← All insights

Cornerstone security guide

The Owner’s Cybersecurity Baseline: Six Controls That Make a Small Business Defensible

A practical starting point for Central Florida owners who need a defensible cybersecurity program without building an enterprise security department.

Office manager reviewing a clear cybersecurity planning board with system categories and action dates

Why a baseline matters

Cybersecurity becomes manageable when an owner can describe the business’s most important systems, the people who can access them, and the actions that will occur if something goes wrong. A small business does not need every security product. It needs a repeatable baseline that reduces common failure points and produces evidence of responsible management.

NIST Cybersecurity Framework 2.0 is designed for organizations of every size and now includes six functions: Govern, Identify, Protect, Detect, Respond, and Recover. The framework is guidance rather than a legal certification or guarantee. It helps an organization connect technical work to business priorities.

For a Central Florida office, that may include Microsoft 365, payroll, accounting, customer records, payment systems, phones, cloud applications, internet-connected equipment, and physical documents.

Six decisions to make first

  • **Name the business-critical services.** List the systems required to open, communicate, bill, serve customers, pay employees, and meet contractual obligations. Include dependencies such as internet service, identity providers, hosted applications, and outside IT support.
  • **Assign ownership.** Every important system should have a business owner, a technical administrator, and a backup contact. Avoid arrangements in which one employee is the only person who knows how to recover an account.
  • **Require strong sign-in protection.** Multifactor authentication should protect email, administrator accounts, remote access, financial systems, payroll, and backup consoles. Prefer phishing-resistant methods where practical, such as passkeys or security keys.
  • **Control administrator access.** Use separate administrative accounts, limit the number of administrators, review access regularly, and remove access promptly when someone changes roles or leaves.
  • **Keep recoverable backups.** Back up business data and configurations, protect backup administration separately, and test restoration. A backup that has never been restored is an assumption, not proven recovery capability.
  • **Prepare for detection and response.** Decide who receives security alerts, who can disable accounts, who contacts the IT provider, who communicates with customers, and when legal, insurance, law-enforcement, or regulatory partners are engaged.

What owners should document

The baseline should produce a short operating file, not a collection of slogans. Keep an asset list, an access review, a backup report, a vendor list, an incident contact sheet, and a record of significant decisions. Record dates, responsible people, exceptions, and follow-up deadlines.

This evidence is useful even when no regulator or insurer asks for it. It helps a new manager understand the environment, helps an IT provider work faster, and gives leadership a factual basis for deciding what to fund next.

Central Florida operating realities

Local businesses commonly depend on seasonal staffing, hybrid work, outside accountants, property managers, payment processors, and cloud platforms. Those relationships create access paths that may be overlooked during a routine office move or personnel change. A hurricane, tropical storm, extended power interruption, or building-access problem can also turn a cyber incident into a continuity problem.

The answer is not to predict one specific disaster. It is to identify dependencies and decide how the business will operate if email, files, phones, internet access, or a key vendor is unavailable.

What is confirmed versus uncertain

Confirmed: no control eliminates all cyber risk, and NIST states that organizations should use risk management to prioritize outcomes according to their needs and resources. Confirmed: small businesses can use the NIST Small Business Quick Start Guide without adopting every enterprise practice.

Uncertain: which controls deserve priority for a particular company. That depends on the records held, payment flows, contractual duties, staffing, technology, and tolerance for downtime. A medical office, construction company, law firm, and retail business should not use identical priorities.

A 30-day starting sequence

  • Week one: identify critical systems, owners, administrators, and vendors.
  • Week two: enable or verify multifactor authentication and remove stale access.
  • Week three: review backups, retention, restoration steps, and emergency contacts.
  • Week four: run a short tabletop exercise involving a compromised mailbox or unavailable file system.

Finish by assigning the next review date. A baseline becomes useful when it is revisited after staffing changes, new software, acquisitions, office moves, and material incidents.

This article is a human-reviewed draft and is not a certification, legal opinion, or substitute for professional advice.

Sources