# Cybersecurity best practices for small business: a prioritized checklist

> The cybersecurity best practices a small business needs first, taken from CIS IG1, NIST CSF 2.0 and Cyber Essentials, as a checklist in priority order.

- URL: https://computese.com/cybersecurity-best-practices/
- Author: Duong Quan Nguyen, CEO, Computese
- Published: 2024-06-06
- Updated: 2026-09-25
- Topics: Security, IT support

## In short
- Build on a published baseline, not a product list. CIS Controls v8.1 IG1, NIST CSF 2.0, CISA's Cyber Essentials, the UK's Cyber Essentials and Canada's baseline controls agree on almost the same short list.
- Start with accounts: list every device, account and supplier, turn on MFA wherever it is offered, give administrators phishing-resistant keys or passkeys and separate admin accounts, and remove access the day someone leaves.
- Keep systems current and recoverable: automatic updates with critical fixes inside 14 days, anti-malware on every device, and automated backups with one isolated copy that you have actually restored from.
- Close the email and people gaps: publish SPF, DKIM and DMARC, train staff to spot phishing and to confirm payment changes by phone, and switch on audit logging, which Microsoft 365 Business plans do not enable by default.
- Write a one-page incident plan before you need it: who leads, who backs them up, and the numbers for your IT provider, insurer, bank and national cyber agency, kept on paper as well.

Cybersecurity best practices for a small business come down to a short, well-agreed baseline: keep a list of every device, account and supplier; require multi-factor authentication; patch automatically; protect every endpoint; back up with an isolated copy you have test-restored; authenticate your email domain; limit admin rights; train staff; and write an incident plan that says who to call.

None of this is new, and that is the point. The Center for Internet Security (CIS), NIST, CISA, the UK's National Cyber Security Centre (NCSC) and the Canadian Centre for Cyber Security each publish a baseline for small organizations, and they overlap far more than they differ. This guide sets them side by side and turns them into a checklist in priority order for a business without a security team. For the habits that protect individuals at home and at work, read our [cyber security tips](https://computese.com/cyber-it-security/).

## The published baselines this checklist is built on

Five baselines are worth knowing. They differ in shape and audience, not in substance.

| Baseline                                        | Publisher and date                                         | Shape                                                              | Best for                                |
| ----------------------------------------------- | ---------------------------------------------------------- | ------------------------------------------------------------------ | --------------------------------------- |
| CIS Controls v8.1, Implementation Group 1 (IG1) | Center for Internet Security; current as of September 2026 | 56 safeguards                                                      | A detailed to-do list                   |
| Cybersecurity Framework (CSF) 2.0, with SP 1300 | NIST, February 2024                                        | Six functions: Govern, Identify, Protect, Detect, Respond, Recover | Owning and explaining the program       |
| Cyber Essentials                                | CISA, United States                                        | Six essential elements, from the leader to crisis response         | An owner deciding where to start        |
| Cyber Essentials scheme, requirements v3.3      | UK government and NCSC, April 2026                         | Five technical controls, certifiable                               | Proving the basics to customers         |
| Baseline cyber security controls                | Canadian Centre for Cyber Security, last updated 2020      | 13 controls for organizations under 500 employees                  | A short list aimed at the biggest gains |

### CIS Controls v8.1, Implementation Group 1

CIS defines [IG1](https://www.cisecurity.org/controls/implementation-groups/ig1) as "essential cyber hygiene": 56 safeguards every organization should apply against the most common attacks, written for small and medium organizations with limited IT expertise and off-the-shelf hardware and software. They come from 15 of the 18 Controls; network monitoring, application software security and penetration testing start at IG2. Grouped into plain actions, from the [CIS Controls Navigator](https://www.cisecurity.org/controls/cis-controls-navigator) for v8.1:

| Plain action                   | CIS Control                            | IG1 safeguards |
| ------------------------------ | -------------------------------------- | -------------- |
| Know your devices              | 1. Inventory of enterprise assets      | 2              |
| Know your software             | 2. Inventory of software assets        | 3              |
| Know and protect your data     | 3. Data protection                     | 6              |
| Set devices up securely        | 4. Secure configuration                | 7              |
| Manage accounts                | 5. Account management                  | 4              |
| Control access and require MFA | 6. Access control management           | 5              |
| Patch                          | 7. Continuous vulnerability management | 4              |
| Keep logs                      | 8. Audit log management                | 3              |
| Protect email and browsing     | 9. Email and web browser protections   | 2              |
| Stop malware                   | 10. Malware defences                   | 3              |
| Back up                        | 11. Data recovery                      | 4              |
| Keep network equipment current | 12. Network infrastructure management  | 1              |
| Train staff                    | 14. Security awareness and skills      | 8              |
| Know your service providers    | 15. Service provider management        | 1              |
| Prepare for incidents          | 17. Incident response management       | 3              |

