← All insights

Cornerstone security guide

A Risk-Based Security Plan for the Seven Decisions Every Small Business Must Make

A practical security foundation for Central Florida businesses that need clear priorities, accountable owners, and evidence of steady improvement.

Office manager reviewing a simple cybersecurity planning worksheet beside a laptop and printed business process map

Security starts with decisions, not products

Small businesses often begin cybersecurity by purchasing a product: endpoint software, a cloud service, a firewall, or an insurance policy. Those tools can help, but they do not answer the management questions that determine whether the business can operate safely under pressure.

The more useful starting point is a short set of decisions. What information matters most? Who is allowed to access it? Which services would stop the business if unavailable? Who responds when something goes wrong? How will the owner know that controls are working?

NIST Cybersecurity Framework 2.0 organizes cybersecurity around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. The framework is voluntary and flexible, but it gives an office manager a way to turn scattered technology tasks into a business risk program.

Decision one: define what must keep working

Create a one-page list of essential business functions. Include client communication, accounting, scheduling, payment processing, line-of-business applications, file access, and any specialized systems used by the office.

For each function, record:

  • The application or service used.
  • The person responsible for it.
  • The data it handles.
  • The maximum tolerable outage.
  • The vendor or third party the business depends on.

This is not a perfect inventory. It is a usable first approximation. Review it quarterly and whenever the business adopts a new system.

Decision two: identify sensitive information

Do not treat every file as equally important. Separate information into practical groups such as public, internal, confidential, and highly restricted. Client records, financial information, credentials, employee data, contracts, and regulated information generally deserve stronger handling than ordinary marketing material.

The classification should affect access, storage, sharing, retention, and deletion. If staff members cannot explain why a document is sensitive, the categories are probably too complicated.

Decision three: make identity the control point

Require individual accounts wherever possible. Shared accounts make it difficult to determine who performed an action and make timely offboarding harder.

Enable multifactor authentication for email, remote access, administrative accounts, cloud storage, financial systems, and any service containing sensitive information. CISA recommends starting with administrators and users who handle important data, while using the strongest available authentication method.

Maintain a short access register showing:

  • User name and job role.
  • Systems accessed.
  • Administrative privileges.
  • Date of most recent review.
  • Date access should be removed if employment ends.

Decision four: decide who may approve change

A small office still needs separation of duties. The person who requests a new user, approves access, and verifies the completed change should not automatically be the same person for every system.

Where staffing makes full separation unrealistic, use compensating controls. For example, require monthly owner review of administrative changes, retain vendor tickets, and require written approval before adding privileged access.

Decision five: define the minimum protective baseline

Your baseline should be short enough to inspect. It may include supported operating systems, automatic updates, endpoint protection, MFA, encrypted laptops, secure configuration of Microsoft 365, tested backups, and a documented process for handling suspicious messages.

Do not call a control complete because a product is licensed. Confirm that it is enabled, configured, monitored, and tested.

Decision six: decide how the business detects trouble

Detection does not require a security operations center. It does require visibility. Determine which systems produce useful alerts and who reviews them.

At minimum, monitor for:

  • Suspicious sign-ins.
  • New administrator accounts.
  • MFA changes.
  • Unexpected mailbox rules.
  • Malware or endpoint isolation events.
  • Backup failures.
  • Large or unusual data transfers.

Document the alert owner and expected response time. An alert without ownership is only noise.

Decision seven: rehearse response and recovery

Write down what staff should do if an account is compromised, a laptop is lost, data is encrypted, or a vendor becomes unavailable. Include internal contacts, technology providers, legal counsel, insurance contacts, law enforcement options, and customer communication responsibilities.

Test one scenario every quarter. A tabletop exercise can reveal missing phone numbers, unclear authority, and untested restoration procedures without interrupting production.

What is confirmed and what is uncertain

Confirmed: NIST provides a current small-business quick-start guide, and CISA provides practical resources covering MFA, updates, logging, backups, encryption, and incident response.

Uncertain: no generic checklist can determine the correct controls for every Central Florida business. A medical practice, contractor, law firm, and retail office may face different contractual, regulatory, and operational requirements. Treat this guide as a starting structure, not a legal or compliance opinion.

Actions for the next 30 days

  • Name one business owner for cybersecurity decisions.
  • List essential systems and their outage tolerances.
  • Review every administrator account.
  • Turn on MFA for email and remote access.
  • Confirm backups and schedule a restoration test.
  • Create a one-page incident contact sheet.
  • Save evidence of completed work in a security folder.

The goal is not to promise that an incident will never happen. The goal is to make important risks visible, assign ownership, and improve the business’s ability to continue operating when conditions are not normal.

Sources