Free Small Business Resource

Small Business Cybersecurity Checklist

10 practical things you can check today to make your business a harder target for cybercriminals.

10 Things You Can Check Today

Start with the basics that stop many common attacks.

Cybersecurity does not have to begin with expensive technology. These practical steps can reduce risk to your accounts, computers, employees, customer information, and day-to-day operations.

1

Turn on multi-factor authentication (MFA).

Enable MFA on email, banking, Microsoft 365, social media, accounting, cloud storage, and other important accounts. A stolen password is much less useful when a second verification step is required.

2

Stop reusing passwords.

Use strong, unique passwords for important accounts. A reputable password manager can help employees avoid using the same password across work and personal services.

3

Update computers, phones, and applications.

Install security updates promptly and enable automatic updates where practical. Outdated software can leave known weaknesses open to attack.

4

Back up important business information.

Maintain backups of information you cannot afford to lose, and periodically test that those backups can actually be restored. Keep at least one backup protected from ordinary user access.

5

Teach employees to stop before they click.

Unexpected links, attachments, QR codes, password-reset notices, and urgent requests should be treated cautiously. When in doubt, verify through a separate trusted method.

6

Verify unusual requests involving money.

Independently confirm new bank details, wire transfers, gift-card requests, payroll changes, and unusual invoices. Do not use contact information supplied only in the suspicious message.

7

Do not give unexpected callers remote access.

A caller claiming to be Microsoft, your bank, an internet provider, or “tech support” should not be allowed into a computer simply because the call sounds convincing.

8

Review who has access to your systems.

Remove accounts belonging to former employees and contractors. Give people only the access they need, and avoid using administrator accounts for routine work.

9

Protect business email.

Email is often the doorway to password resets, invoices, customer conversations, and other accounts. Use MFA, watch for unexpected forwarding rules, and verify sensitive requests even when the sender name looks familiar.

10

Have a plan before something happens.

Employees should know who to contact and what to do if they click a suspicious link, disclose a password, send money, lose a device, or notice unusual activity. Fast reporting matters.

Recognize the Warning Signs

Something doesn't look right. What should make you suspicious?

!

Unexpected urgency

“Act now,” “keep this confidential,” “your account will be closed,” or pressure to bypass normal procedures.

$

Money or payment changes

New banking instructions, unusual invoices, gift-card requests, wire transfers, or payroll/direct-deposit changes.

@

Messages that almost look right

A familiar display name with a different email address, a slightly misspelled domain, or a login page reached through an unexpected link.

↗

Unexpected links or attachments

Files, QR codes, shared documents, password resets, or links you were not expecting—even when they appear to come from someone you know.

PC

Unsolicited tech support

A caller or pop-up says your computer is infected and asks you to install software, call a number, or allow remote access.

?

Anything outside the normal process

A request that asks an employee to ignore policy, change a familiar procedure, keep something secret, or move unusually fast deserves verification.

Something Happened—What Do I Do?

Act quickly, but don't panic.

If an employee clicks something suspicious, gives away a password, sends money, or allows remote access, early action can limit the damage.

1

Report it immediately.

Employees should know exactly who inside the organization needs to be told. Do not hide a mistake or wait to see what happens.

2

Disconnect if remote access or malware is suspected.

If someone has taken remote control or suspicious software is running, disconnect the affected computer from the network without erasing evidence.

3

Protect compromised accounts.

From a known-safe device, change exposed passwords, revoke active sessions where available, and enable or reset MFA. Do not reuse the replacement password elsewhere.

4

Contact financial institutions quickly.

If money or banking information is involved, contact the bank or payment provider using a trusted number as soon as possible and explain what occurred.

5

Get qualified help.

Preserve relevant emails, messages, transaction details, timestamps, and other information. Your IT or cybersecurity provider can help determine the appropriate next steps.

Important: Every incident is different. These are general first-response steps, not a substitute for an incident-response plan, legal advice, or professional investigation.
Protect. Prepare. Advance.

You don't have to become a cybersecurity expert.

Your business does need reasonable protections, employees who recognize suspicious activity, and a plan for what happens next. Tivarden Technology Group helps businesses improve cybersecurity awareness, reduce risk, and strengthen everyday security practices.