### NIST CSF 2.0 and the small business quick-start guide

NIST [released CSF 2.0 on February 26, 2024](https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework), widening it to organizations of every size and adding a sixth function, Govern. Its [Small Business Quick-Start Guide (SP 1300)](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1300.pdf) lists a few actions per function for businesses with modest or no security plans. Treat CSF as the structure around the checklist: who owns security, which risks you accept, how you report progress.

### CISA's Cyber Essentials

CISA's [Cyber Essentials](https://www.cisa.gov/resources-tools/resources/cyber-essentials) is written for leaders of small businesses and small local governments, in six elements: Yourself, Your Staff, Your Systems, Your Surroundings, Your Data and Your Crisis Response. It separates what the owner decides from what IT does.

### The UK's Cyber Essentials scheme

The NCSC calls [Cyber Essentials](https://www.ncsc.gov.uk/cyberessentials/overview) the minimum standard the UK government recommends for organizations of all sizes. It has five technical controls (firewalls, secure configuration, security update management, user access control and malware protection) and is a certification: as of September 2026 it starts at £320 plus VAT, and Cyber Essentials Plus adds independent technical testing. The current [Requirements for IT Infrastructure v3.3](https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf), dated April 2026, states that cloud services cannot be excluded from scope and counts FIDO2 authenticators as multi-factor.

### Canada's baseline cyber security controls

The Cyber Centre's [baseline controls](https://www.cyber.gc.ca/en/guidance/baseline-cyber-security-controls-small-and-medium-organizations) are 13 controls for organizations with fewer than 500 employees, chosen to get 80% of the benefit from 20% of the effort. Last modified in February 2020, they still hold up, and they are the only baseline here that puts the incident response plan first.

## The small business cybersecurity checklist, in priority order

The order follows one rule: close first what ordinary, non-targeted attacks use (stolen passwords, unpatched software, phishing), then make sure you can recover.

1. **Inventory** devices, software, accounts, sensitive data and suppliers.
2. **Require MFA** on every account that offers it, phishing-resistant for administrators.
3. **Separate admin accounts**, remove everyday admin rights, and cut off leavers the day they leave.
4. **Patch automatically**, with critical and high-risk fixes inside 14 days; retire unsupported software.
5. **Protect every device** with anti-malware, a host firewall, a screen lock and disk encryption; our guide to [managing security on company devices](https://computese.com/how-to-manage-cybersecurity-on-your-devices/) shows how to enforce it from one console.
6. **Back up automatically**, keep one isolated copy, and prove it with a restore test.
7. **Authenticate your email domain** with SPF, DKIM and DMARC.
8. **Train staff** to spot phishing and payment fraud, and to report it.
9. **Control vendor and remote access**: who has it, MFA on every path in, one approved remote tool.
10. **Switch on audit logging** and keep the logs.
11. **Write an incident response plan** with names and phone numbers, on paper too.

## Take inventory of devices, software, accounts, data and suppliers

You cannot protect what nobody has written down, so every baseline starts here. IG1 asks for five lists: devices that can store or process data (laptops, phones, network equipment, servers, cloud machines), kept current; software, with only supported versions authorized; every account, including administrator and service accounts; sensitive data; and service providers, each with a named contact. NIST's guide and CISA's Cyber Essentials ask for the same.

Build the lists from what already exists:

- **Devices:** the device management console, the router's list of connected clients, purchase records.
- **Accounts:** the Microsoft 365 or Google Workspace user list, then everything outside it: bank, payroll, accounting, domain registrar, DNS host, website hosting, social media.
- **Software and cloud services:** card statements show the subscriptions nobody listed.
- **What faces the internet:** domains, subdomains, remote-access portals and certificate renewal dates, because an [expired SSL certificate](https://computese.com/ssl-certificate/) takes a site down as surely as an attack.

