domains, websites, remote-access systems, and internet-facing assets;
  • sensitive data categories and where they are stored or transmitted; and
  • providers that can access systems or important information.

NIST recommends inventorying hardware, software, systems, and services, then identifying their owners, access to sensitive data, MFA status, and business impact if unavailable. For many small businesses, a disciplined spreadsheet is a better starting point than an expensive asset-management platform—as long as someone maintains it.

3. Identity, email, and access security

Identity is where small-business security should become concrete. Priority work includes:

  • MFA for email, cloud administration, remote access, finance, payroll, banking, password managers, and other critical services;
  • separate administrator and everyday-user accounts;
  • removal of dormant, shared, or unnecessary access;
  • secure account recovery and backup-factor procedures;
  • password-manager deployment;
  • rapid offboarding when personnel or vendors leave;
  • anti-phishing controls and user reporting; and
  • email-domain protections such as SPF, DKIM, and DMARC, implemented and monitored carefully.

NIST describes MFA as one of the fastest and least costly protections available to a small business. Ownership still matters: buying an identity license does not ensure every privileged or high-risk account is covered.

4. Endpoint, cloud, network, and vulnerability management

The business needs a repeatable process—not an occasional cleanup—for maintaining the technology it uses.

Core services commonly include:

  • supported operating systems and automatic security updates;
  • endpoint protection with tamper protection and alert monitoring;
  • secure configuration of Microsoft 365, Google Workspace, cloud platforms, firewalls, and remote access;
  • device encryption and screen-lock requirements;
  • vulnerability identification and risk-based remediation;
  • removal or isolation of obsolete systems; and
  • administrative controls for software installation and configuration changes.

CISA maintains the Known Exploited Vulnerabilities Catalog as an authoritative list of vulnerabilities known to have been exploited in the wild. Small businesses should use active exploitation, internet exposure, asset importance, and available mitigations to improve patch prioritization rather than relying only on raw severity scores.

5. Tested backups and recoverability

A backup is not a recovery capability until the organization has confirmed that it can restore the systems and data required to operate.

The service should define:

  • which systems and data are backed up;
  • backup frequency and retention;
  • separation from ordinary user and administrator access;
  • protection against deletion or ransomware encryption;
  • recovery-time and recovery-point expectations;
  • restoration priority; and
  • scheduled restore testing with documented results.

CISA's Cyber Guidance for Small Businesses specifically emphasizes performing and testing backups. A successful dashboard status is not the same as a demonstrated restore.

6. Monitoring, alert ownership, and escalation

Security tools create value only when someone receives, understands, and acts on their output. At minimum, monitoring should cover critical identity events, endpoint detections, email threats, backup failures, administrative changes, internet-facing services, and other systems whose compromise or outage would materially affect the business.

Define:

  • which sources are monitored;
  • who reviews alerts and during which hours;
  • how severity is determined;
  • who can contain a device or disable an account;
  • when leadership, legal counsel, insurance, customers, or law enforcement may need notification; and
  • how actions and evidence are documented.

NIST recommends considering a service provider for monitoring when the business lacks internal resources. The contract should make the difference between notification, investigation, and containment explicit.

7. Incident response and recovery practice

Every small business needs a short, usable response plan. It should identify a business leader, technical contacts, legal and insurance contacts, communication methods, decision authority, reporting obligations, and the first actions for likely scenarios.

Practice at least one scenario such as:

  • compromised Microsoft 365 or Google Workspace administrator;
  • fraudulent payment request or business email compromise;
  • ransomware on an endpoint or server;
  • lost device containing sensitive data;
  • cloud application or critical vendor outage; or
  • exposed customer information.

NIST advises small businesses to identify who has authority, whom to call, what must be reported, and whether the response plan has been practiced. The FTC's Cybersecurity for Small Business resources also address common attacks and practical protection steps.

The outside-in layer small businesses frequently miss

Internal security reviews are necessary, but they can inherit internal blind spots. A passive external exposure review can identify conditions that warrant investigation, including:

  • forgotten or shadow internet-facing systems;
  • exposed remote-access services;
  • email authentication weaknesses;
  • public indicators of vulnerable technology;
  • historical corporate credentials appearing in breach collections;
  • third-party relationships visible through public infrastructure; and
  • public information that could improve phishing or impersonation attempts.

These observations are leads for validation. They are not proof that an account works, a system is exploitable, data was accessed, or the business is compromised. Used responsibly, outside-in intelligence helps the company decide where internal verification and remediation should begin.

The 90-day small business cybersecurity checklist

Days 1–30: establish control of the basics

  • Assign a security owner and escalation path.
  • Inventory critical systems, applications, vendors, administrators, and sensitive data.
  • Enforce MFA on high-value and privileged accounts.
  • Remove unnecessary access and secure account recovery.
  • Confirm endpoint protection and security updates are operating.
  • Validate backup coverage and perform a documented restore.
  • Identify who receives security alerts and what they must do.
  • Create a one-page incident contact and decision sheet.
  • Review the public attack surface for unexpected exposure.

