← All insights

Cornerstone security guide

The Small-Office Security Baseline: Six Questions Every Owner Should Be Able to Answer

A practical starting point for Central Florida owners who need to understand their cybersecurity posture without building a large security department.

Central Florida manufacturing leaders reviewing six operational security checkpoints

Why a baseline matters

Many Central Florida offices do not need a large security department to make meaningful progress. They do need a shared understanding of what is protected, who can access it, how the business would respond to an incident, and which decisions remain unresolved.

The National Institute of Standards and Technology’s Cybersecurity Framework 2.0 is designed for organizations of different sizes, sectors, and levels of maturity. Its small-business quick-start guidance is intended for businesses with modest or no cybersecurity plans. The framework is not a product list or a certification program. It is a way to organize risk-management conversations around Govern, Identify, Protect, Detect, Respond, and Recover.

Source: https://csrc.nist.gov/pubs/sp/1300/final

For a small professional office, the goal is not to document every technical setting. The goal is to answer six operating questions clearly enough that an owner, office manager, IT provider, and outside advisor would make consistent decisions.

1. What information and systems matter most?

Start with business impact rather than technology names. List the systems that support revenue, client service, patient care, payroll, billing, scheduling, and regulatory obligations.

  • Identify the email platform, file storage, accounting system, practice-management system, payment tools, website, phones, and line-of-business applications.
  • Identify where sensitive information is stored, including client records, patient information, employee data, tax records, bank details, and contracts.
  • Note which systems are operated by the office and which are hosted by vendors.
  • Record the business owner for each system, not only the technical administrator.

This inventory does not need to be perfect on day one. A useful first version is better than an undocumented assumption. Update it when the office adopts a new application, changes providers, or ends a contract.

2. Who can access those systems?

Access should follow job responsibility. Every account should have a named user or a documented administrative purpose. Shared credentials make it difficult to determine who acted, and they create problems when an employee leaves.

  • Review administrator accounts first.
  • Remove former employees and unused accounts promptly.
  • Confirm that contractors and vendors have only the access they need.
  • Use separate administrative accounts where the platform supports them.
  • Require multifactor authentication for email, remote access, financial systems, and privileged accounts.

CISA advises small and medium-sized businesses to require MFA wherever possible and to prefer phishing-resistant methods when available. Security keys and other phishing-resistant options generally provide stronger protection than text-message codes. If stronger methods cannot yet be deployed, use the strongest available option and document the transition plan.

Source: https://www.cisa.gov/audiences/small-and-medium-sized-businesses/secure-your-business/require-multifactor-authentication

3. What happens when normal access fails?

An office should know how it will continue if email, cloud files, a server, or a key vendor becomes unavailable. This is a continuity question, not merely a backup question.

  • List the people who can declare an operational disruption.
  • Record alternate contact methods for staff, vendors, banks, insurers, and legal counsel.
  • Identify the minimum services required to operate for one business day, one week, and one month.
  • Confirm how urgent payments, appointments, payroll, and client communications would be handled.
  • Keep a printed or offline copy of essential contacts and recovery instructions.

A backup is useful only if the business can restore the needed information within an acceptable time. Ask the provider to demonstrate recovery, not simply confirm that a backup job completed.

4. How will the office detect suspicious activity?

Detection does not require a security operations center. It requires clear signals and a person responsible for reviewing them.

Examples include unexpected MFA prompts, new mailbox forwarding rules, unfamiliar administrator accounts, password-reset notices, unusual payment requests, antivirus alerts, and missing files. Decide which alerts require immediate action and which can wait for routine review.

The office should also make it easy for employees to report mistakes. A worker who clicked a suspicious link or approved an unexpected MFA prompt needs a fast reporting route, not fear of punishment. Early reporting may allow the office to revoke sessions, change credentials, contact the bank, or preserve evidence before the situation worsens.

5. Who makes decisions during an incident?

Write down the first calls. A useful incident contact list may include the owner, office manager, IT provider, cyber-insurance carrier, attorney, bank, law enforcement contact, and affected technology vendors.

Do not assume the person who manages technology should decide every business or legal question. The owner may need to decide whether to close operations, notify customers, approve emergency spending, or use manual processes. The attorney may advise on notification duties. The bank may have a time-sensitive role in attempting to recall fraudulent funds.

If a payment fraud or business email compromise occurs, the FBI advises contacting the financial institution immediately and reporting the incident to the Internet Crime Complaint Center.

Source: https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise

Source: https://www.ic3.gov/CrimeInfo/BEC

6. What evidence proves the office is doing the work?

A defensible program produces modest, useful records. Keep dated evidence of access reviews, backup tests, software updates, employee training, vendor reviews, incident exercises, and unresolved risks.

The record does not need to be elaborate. For each action, capture the date, responsible person, result, and next step. If the office accepts a risk temporarily, record why, who approved it, and when it will be reconsidered.

What is confirmed and what remains uncertain?

Confirmed: NIST provides a small-business framework for organizing cybersecurity risk management, and CISA recommends MFA with a preference for phishing-resistant methods. These are authoritative starting points, not guarantees of protection.

Uncertain: No generic checklist can determine whether an office satisfies a specific contract, insurance condition, licensing rule, or privacy obligation. Healthcare, financial, legal, defense, and government suppliers may face additional requirements.

The practical objective is simple: make the six answers visible, assign owners, and revisit them monthly. A small office becomes more resilient when cybersecurity is treated as a routine operating responsibility rather than a once-a-year technology project.

Sources