Managing the device fleet itself is a topic of its own; here the goal is a complete list. The internet-facing part is the hardest to see from inside, because forgotten test sites and old subdomains appear on no invoice. Our [security scanning](https://computese.com/services/security-testing/) service discovers domains, subdomains, IP ranges, certificates and cloud accounts from the outside, the way an attacker would find them, including the ones nobody remembered.

## Require MFA everywhere, and phishing-resistant MFA for admins

NIST's small business guide calls multi-factor authentication one of the fastest, cheapest ways to protect your data, starting with the accounts that reach the most: banking, accounting, payments, email, password managers and your Microsoft, Google or Apple accounts. If you are still choosing those tools, our guide to [software for starting an online business](https://computese.com/software-tools-for-starting-an-online-business/) covers who should own each account. IG1 requires it on internet-facing applications (enforcing it through single sign-on counts), on remote access and on every administrative account. Cyber Essentials v3.3 requires it wherever available and always for cloud services; CISA wants it for all users, privileged and remote-access users first.

Not all MFA is equal. CISA's [phishing-resistant MFA fact sheet](https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf) (October 2022) ranks the methods from strongest to weakest:

| Method                                                     | What CISA says                                                                  | Use it for                         |
| ---------------------------------------------------------- | ------------------------------------------------------------------------------- | ---------------------------------- |
| FIDO2 security key or passkey (WebAuthn), PKI smart card   | Phishing-resistant, the "gold standard"; push bombing and SIM swap do not apply | Administrators, finance and email  |
| Authenticator app or token code, push with number matching | Can be phished; resists push bombing                                            | Everyone else, until they can move |
| Push prompt without number matching                        | Vulnerable to push bombing and user error                                       | Nothing: turn on number matching   |
| SMS or voice code                                          | Vulnerable to phishing, SIM swap and telephone network (SS7) attacks            | A last resort                      |

The difference is what a fake sign-in page can steal. A code can be typed into the attacker's lookalike page and replayed to the real site while it is still valid. A passkey or FIDO2 key has nothing to type: it holds a key pair created for one domain and account, and [by design it is only presented to the site it was registered with](https://www.passkeycentral.org/introduction-to-passkeys/how-passkeys-work), so a perfect copy of your login page on another domain gets nothing it can use. Why the UK NCSC now recommends passkeys over passwords, and the other shifts coming by 2030, are covered in [the future of cybersecurity](https://computese.com/the-future-of-cybersecurity-2/).

![A laptop with an orange security key plugged in signs in to the real cloud service, while a lookalike server that tries to capture the sign-in gets nothing and is crossed out.](https://computese.com/images/blog/cybersecurity-best-practices/passkey.329c515e9e-1536.webp)

*A passkey or security key only answers the site it was registered with, so a perfect copy of your sign-in page gets nothing to replay.*

CISA suggests starting where support is already good, noting that most hosted email and single sign-on services support FIDO. Give each administrator two hardware keys (one spare), register passkeys for the people who approve payments, and use number matching for everyone else until they can move.

## Keep admin rights separate and remove access when people leave

CISA's Cyber Essentials asks for access and admin rights to be granted on need-to-know and least privilege. It matters because malware runs with the rights of whoever opened it. The Cyber Essentials requirements give the example of an administrator who opens a malicious attachment: the ransomware inherits admin privileges and encrypts far more than a standard account could reach. The fixes are routine:

- **Use a dedicated admin account for admin work only**, and a standard account for email and browsing (CIS safeguard 5.4, Cyber Essentials, Canada's control 12). Keep cloud admin accounts separate from internal ones, with MFA.
- **Remove local admin rights from everyday users.** For the local administrator account on Windows devices, [Windows LAPS](https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview) rotates a unique password on each device and backs it up, so one shared password no longer opens every machine.
- **Change or disable default accounts and passwords** on routers, printers, cameras and new software.
- **Grant access through a documented process, and revoke it immediately** when someone leaves or changes role. CIS also asks for dormant accounts to be disabled after 45 days of inactivity.
- **Keep password rules sane.** CIS suggests at least 8 characters with MFA and 14 without; Cyber Essentials and the Cyber Centre advise against forced periodic changes, and for a change whenever compromise is suspected.

Offboarding is where small businesses leak access. Our [IT support](https://computese.com/services/it-support/) service handles it as one documented sequence that revokes accounts, sessions and devices.

