← All insights

Cornerstone security guide

The Six Security Decisions That Keep a Small Business Defensible

A practical governance guide for owners who need cybersecurity decisions to become visible, repeatable, and useful—not just another stack of tools.

Central Florida small-business team reviewing six security decisions beside network equipment in a commercial print workshop.

Why security decisions matter

Small businesses rarely fail because the owner refused to buy any security technology. More often, the problem is that important decisions were never made clearly. Nobody knows which accounts are most important, whether backups can be restored, who can approve a payment change, or what should happen when a suspicious login appears.

A defensible business does not need perfect security. It needs a small set of decisions that are documented, assigned, tested, and revisited. CISA’s small-business guidance emphasizes multifactor authentication, software updates, backups, phishing resistance, logging, and encryption. NIST’s current small-business work similarly frames cybersecurity as a risk-management activity rather than a one-time technology purchase.

The following six decisions give an owner or office manager a practical foundation.

1. Decide which accounts require the strongest protection

Start with email, administrator accounts, banking access, payroll, customer-management systems, file storage, and remote-access tools. These accounts can unlock other systems or redirect money and information.

CISA recommends requiring MFA wherever possible and moving toward phishing-resistant methods such as security keys or passkeys. Text-message codes are better than no MFA, but CISA identifies them as weaker than authenticator apps and phishing-resistant methods.

  • List every system that can approve money movement, reset passwords, access sensitive files, or administer technology.
  • Require MFA for those systems first.
  • Separate administrator accounts from everyday work accounts where practical.
  • Review who has administrator access every quarter.

Confirmed: MFA reduces the chance that a stolen password alone will provide access. Uncertain: MFA does not prove that every sign-in is legitimate, and weaker MFA methods can still be attacked through social engineering.

2. Decide what data must be recoverable

A backup is not the same as a recovery capability. Owners should decide which information the business must recover first, how quickly it is needed, and who is authorized to approve restoration.

Critical data may include accounting records, active customer files, scheduling information, contracts, payroll records, inventory data, and system configurations. A cloud application may retain copies, but that does not automatically guarantee recovery from deletion, ransomware, account compromise, or a provider outage.

  • Identify the five most important business processes.
  • Name the systems and data each process depends on.
  • Define a realistic recovery order.
  • Test a restore instead of only checking that a backup job completed.
  • Keep at least one backup protected from ordinary administrative access.

CISA recommends backing up critical data and system configurations and maintaining restoration procedures. The practical owner question is simple: “Can we demonstrate that the most important work can resume?”

3. Decide who can approve sensitive changes

A fraudulent request often looks like a normal business request: change a vendor’s bank account, add an urgent wire, disclose a file, or create a new administrator. The control is not merely technical. It is a decision rule.

Create a written requirement that payment changes, new vendors, unusual data requests, and privileged-access changes receive independent verification. Verification should use a known phone number or a separate trusted channel—not the contact information in the request.

  • Assign a primary approver and a backup.
  • Require two-person confirmation for payment-account changes.
  • Prohibit approval based only on email or text.
  • Record who verified the request, when, and how.

This is especially important for small offices where one person may handle accounting, purchasing, and email administration.

4. Decide how software and vulnerabilities are managed

Software updates are a business process. Someone must know which devices, applications, routers, remote-access tools, and cloud services exist and who is responsible for updating them.

  • Maintain a basic asset list.
  • Identify unsupported or end-of-life products.
  • Enable automatic updates where appropriate.
  • Prioritize internet-facing systems, identity platforms, remote access, and known exploited vulnerabilities.
  • Ask technology providers how urgent security updates are communicated and applied.

CISA’s Known Exploited Vulnerabilities catalog is a prioritization aid, not a complete inventory. A product absent from the catalog is not automatically safe.

5. Decide what happens during an incident

An incident plan should answer operational questions before stress takes over. Who can declare an incident? Who contacts the IT provider? Who talks to the bank, insurer, attorney, customers, or law enforcement? Who preserves evidence?

Keep a printed or offline contact sheet containing:

  • Technology provider and after-hours contact.
  • Domain, email, banking, payroll, and insurance contacts.
  • Primary and backup decision-makers.
  • Local law-enforcement contact information.
  • Instructions for isolating a device without destroying evidence.
  • The location of offline or separately protected recovery information.

Do not assume that every incident requires the same response. A lost laptop, compromised mailbox, ransomware event, and fraudulent payment may involve different containment and reporting steps.

6. Decide what evidence proves the work happened

Security becomes easier to manage when the business keeps a small evidence file. It does not need to be elaborate. Useful records include MFA coverage, access reviews, backup test results, security-training completion, software-update exceptions, incident exercises, vendor contacts, and policy approvals.

Evidence should show:

  • What was reviewed.
  • When it was reviewed.
  • Who performed the review.
  • What problem was found.
  • What owner and due date were assigned.
  • Whether the issue was resolved or accepted as a documented risk.

This record can help with customer questions, insurance applications, regulatory inquiries, and internal decision-making. It also prevents the same uncertainty from returning every few months.

A monthly management rhythm

Owners can turn these decisions into a 30-minute monthly meeting:

  • Review new accounts, vendors, and privileged access.
  • Check backup and restore evidence.
  • Discuss unresolved software or security issues.
  • Confirm incident contacts.
  • Record one improvement for the next month.

The goal is not to claim that the business is breach-proof. The goal is to make important security choices visible, explainable, and repeatable. That is what makes a small business more defensible when technology fails, staff changes, or a suspicious request arrives.

Human-reviewed draft. Validate technical settings and legal obligations with the organization’s IT, legal, insurance, and compliance advisers.

Sources