← All insights

Cornerstone security guide

The Defensible Small Business: Build Security Around Six Everyday Outcomes

A practical foundation for Central Florida owners who need cybersecurity decisions that are understandable, documentable, and proportionate to business risk.

Office manager reviewing a simple cybersecurity planning board with service, access, backup, and response notes

Security starts with outcomes

Small businesses do not need a giant security department to become more defensible. They do need a repeatable way to answer six questions: What matters most? Who can access it? How could access be misused? How would the business notice trouble? How would it continue operating? Who makes decisions when something goes wrong?

NIST’s Cybersecurity Framework 2.0 organizes cybersecurity around Govern, Identify, Protect, Detect, Respond, and Recover. CISA’s Cross-Sector Cybersecurity Performance Goals provide a shorter set of voluntary, high-impact practices intended to help small and midsize organizations prioritize. Neither framework is a certification, guarantee, or substitute for legal advice. They are decision structures.

For a Central Florida office, that distinction matters. A roofing contractor, medical practice, title company, engineering firm, and restaurant may use different systems and face different obligations. The foundation should therefore be built around business outcomes rather than a generic list of products.

1. Know the business-critical services

Write down the services that must continue during a bad day. Examples include scheduling patients, accessing client files, processing payroll, accepting payments, dispatching field staff, or communicating with customers.

  • Name the system supporting each service.
  • Identify the owner of the process, not just the person who installed the software.
  • Record the maximum tolerable interruption in plain language.
  • Note dependencies such as internet access, Microsoft 365, phones, vendors, and payment providers.

This list becomes the basis for backup priorities, recovery testing, and incident decisions. Without it, an office may restore a server while overlooking the cloud account, application license, or administrator needed to make the service usable.

2. Control identity before buying more tools

Most small offices should begin with accounts, not appliances. Require multifactor authentication for email, remote access, financial systems, payroll, and administrator accounts. Prefer phishing-resistant methods such as passkeys, FIDO2 security keys, or Windows Hello where practical. CISA identifies phishing-resistant MFA as a priority, while Microsoft recommends phishing-resistant authentication for Entra ID users, especially privileged accounts.

  • Inventory every administrator and shared account.
  • Remove former workers promptly.
  • Separate administrator accounts from ordinary work accounts.
  • Review mailbox forwarding rules and application permissions.
  • Keep at least two controlled emergency administrator accounts and test their recovery process.

SMS-based MFA is better than password-only access, but it is not the long-term target for high-value accounts. A staged migration is more realistic than an overnight change.

3. Reduce preventable exposure

Patch internet-facing systems, routers, firewalls, remote-access tools, operating systems, browsers, and business applications. Replace unsupported software when it handles sensitive information or provides external access.

  • Turn off unused remote-management services.
  • Restrict administrative interfaces to approved locations or secure access paths.
  • Use endpoint protection and ensure alerts reach someone who will act.
  • Encrypt laptops and mobile devices that store business data.
  • Establish a process for urgent vendor security advisories.

A patching policy is only useful if it identifies who checks for updates, who approves exceptions, and when overdue items are escalated.

4. Make recovery measurable

A backup is not proof of recovery. CISA recommends offline, encrypted backups and regular testing of availability and integrity. Test a representative file, a complete workstation, and the systems needed for the most important business service.

Record:

  • What was restored.
  • How long it took.
  • Which credentials were required.
  • Whether the restored data was complete and usable.
  • What failed and who owns the correction.

Keep backup administration separate from ordinary user accounts where possible. Ransomware operators frequently seek accessible backups after obtaining an initial foothold.

5. Decide how the office will detect and respond

A small office may not have a 24-hour security operations center. It still needs a monitored path for important alerts and a written response sequence.

The first page should answer:

  • Who can declare an incident?
  • Who disconnects a suspected device?
  • Who contacts the IT provider, insurer, attorney, and affected vendors?
  • Who communicates with employees and customers?
  • When should the FBI, CISA, or another regulator be contacted?

Do not improvise evidence handling. Preserve emails, alerts, logs, ransom notes, and relevant system images before resetting devices or deleting accounts.

6. Govern the work with evidence

Assign an owner and review date to each major control. Keep evidence in a restrained, useful format: an access review export, backup-test record, patch exception list, incident exercise note, and current vendor contact sheet.

The goal is not to create paperwork for its own sake. Evidence shows whether a control operated and reveals where the business is relying on assumption. It also helps explain security decisions to an insurer, client, auditor, attorney, or management team.

What is confirmed and what remains uncertain

Confirmed: NIST and CISA provide voluntary frameworks and goals that small businesses can use to prioritize risk reduction. Confirmed: MFA, secure configuration, tested backups, and incident planning address common attack paths. Uncertain: no framework can predict the exact attack a particular Central Florida business will face, and no vendor can promise that a service will prevent every incident.

A practical first month

  • Week one: inventory critical services, accounts, and vendors.
  • Week two: enforce MFA and remove stale access.
  • Week three: verify patching, endpoint protection, and backup isolation.
  • Week four: conduct a 30-minute incident exercise and document gaps.

A defensible program is not defined by how sophisticated it looks. It is defined by whether the owner can explain the important decisions, verify that they operate, and improve them when conditions change.

Sources:

  • https://www.nist.gov/cyberframework
  • https://www.cisa.gov/cybersecurity-performance-goals
  • https://www.cisa.gov/stopransomware/ransomware-guide
  • https://learn.microsoft.com/en-us/azure/active-directory/authentication/overview-authentication

Sources