## Patch automatically and retire unsupported software

IG1 asks for automated operating system and application patching at least monthly, and for network equipment such as routers and firewalls to run current, supported software. The Cyber Essentials requirements are more precise: all software must be licensed and supported, automatic updates must be on where possible, and updates that fix critical or high-risk vulnerabilities (a CVSS v3 score of 7 or above, or no rating from the vendor) must be installed within 14 days of release. Canada's baseline asks for automatic patching everywhere, and a decision about devices that cannot update themselves.

When there is more to patch than time:

- **Fix what is already being exploited first.** CISA's [Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) lists vulnerabilities exploited in the wild, and CISA recommends using it to set priorities; our guide to [patch prioritization](https://computese.com/the-future-of-cybersecurity/) turns it into deadlines a small team can meet.
- **Replace what no longer gets fixes.** [Windows 10 reached end of support on October 14, 2025](https://support.microsoft.com/en-us/windows/deployment/updates-lifecycle/windows-10-support-has-ended-on-october-14-2025); a PC not enrolled in Extended Security Updates gets no more security updates, and Cyber Essentials requires unsupported software to be removed or cut off from the internet.

For the steps on each platform, see [how to update your computer or phone](https://computese.com/how-to-update-your-computer-or-phone/).

## Protect every device: anti-malware, firewall, lock and encryption

The endpoint safeguards in IG1 are unglamorous and effective: anti-malware on every device with automatic updates, autorun disabled for removable media, a host firewall on servers and laptops, an automatic screen lock after no more than 15 minutes on computers, and encryption on end-user devices that hold sensitive data (CIS names BitLocker, FileVault and dm-crypt as examples). NIST's guide asks specifically for full-disk encryption on laptops and tablets.

IG1 asks only for anti-malware that updates itself; behaviour-based detection, which is what endpoint detection and response (EDR) adds, appears in IG2. If you have Microsoft 365 Business Premium, you may already own it: [Microsoft Defender for Business](https://learn.microsoft.com/en-us/defender-business/mdb-overview), built on Defender for Endpoint for organizations of up to 300 users, is included. Whether the antivirus built into Windows is enough for a single PC is covered in [how to choose antivirus software](https://computese.com/choose-the-right-antivirus-software-for-your-pc/).

## Back up with an isolated copy, and prove it by restoring

Backups turn ransomware from a catastrophe into a bad week, but only if the attacker cannot reach them. IG1 asks for a documented recovery process, automated backups at least weekly, backups protected as well as the originals, and one isolated copy: offline, off-site or in versioned cloud storage. Canada's baseline asks for encrypted backups and requires long-term ones, such as weekly backups, to be kept offline; CISA also calls for offline copies. Cyber Essentials v3.3 does not require backups, but recommends them strongly.

An online backup is exposed to anything the attacker can reach from your network, including a drive left plugged in. The isolated backup is the one that survives.

![Two laptops feed a file server marked with a bug, which copies to a cloud backup and to an orange external drive whose cable is unplugged; an arrow from that drive restores files to a clean laptop with a check mark.](https://computese.com/images/blog/cybersecurity-best-practices/backup.abcc2483af-1536.webp)

*A backup ransomware can reach is not a backup. Keep one copy out of reach, and restore from it before you need to.*

A backup you have never restored is a hope. NIST's guide asks you to test backups; CIS makes it safeguard 11.5 (a sample, at least quarterly) and places it in IG2, but it is the cheapest insurance on this list:

1. Restore a sample (a shared folder, a mailbox, the accounting database) from the isolated copy to a separate location, never over the live data.
2. Open the files and check that they are complete and current; NIST also asks you to confirm backed-up data is intact before any real restore.
3. Time the restore, so the incident plan can say how long recovery takes.
4. Record the date and the result, and fix what failed before the next test.

Include cloud services in scope: Microsoft 365 or Google Workspace mailboxes and files, and any software that holds your records.

## Authenticate your email domain with SPF, DKIM and DMARC

Without email authentication, anyone can send mail that claims to come from your domain, to your customers and to your own staff. Three DNS records fix that. SPF lists the servers allowed to send for your domain. DKIM signs each message with a key published in DNS. DMARC ties them to the address people actually see: a message passes only if SPF or DKIM passes for the same domain as its From: header, and the DMARC record tells receiving servers what to do with mail that fails and where to send reports ([Google](https://support.google.com/mail/answer/81126)).

