← All insights

Cornerstone security guide

The First 90 Days of a Small-Business Cybersecurity Program

A practical 90-day plan for Central Florida businesses that need a defensible cybersecurity foundation without building a large internal IT department.

Why a 90-day plan works

Cybersecurity becomes easier to manage when it is treated as an operating process rather than a collection of purchases. A small business does not need to solve every technical problem in one week. It does need to establish ownership, identify the systems that keep the business operating, reduce the most likely access risks, and create evidence that important safeguards are being checked.

The NIST Cybersecurity Framework 2.0 is useful because it organizes the work around Govern, Identify, Protect, Detect, Respond, and Recover. NIST’s small-business guide is designed for organizations with modest or nonexistent cybersecurity programs, but it does not prescribe a single technology stack. The right implementation depends on the company’s size, sector, resources, contractual obligations, and risk tolerance.

For a Central Florida office, that may mean protecting Microsoft 365, accounting software, payroll, payment systems, customer records, building-access systems, laptops, phones, and internet-connected equipment used by employees or vendors.

Days 1–30: establish ownership and visibility

The first month is about knowing what exists and who is responsible for it.

  • Name a business owner for cybersecurity decisions. This may be the owner, office manager, operations leader, or another trusted employee.
  • List critical services: email, file storage, payroll, accounting, scheduling, customer relationship management, payment processing, phone systems, websites, and line-of-business applications.
  • Record each system’s administrator, renewal date, support contact, backup arrangement, and recovery priority.
  • List all people and organizations with access, including employees, former employees, contractors, bookkeepers, vendors, and managed service providers.
  • Confirm that the business controls its domain, registrar account, DNS records, cloud subscriptions, and administrator accounts.
  • Identify systems that cannot be unavailable for more than a few hours and those that can wait until the next business day.

Do not assume that a vendor manages everything simply because a service is cloud-hosted. A provider may secure the underlying platform while the business remains responsible for users, permissions, configurations, data retention, and recovery decisions.

Days 31–60: reduce common attack paths

The second month focuses on controls that generally provide broad risk reduction.

  • Turn on phishing-resistant or app-based multifactor authentication for administrators and all users where supported.
  • Remove inactive accounts and immediately disable accounts belonging to separated workers.
  • Replace shared administrator credentials with individually assigned accounts.
  • Apply operating-system, browser, application, firewall, and network-device updates.
  • Enable automatic updates for supported devices and document exceptions.
  • Use standard user accounts for daily work rather than local administrator accounts.
  • Configure endpoint protection and confirm that alerts reach someone who will act on them.
  • Review remote-access tools and remove those that are no longer needed.
  • Protect backups with separate credentials and prevent ordinary users from deleting or altering them.
  • Train employees to verify payment changes, urgent wire instructions, password-reset requests, and unexpected document-sharing notices through a second channel.

CISA’s small and medium business guidance emphasizes practical steps such as multifactor authentication, software updates, incident planning, and phishing awareness. These measures do not eliminate risk, but they can make common intrusion paths harder to use.

Days 61–90: create response and recovery discipline

A security program becomes operational when people know what to do during an incident.

Create a short incident plan that answers:

  • Who declares a suspected incident?
  • Who contacts the technology provider, cyber-insurance carrier, bank, attorney, and law enforcement?
  • Which systems should be disconnected, and who has authority to do that?
  • How will employees communicate if email is unavailable?
  • Which business functions must continue manually?
  • What evidence must be preserved?
  • When should customers, regulators, or partners be notified?

Then test the plan with a tabletop exercise. Pick a realistic scenario such as a compromised mailbox, fraudulent payment request, lost laptop, or ransomware affecting shared files. The objective is not to perform perfectly. It is to expose unclear responsibilities before a real event.

Test recovery as well. A backup is not confirmed merely because a dashboard says “successful.” Restore a representative file, verify that the restored data is usable, and document how long the process takes. If the company depends on a vendor to restore a service, ask what the vendor’s recovery process actually includes.

What is confirmed and what remains uncertain

Confirmed: NIST provides a current small-business starting point, and CISA provides practical guidance for smaller organizations. Confirmed: no framework guarantees prevention of every incident. Uncertain: the specific controls your business needs until its systems, data, contracts, and regulations are reviewed.

A 90-day plan is therefore a beginning, not a certification. At the end of the period, management should have a prioritized risk list, assigned owners, documented exceptions, tested recovery steps, and a schedule for recurring reviews.

A useful management habit

Schedule one monthly security meeting lasting 30 to 45 minutes. Review open risks, account changes, backup tests, critical updates, vendor issues, incidents, and upcoming technology changes. Keep meeting notes and evidence in one controlled location.

Small businesses do not need a complicated program to become more resilient. They need clear ownership, repeatable checks, and decisions that are recorded before an urgent event forces them to improvise.

Sources