Days 31–60: make the program repeatable

  • Prioritize configuration and vulnerability remediation.
  • Harden cloud, email, network, and remote-access settings.
  • Formalize onboarding, role changes, offboarding, and vendor access.
  • Build a risk register and sequenced security roadmap.
  • Improve logging for critical systems and test escalation.
  • Run an incident-response tabletop exercise.
  • Review cyber-insurance requirements and response contacts.
  • Document recovery priorities and repeat restore testing.

Days 61–90: verify and exercise

  • Recheck privileged accounts, MFA coverage, dormant access, and vendor access.
  • Confirm priority vulnerability and configuration fixes with evidence.
  • Test alert escalation from detection through leadership notification.
  • Perform a second documented restore against the agreed recovery objective.
  • Run an incident-response tabletop and record decisions, gaps, and owners.
  • Compare the current external attack surface with the initial review.
  • Brief leadership on residual risk, accepted risk, and the next-quarter roadmap.

Add later—or sooner when risk requires it

The following services can be valuable, but they require a business case and appropriate prerequisites:

  • 24/7 managed detection and response;
  • penetration testing or red-team exercises;
  • security information and event management beyond core monitoring needs;
  • data loss prevention and advanced information-protection tooling;
  • formal compliance-management platforms;
  • application security testing and secure-development programs;
  • full-time internal security staffing; and
  • advanced threat hunting or digital forensics retainers.

"Later" does not mean unnecessary. A regulated company, high-value target, software provider, healthcare organization, manufacturer, financial services firm, or business with significant sensitive data may need these capabilities immediately. The point is to make the decision based on exposure, obligations, architecture, and impact—not product fashion.

What can usually wait when fundamentals are weak?

A broad penetration test before scope and ownership are clear

Testing may identify exploitable conditions, but it will not correct weak account lifecycle management, missing recovery plans, unknown assets, or unowned alerts. Establish the environment and remediation capacity first unless a customer, contract, incident, or credible risk requires immediate testing.

An enterprise-scale SIEM without an operating model

Collecting more logs can increase cost and noise. Define critical detection use cases, retention needs, data owners, investigation responsibilities, and response authority before purchasing enterprise-scale ingestion.

A compliance platform before requirements are understood

Workflow software can organize evidence, but it cannot decide what applies or whether a control operates effectively. Confirm obligations and scope before automating the paperwork.

Multiple overlapping security tools

More agents and dashboards can create conflicts, blind spots, and unclear ownership. Determine which capability each product provides, who manages it, what happens when it alerts, and whether an existing service already covers the need.

How to choose between an MSP, MSSP, consultant, and vCISO

Choosing a provider by need
NeedBest-fit service
Day-to-day devices, accounts, networks, and IT supportMSP
Continuous monitoring and alert investigationMSSP or MDR provider
Defined assessment, architecture question, or security projectCybersecurity consultant
Ongoing governance, roadmap ownership, provider coordination, and executive reportingvCISO
Controlled exploitation of a defined scopePenetration-testing firm

Many businesses need more than one provider. Require a responsibility matrix that identifies who operates, monitors, approves, investigates, contains, communicates, and verifies. "Our MSP handles security" is not a control description.

Questions to ask before buying small-business cybersecurity services

  1. Which business outcome or risk does this service address?
  2. What systems, users, locations, and cloud services are included or excluded?
  3. Who configures the service and verifies that it remains correctly configured?
  4. Who reviews alerts, during what hours, and what action can they take?
  5. What evidence will demonstrate that the service is operating?
  6. How does the provider protect administrative access and customer data?
  7. How are incidents escalated, preserved, and communicated?
  8. What integrations or internal work are required from us?
  9. What happens to our data, configurations, and logs when the contract ends?
  10. How will the service adapt as our business, technology, and obligations change?

The answers should be understandable to both leadership and the people responsible for implementation.

Turn the checklist into an accountable program

HostBreach provides threat-informed cybersecurity advisory that helps small and midsized organizations decide what to protect, what to fix first, which services are justified, and how to verify progress.

Our Cyber Intel Snapshot supplies a passive outside-in view for internal validation and prioritization. It does not prove compromise or replace authorized assessment. When the business needs continuing leadership, Threat-Informed vCISO services provide roadmap ownership, provider coordination, risk governance, and executive communication.

If you need a practical security plan instead of another disconnected product, book a focused advisory conversation.

Primary sources

Source and interpretation note

Prepared September 23, 2026. Government sources are cited for their published guidance. The service sequencing, buyer guidance, outside-in interpretation, and "what can wait" analysis are HostBreach recommendations. Each business should adjust priorities to its operations, threats, contracts, regulatory obligations, architecture, and risk tolerance.