![Two emails reach a receiving mail server. The one from the real sender carries a seal and passes a check against DNS records; the one from an impostor server is stopped by an orange shield.](https://computese.com/images/blog/cybersecurity-best-practices/dmarc.2afbd5c7a3-1536.webp)

*DMARC turns SPF and DKIM into an instruction: mail that claims your domain and fails the checks goes to spam or is refused.*

Mail providers now expect it. Gmail requires every sender to use SPF or DKIM, and since February 1, 2024 has required senders of more than 5,000 messages a day to Gmail accounts to add DMARC. Canada's baseline asks for DMARC on all email services and for email filtering; CIS places DMARC in IG2.

Roll it out in this order, following [Google's recommended DMARC rollout](https://knowledge.workspace.google.com/admin/security/recommended-dmarc-rollout):

1. List every service that sends mail as your domain: your mailbox provider, newsletter tool, invoicing system, website forms, CRM.
2. Set up SPF and DKIM for each, and let them run for at least 48 hours.
3. Publish a DMARC record that only monitors, as a TXT record at `_dmarc.example.com` ([Google: set up DMARC](https://knowledge.workspace.google.com/admin/security/set-up-dmarc)):

   ```text
   v=DMARC1; p=none; rua=mailto:dmarc@example.com
   ```

4. Read the reports daily for at least a week, and fix any legitimate sender that fails.
5. Move to `p=quarantine` for a small share of mail, raise it to all of it, then consider `p=reject`.

Our [security scanning](https://computese.com/services/security-testing/) service checks DMARC, SPF and DKIM from the outside, along with MTA-STS, DNSSEC and registrar lock.

## Train staff to spot phishing and report it

Eight of the nine training safeguards in CIS Control 14 are in IG1: recognizing social engineering (phishing, business email compromise, pretexting, tailgating), authentication habits, handling sensitive data, avoiding accidental exposure, spotting missing updates, the risks of insecure networks, and recognizing and reporting an incident. IG1 also asks for a written process that tells staff how, to whom and how quickly to report. NIST's guide adds a check on how often, and how well, training actually happens.

Payment fraud deserves its own rule. The FBI's [Internet Crime Report 2025](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf) records 24,768 business email compromise complaints and $3,046,598,558 in reported losses for 2025. The defence costs nothing: any change to a supplier's or employee's bank details is confirmed by phone, on a number you already had, before money moves.

> [!TIP]
> Make reporting faster than ignoring: one address for "this looks wrong", thanks for every report, and no blame for the person who clicked. The minutes after a click matter more than the click.

Staff who run the company's social media accounts face their own scams and takeovers; see [how to use social media safely](https://computese.com/how-to-use-social-media-safely/).

## Control vendor and remote access

Suppliers with access to your systems carry your risk. IG1 asks for a list of service providers with a contact for each; policies and contract clauses come at IG2. NIST's guide asks you to assess a supplier's risk before signing. Canada's baseline adds, for cloud and outsourced IT: ask cloud providers for a SOC 3 report, and decide whether you are comfortable with how a provider handles your data and where it is stored. Cyber Essentials counts accounts used by your support providers as yours to control.

Remote access is where vendors and attackers meet. IG1 requires MFA for remote network access, and Canada's baseline asks for a VPN with two-factor authentication for all of it. In a January 2023 advisory, [CISA described criminals using legitimate remote monitoring and management (RMM) tools](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a), ScreenConnect and AnyDesk, delivered by phishing and run as portable programs that need no admin rights. Its mitigations fit a small business: audit which remote tools are in use, allow only the approved one, and use it only over approved remote access such as a VPN.

So every vendor gets a named account with MFA, access ends when the job ends, and there is one approved remote-support tool; our own IT support access follows the same rule. If an agency or developer builds your website or app, ask how they handle [secure coding](https://computese.com/best-practices-for-secure-coding/): Canada's baseline asks websites to meet OWASP ASVS Level 1.

## Switch on the logs you will need

Logs rarely stop an attack, but without them nobody can say what happened, which accounts were used or what data left. IG1 asks you to decide what to log, turn logging on across your systems and keep enough storage; reviewing logs weekly is an IG2 safeguard.

Check the basics, because some are off by default. Microsoft states that [audit logging is not enabled by default for Microsoft 365 Business Basic, Business Standard and Business Premium](https://learn.microsoft.com/en-us/purview/audit-log-enable-disable); once it is on, records are kept for 180 days. In Exchange Online PowerShell, this returns `True` when auditing is on:

```powershell
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled
```

Also keep anti-malware or EDR alerts, firewall and VPN logs, and backup job results. NIST lists the signs worth noticing: lost access to data or services, an unusually slow network, anti-malware alerts, many failed sign-ins, bounced emails with suspicious content and unusual network traffic. If nobody can watch for them, its guide suggests engaging a service provider to monitor for you.

