Why a baseline matters
For a small professional office, cybersecurity often becomes a list of purchases: email protection, antivirus, cloud backup, a password manager, and perhaps an outside IT provider. Those tools may be useful, but ownership becomes difficult when nobody can explain what the business is trying to protect, which risks matter most, or what should happen during an incident.
A better starting point is a short operating baseline. The goal is not to imitate a large enterprise. It is to create enough structure that an owner, office manager, and technology provider can make consistent decisions and produce evidence that the work is being done.
NIST’s Cybersecurity Framework 2.0 is designed for organizations of any size, sector, or maturity. Its small-business quick-start guidance organizes the work into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. The framework is voluntary guidance, not a certification or legal safe harbor.
The six outcomes to manage
Use the following outcomes as a plain-language baseline. Each should have an owner, a current status, and a next action.
- Govern: Decide who accepts cyber risk, who can approve technology changes, and which information requires special handling.
- Identify: Maintain a practical inventory of people, devices, cloud services, important data, vendors, and administrator accounts.
- Protect: Apply safeguards such as multifactor authentication, software updates, access restrictions, secure configurations, and employee training.
- Detect: Know how suspicious sign-ins, malware alerts, payment changes, and unusual mailbox activity will be noticed and escalated.
- Respond: Define the first contacts, containment decisions, evidence-preservation steps, and communications process for an incident.
- Recover: Confirm how the office will restore systems, validate data, resume essential work, and learn from the disruption.
The important point is connection. A backup without a restoration test is not a demonstrated recovery capability. Multifactor authentication without an inventory of privileged accounts leaves gaps. Training without a reporting route may not help when an employee receives a convincing payment-change request.
Start with governance, not software
Governance does not require a board committee. In a small office, it may be a one-page decision record approved by the owner or managing partner.
Record:
- The three business services that must continue during an outage.
- The types of information that would cause the greatest harm if exposed or altered.
- The person who can authorize emergency technical work.
- The outside contacts for IT, cyber insurance, legal counsel, banking, and law enforcement reporting.
- The date of the next review.
This record reduces ambiguity. It also gives a technology provider useful business context instead of asking the provider to choose priorities without knowing what the office considers essential.
Build an inventory that can be checked
The inventory does not need to begin as an elaborate configuration-management database. A spreadsheet can be sufficient if it is accurate and reviewed.
Include:
- Microsoft 365 or other cloud tenants.
- Email, file-sharing, accounting, practice-management, scheduling, and payment systems.
- Laptops, desktops, servers, network equipment, printers, and remote-access tools.
- Administrators, service accounts, shared accounts, and emergency recovery accounts.
- Critical vendors and the data or access each vendor receives.
- Backup locations, retention periods, and the person responsible for testing recovery.
Mark each entry with an owner, business purpose, administrator, last review date, and whether multifactor authentication is enabled. Treat uncertainty as a finding. “Nobody knows who owns this account” is actionable information.
Prioritize identity protection
CISA advises businesses to require multifactor authentication wherever possible, especially for email, remote access, administrative accounts, and systems containing sensitive information. CISA also recommends moving toward phishing-resistant methods. Security keys and passkeys are examples of stronger options; authenticator applications can be an interim improvement, while text-message codes provide weaker protection than stronger methods.
A practical sequence is:
- Secure administrator and financial accounts first.
- Remove former employees and unnecessary accounts.
- Require separate administrator accounts rather than using one account for everyday email and administration.
- Confirm recovery methods are controlled by the business, not by one departing employee.
- Review sign-in alerts and investigate unexpected prompts or repeated failed attempts.
Do not describe MFA as complete merely because a prompt appears during login. Record which systems are covered, which exceptions exist, and when exceptions will be removed.
Make recovery observable
The baseline should include a small recovery exercise. Choose one scenario, such as a locked Microsoft 365 account, unavailable file share, or encrypted workstation.
Ask:
- Who declares the disruption?
- How will staff communicate if email is unavailable?
- Which work can continue manually?
- Where are clean backups or replacement devices located?
- Who verifies that restored data is complete and usable?
- Which customers, regulators, insurers, or authorities may need notification?
The answers may reveal more risk than another product purchase. If nobody can identify the recovery account, locate a backup, or approve a customer communication, the office has a process gap.
What is confirmed and what is uncertain
Confirmed: NIST provides a current CSF 2.0 small-business quick-start resource, and CISA recommends MFA, stronger authentication options, software updates, backups, and employee awareness as practical safeguards.
Uncertain: No generic framework can determine the exact legal, contractual, insurance, or sector requirements for every Central Florida business. A healthcare practice, financial-services office, government contractor, and ordinary commercial firm may face different obligations. Legal and regulatory questions should be reviewed with qualified counsel or the relevant regulator.
A 30-day implementation plan
- Week 1: Name the business owner, technology owner, and incident contacts.
- Week 2: Inventory cloud systems, privileged accounts, devices, vendors, and backups.
- Week 3: Close the highest-risk identity gaps and remove obsolete access.
- Week 4: Run a recovery discussion and document decisions, exceptions, and deadlines.
The result is modest by design: a current inventory, visible decisions, stronger access controls, and a recovery process that has been discussed before pressure arrives. That is a more defensible foundation than buying additional tools without an operating plan.
Sources
- NIST Cybersecurity Framework 2.0 for Small Business: https://www.nist.gov/itl/smallbusinesscyber/nist-cybersecurity-framework-0
- NIST CSF 2.0 Small Business Quick-Start Guide: https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=957322
- CISA Require Multifactor Authentication: https://www.cisa.gov/audiences/small-and-medium-sized-businesses/secure-your-business/require-multifactor-authentication
- CISA Small and Medium-Sized Business Resources: https://www.cisa.gov/small-and-medium-sized-business-resources
Human-reviewed draft. Guidance should be adapted to the office’s systems, contracts, insurance requirements, and applicable law.

