Security starts with business decisions
Cybersecurity becomes manageable when an owner or office manager connects it to ordinary business outcomes. The question is not whether a company has every security product. The question is whether the business can make and demonstrate six decisions: what matters, who should access it, how threats will be noticed, what happens during an incident, how operations will recover, and who is accountable.
This approach is consistent with the NIST Cybersecurity Framework 2.0, which organizes cybersecurity risk management around Govern, Identify, Protect, Detect, Respond, and Recover. NIST describes the framework as usable by organizations of any size, sector, or maturity, including small businesses with modest or no formal cybersecurity plan.
1. Govern the risk
Someone must own cybersecurity decisions. In a smaller office, that person may be the owner, operations manager, controller, or practice administrator rather than a full-time security leader.
Write down:
- Which systems are essential to revenue, patient care, client service, payroll, scheduling, or legal obligations.
- Which information is sensitive, such as tax records, health information, financial data, credentials, or confidential client files.
- Who approves new software, remote access, vendors, and exceptions to security procedures.
- How quickly important risks must be addressed.
This does not need to become a large policy binder. A one-page decision record is more useful than a policy no one follows.
2. Identify what exists
Many small businesses cannot answer basic questions about their technology environment. Start with an inventory of users, computers, phones, servers, cloud services, network equipment, business applications, backup systems, and vendors with access.
Include technology that is easy to overlook:
- Personal devices used for work.
- Shared mailboxes and generic accounts.
- Former employee accounts.
- Remote-support tools.
- Online payment, payroll, and accounting services.
- Microsoft 365, Google Workspace, line-of-business applications, and file-sharing platforms.
For each important system, record its owner, administrator, data stored, authentication method, backup arrangement, and recovery contact. Mark uncertain items clearly. An uncertain inventory entry is still better than an invisible dependency.
3. Protect the pathways into the business
Protection should concentrate on the routes attackers commonly use: identities, email, remote access, unpatched software, and exposed services.
Practical baseline actions include:
- Require multifactor authentication for email, financial, administrative, remote-access, and backup accounts.
- Prefer phishing-resistant methods such as passkeys or hardware security keys where the platform supports them.
- Remove administrator privileges from ordinary user accounts.
- Apply operating-system, browser, application, and network-device updates on a defined schedule.
- Use separate administrator accounts for administrative work.
- Encrypt laptops and mobile devices where available.
- Configure email authentication and filtering with a qualified technology provider.
- Train staff to verify unusual payment, password, and access requests through a second channel.
CISA’s Cybersecurity Performance Goals are designed as a prioritized starting point for small and medium-sized organizations. They are voluntary, but they provide a useful way to compare a security plan against high-impact practices.
4. Detect changes early
A business cannot respond to activity it never sees. Detection does not necessarily require a large security operations center. It does require useful signals and a person who reviews them.
Confirm that someone receives alerts for:
- Suspicious Microsoft 365 sign-ins.
- New administrator accounts.
- Disabled security controls.
- Large or unusual file transfers.
- Endpoint malware detections.
- Backup failures.
- New forwarding rules or mailbox delegates.
- Remote-access activity outside normal patterns.
Ask the provider to explain what is monitored, what creates an alert, who receives it, and how quickly it is reviewed. “Monitoring included” is not specific enough to make a management decision.
5. Respond without improvising
An incident plan should tell staff what to do before the situation becomes confusing. Keep it short and operational.
Include:
- Who declares an incident.
- Who can disconnect a device or disable an account.
- Which technology and cybersecurity contacts should be called.
- Who communicates with employees, customers, insurers, regulators, and legal counsel.
- How evidence will be preserved.
- Which payment or wire-transfer instructions require independent verification.
- When to contact law enforcement or report a suspected crime.
The plan should cover account compromise, ransomware, lost equipment, fraudulent payments, and suspicious vendor access—not only a network outage.
6. Recover the business, not just the files
Recovery means restoring the services the business needs to operate. Identify the order in which systems should return: identity and communications, scheduling, financial systems, file access, specialized applications, and less critical services.
CISA recommends offline, encrypted backups and regular testing of their availability and integrity. A backup that cannot be restored, or that depends on a compromised administrator account, is not a dependable recovery capability.
Test one realistic scenario at a time. For example, ask whether the office could continue if email were unavailable for one business day, the file server were encrypted, or the administrator account were compromised. Record the time needed to restore, the data that was missing, and the decisions that were unclear.
What is confirmed and what remains uncertain
Confirmed: NIST CSF 2.0 provides a voluntary structure for managing cybersecurity risk, and CISA provides prioritized practices intended to reduce common risks. These resources do not certify a business, guarantee protection, or replace legal and regulatory advice.
Uncertain: The right technology, staffing model, insurance requirement, and recovery time will vary by business size, industry, contracts, and dependencies. An accountant, medical office, law firm, contractor, or property-management company may need different safeguards even if each has ten employees.
A practical first month
- Week one: inventory users, systems, vendors, and critical data.
- Week two: secure administrator and financial accounts with strong MFA.
- Week three: verify patching, endpoint protection, and backup status.
- Week four: run a short incident and recovery exercise.
The goal is not to claim that risk has disappeared. The goal is to make important decisions visible, repeatable, and easier to improve.