## Write an incident response plan that says who to call

Canada's baseline makes this control number one: the first hour of an incident is the worst time to look up phone numbers. The baselines agree on what the plan needs:

- **A lead and a backup.** CIS asks for one key person and at least one backup; if a provider does the technical work, someone inside the business still oversees it.
- **Who to call**, with numbers, responsibilities and authority, checked once a year.
- **What must be reported, to whom and by when**, under your laws, regulations and contracts.
- **A recovery order**, from the business impact assessment CISA recommends, so you know which systems come back first.
- **A paper copy**, which the Cyber Centre asks for, because the plan may be needed when the network is down.

| Call                        | Why                                                           |
| --------------------------- | ------------------------------------------------------------- |
| Your IT provider or IT lead | Contain the attack, preserve evidence, restore from backup    |
| Your cyber insurer          | Learn what the policy requires you to do, and by when         |
| Your bank                   | Stop or recall fraudulent payments                            |
| Your lawyer or privacy lead | Decide whether regulators or affected people must be notified |
| Police and national agency  | Report the crime and get guidance                             |

National reporting points:

- **United States:** CISA's [Incident Reporting System](https://www.cisa.gov/report), and the FBI's [IC3](https://www.ic3.gov/) for cybercrime such as business email compromise and ransomware.
- **Canada:** the Cyber Centre's [incident reporting form](https://www.cyber.gc.ca/en/incident-management); local police or the RCMP when the incident is criminal or threatens life.
- **United Kingdom:** the NCSC's [incident reporting service](https://report.ncsc.gov.uk/), monitored around the clock. It does not meet any legal reporting duty, and it asks you to report from a device that is not compromised.

A flood of traffic that takes your website offline is an incident too; the guide to [DDoS attacks](https://computese.com/understanding-ddos-attacks-how-they-work/) includes a response runbook for a small business.

> [!IMPORTANT]
> CISA says to test the plan often. Once a year, walk through a real scenario around a table: ransomware on the file server, or a supplier's "new bank details" email that someone paid. It finds the wrong phone numbers while that is still cheap.

If you would rather hand the baseline to someone, our [IT support](https://computese.com/services/it-support/) service uses CIS Controls IG1 as the baseline for the small teams it supports, and starts with an assessment that inventories devices, accounts and licences, shows who has admin access and ranks the gaps in MFA, patching, backups and mail. Our [security scanning](https://computese.com/services/security-testing/) service adds the outside view: what is online, what is exposed and what to fix first.

## Key terms
- **CIS Controls IG1**: Implementation Group 1 of the CIS Critical Security Controls: the 56 safeguards that the Center for Internet Security defines as essential cyber hygiene for every organization.
- **NIST CSF 2.0**: Version 2.0 of NIST's Cybersecurity Framework, released in February 2024. It sorts security outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover.
- **Cyber Essentials (UK)**: The UK government's minimum standard and certification scheme, built on five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.
- **Multi-factor authentication (MFA)**: Signing in with something more than a password, such as a code from an app, a push prompt, a passkey or a hardware security key.
- **Phishing-resistant MFA**: MFA that a fake sign-in page cannot capture and replay. FIDO2 security keys and passkeys (WebAuthn) and PKI smart cards qualify; codes and plain push prompts do not.
- **Least privilege**: Giving each account only the access its job needs, with administrator rights kept in separate accounts that are used for administration and nothing else.
- **SPF, DKIM and DMARC**: Email authentication published in DNS: SPF lists the servers allowed to send for your domain, DKIM signs each message, and DMARC tells receivers what to do with mail that fails and sends you reports.
- **Isolated backup**: A copy of your recovery data that an attacker on your network cannot reach or change, such as an offline drive, an off-site service or versioned cloud storage.
- **Business email compromise (BEC)**: Fraud in which a criminal poses as a supplier, customer or executive by email, usually to redirect a payment to their own bank account.
- **Incident response plan**: A short written plan that names who leads during a security incident, who they call and what must be reported, kept where it can be read when systems are down.

