← All insights

Cornerstone security guide

The Six-Part Security Operating Plan for a Central Florida Small Business

A practical way for owners and office managers to organize cybersecurity around governance, assets, access, monitoring, response, and recovery.

A Central Florida office manager reviewing a simple cybersecurity planning board with a technology adviser

Why a security operating plan matters

Cybersecurity becomes difficult when it is treated as a collection of disconnected purchases. A business may have antivirus software, cloud email, backups, and an insurance policy but still lack a clear answer to basic questions: Which systems are essential? Who can approve access? How will the office operate if email is unavailable? Who decides whether an incident is serious enough to report?

The NIST Cybersecurity Framework 2.0 gives small businesses a useful structure through six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is voluntary and flexible, not a certification requirement. Its value is that it gives an owner and an IT provider a shared vocabulary for deciding what matters first.

1. Govern: assign ownership

Cybersecurity should have a business owner, even when technical work is outsourced. The owner does not need to configure systems, but should approve priorities, risk tolerance, spending, and response decisions.

Create a one-page responsibility record that identifies:

  • The executive who can declare a security incident.
  • The person who can approve emergency spending.
  • The technology provider or internal administrator.
  • The attorney, insurer, or breach-response contact.
  • The person who communicates with employees and customers.
  • The backup decision-maker for each role.

Keep this record outside the normal email system so it remains available during an outage.

2. Identify: know what the office depends on

Make a plain-language inventory of systems and information. Include Microsoft 365, accounting, payroll, customer or patient-management systems, file shares, websites, payment platforms, remote-access tools, internet equipment, printers, cameras, and vendor portals.

For each item, record:

  • Business purpose.
  • Data stored or processed.
  • Owner and vendor.
  • Administrator accounts.
  • Backup or recovery method.
  • Maximum acceptable downtime.
  • Contractual or regulatory obligations.

Do not assume that a cloud service is automatically backed up in the way your business needs. Confirm retention, restoration options, administrator controls, and who performs recovery.

3. Protect: reduce the easiest paths in

Start with controls that apply broadly:

  • Require multi-factor authentication for email, remote access, administrator accounts, financial systems, and vendor portals.
  • Use unique passwords stored in a reputable password manager.
  • Remove access promptly when employees, contractors, or vendors leave.
  • Apply operating-system, browser, application, and firmware updates on a defined schedule.
  • Encrypt laptops and mobile devices that contain business information.
  • Separate guest Wi-Fi from business systems.
  • Limit administrator rights on ordinary workstations.
  • Train staff to report suspicious messages without fear of punishment.

CISA and the FTC both emphasize MFA, patching, backups, access control, and employee awareness as foundational measures for small businesses.

4. Detect: make unusual activity visible

A small office may not need a large security operations center, but it does need a way to notice important events. Turn on available audit logging for Microsoft 365, endpoint protection, remote-access tools, and backup systems. Decide who reviews alerts and how quickly.

Useful signals include:

  • A new administrator account.
  • A sign-in from an unexpected location or device.
  • Repeated failed logins.
  • Mass file deletion or renaming.
  • Disabled security software.
  • A backup job that fails or suddenly changes.
  • A vendor requesting unusual access.

Document what is normal for the office. Without that baseline, every alert becomes either a crisis or an ignored warning.

5. Respond: prepare decisions before pressure arrives

Write a short incident plan. It should tell employees what to do if they suspect a compromise: stop using the affected device, disconnect it when appropriate, call the designated contact, and avoid deleting evidence. It should also identify who contacts the IT provider, insurer, legal counsel, law enforcement, and affected parties.

Plan for the possibility that email and chat are unavailable. Keep current phone numbers, an alternate communication method, and printed or offline copies of critical procedures.

6. Recover: define what “back in business” means

Recovery is more than restoring files. Identify the order in which operations must return. For an office, that may mean internet access, identity administration, phones, scheduling, accounting, line-of-business applications, shared files, and customer communications.

Set recovery time and recovery point objectives in business language. Then test them. A successful backup job does not prove that the business can restore a working environment under pressure.

What is confirmed and what remains uncertain

Confirmed: NIST provides a current small-business starting point, and federal guidance consistently recommends MFA, updates, access control, backups, training, and response planning. Uncertain: no outside framework can determine your office’s acceptable downtime, legal obligations, or priority systems without business-specific information.

Review this plan quarterly and after major changes. The goal is not perfect security. It is a managed, visible, and recoverable level of risk.

Sources

The NIST CSF 2.0 Small Business Quick-Start Guide: https://www.nist.gov/itl/smallbusinesscyber/nist-cybersecurity-framework-0

FTC Cybersecurity for Small Business: https://www.ftc.gov/business-guidance/small-businesses/cybersecurity

CISA Small and Medium Businesses: https://www.cisa.gov/audiences/small-and-medium-businesses

Sources