Small businesses are now the #1 target for ransomware because they're big enough to pay and small enough not to have a security team. The good news: 95% of real-world attacks are stopped by the basics. Here is our full one-hour checklist — no jargon, no fear-selling.
Part 1: Accounts (15 minutes)
- Turn on 2FA for every email, cloud and admin account. This alone blocks 99% of automated attacks.
- Remove ex-employees and inactive accounts from every SaaS you pay for. Audit quarterly.
- Give every person their own login. Never share credentials — you can't audit or revoke a shared account.
- Use a company password manager (Bitwarden, 1Password Business, or Dashlane).
Part 2: Email (15 minutes)
- Enable Advanced Threat Protection in Microsoft 365 (Defender) or Google Workspace (Advanced Protection).
- Set SPF, DKIM and DMARC on your domain — stops attackers spoofing your business name.
- Turn on a strict 'external sender' warning banner. Cheapest, best anti-phishing training there is.
- Set up mail archiving / journaling if you're in a regulated industry.
Part 3: Devices (15 minutes)
- Enable full-disk encryption everywhere: BitLocker (Windows) or FileVault (Mac). A stolen laptop with encryption on is a nuisance; without, it's a breach.
- Enforce screen lock after 5 minutes.
- Turn on automatic OS and browser updates.
- Run one real-time antivirus per device (Windows Defender is fine).
Part 4: Backups (10 minutes)
- Cloud-first: OneDrive/Google Drive for daily files, IDrive/Backblaze Business for machine images.
- Immutable snapshots — pick a provider that keeps 30 days of versions you can restore from.
- Test one restore per quarter. A backup you've never restored is a hope, not a backup.
Part 5: People (5 minutes)
One 15-minute phishing awareness session a year cuts click-rate by around 70%. We include one with every Fleet Maintenance Plan. Also: publish a simple 'if in doubt, forward it to IT' rule so your team never feels stupid asking.
For regulated industries
If you handle payment cards (PCI), health data (HIPAA), or EU citizen data (GDPR), the above is the floor, not the ceiling. Add endpoint detection (Defender for Business, SentinelOne), a written incident-response plan and an annual penetration test.
Want us to run this checklist for you? Our $299 remote SMB security audit covers all of the above with a written report and prioritised fix list. Optional monthly Fleet Maintenance keeps everything current.
Related service
Antivirus Installation, Consultation & Removal · $69 flat
Honest advice on the right antivirus for you — plus clean install, configuration and safe removal of unwanted security software.
Book this service