## Common questions

### What are the most important cybersecurity best practices for a small business?

Multi-factor authentication on every account, automatic updates, anti-malware on every device, automated backups with an isolated copy, and email domain authentication. Around them sit an inventory of what you have, separate admin accounts, staff training and a written incident plan. Every major baseline for small organizations includes all of these.

### Should a small business follow CIS Controls, NIST CSF or Cyber Essentials?

Use them together. CIS Controls IG1 is the most specific to-do list, NIST CSF 2.0 is the structure for owning and explaining the program, and the UK's Cyber Essentials is the one to certify against if UK customers ask for proof. They overlap far more than they differ.

### Is Cyber Essentials certification worth it?

If you sell to UK organizations, often yes: the NCSC notes that a growing number require suppliers to be certified. Basic certification starts at £320 plus VAT, priced by organization size, and Cyber Essentials Plus adds independent technical testing. Outside the UK, its five controls are still a sound checklist.

### How often should a small business test its backups?

Restore a sample at least once a quarter, which is the rhythm CIS sets in safeguard 11.5, and after any change to the backup system. NIST's small business guide also asks you to check that backed-up data is intact before you restore from it.

### Does a small business need 24/7 security monitoring?

Not to meet the baseline. IG1 asks you to collect and keep audit logs; regular log review starts at IG2. If nobody can watch alerts, NIST's small business guide suggests engaging a service provider to monitor computers and networks for you.

### Does a small business need cyber insurance?

Consider it. Canada's baseline controls ask organizations to consider a policy that covers incident response and recovery, or to record why they chose not to, and NIST's small business guide lists assessing insurance as a governance task. Read what the policy requires you to do, and by when, after an incident.

## Sources
1. [CIS Critical Security Controls Implementation Group 1](https://www.cisecurity.org/controls/implementation-groups/ig1), Center for Internet Security
2. [CIS Controls Navigator v8.1](https://www.cisecurity.org/controls/cis-controls-navigator), Center for Internet Security
3. [NIST Releases Version 2.0 of Landmark Cybersecurity Framework](https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework), NIST
4. [NIST Cybersecurity Framework 2.0: Small Business Quick-Start Guide (SP 1300)](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1300.pdf), NIST
5. [Cyber Essentials](https://www.cisa.gov/resources-tools/resources/cyber-essentials), CISA
6. [Cyber Essentials](https://www.ncsc.gov.uk/cyberessentials/overview), National Cyber Security Centre (UK)
7. [Cyber Essentials: Requirements for IT Infrastructure v3.3](https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf), National Cyber Security Centre (UK)
8. [Baseline cyber security controls for small and medium organizations](https://www.cyber.gc.ca/en/guidance/baseline-cyber-security-controls-small-and-medium-organizations), Canadian Centre for Cyber Security
9. [Implementing Phishing-Resistant MFA](https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf), CISA
10. [How Passkeys Work](https://www.passkeycentral.org/introduction-to-passkeys/how-passkeys-work), FIDO Alliance (Passkey Central)
11. [Windows LAPS overview](https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview), Microsoft Learn
12. [Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog), CISA
13. [Windows 10 support has ended on October 14, 2025](https://support.microsoft.com/en-us/windows/deployment/updates-lifecycle/windows-10-support-has-ended-on-october-14-2025), Microsoft Support
14. [What is Microsoft Defender for Business?](https://learn.microsoft.com/en-us/defender-business/mdb-overview), Microsoft Learn
15. [Email sender guidelines](https://support.google.com/mail/answer/81126), Google (Gmail Help)
16. [Set up DMARC](https://knowledge.workspace.google.com/admin/security/set-up-dmarc), Google Workspace Help
17. [Recommended DMARC rollout](https://knowledge.workspace.google.com/admin/security/recommended-dmarc-rollout), Google Workspace Help
18. [Internet Crime Report 2025](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf), FBI Internet Crime Complaint Center (IC3)
19. [Protecting Against Malicious Use of Remote Monitoring and Management Software (AA23-025A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a), CISA
20. [Turn auditing on or off](https://learn.microsoft.com/en-us/purview/audit-log-enable-disable), Microsoft Learn
21. [Incident Reporting System](https://www.cisa.gov/report), CISA
22. [Internet Crime Complaint Center (IC3)](https://www.ic3.gov/), FBI
23. [Report a cyber incident](https://www.cyber.gc.ca/en/incident-management), Canadian Centre for Cyber Security
24. [Report a Cyber Incident](https://report.ncsc.gov.uk/), National Cyber Security Centre (UK)
