The first security baseline for a small team
Security is a deep field, with hundreds of controls and advice from every direction. For a small business with limited time and no security team, that depth is the problem: the list looks so long that nothing gets started. So this is not the whole programme. It is a triage list — five concrete fixes, in order, that cover the most common ways small businesses actually get broken into. None requires technical skill. Most fit in one afternoon. They are the highest-return few hours of security work you can do.
The order is deliberate. Each fix removes a real amount of risk, ranked by how much it removes and how fast you can finish. If you can only do one, do the first. If you can only do two, do the first two.
Fix 1 — Turn on two-step login for email and finance (today, 30 minutes)
This is the most valuable half-hour you can spend. Your business email is, in practice, the master key to everything else. Password resets, bank confirmations, and admin logins all land there. Anyone who controls your email controls a large share of your business.
Two-step login (a code or tap on your phone, also called Multi-Factor Authentication or MFA) asks for a second proof beyond the password. It is meant to close the most common attack path against email. The automated attacks that fire millions of stolen passwords at business accounts usually stop at the two-step prompt, because the attacker does not have your phone. Today: open your email admin settings (Microsoft 365 Admin Center or Google Workspace Admin Console), find the security section, and set two-step login to required for all users — not optional, not suggested, required. Then do the same for your bank portal and your accounting software, the other two places money moves. Prefer a code app on your phone over text-message codes; texts can be hijacked through a phone-carrier trick called SIM-swapping.
Fix 2 — Audit and remove dormant accounts (this week, 60–90 minutes)
Almost every small business has live accounts that belong to former employees, ex-contractors, and old vendors — never switched off. Each one is a silent door an attacker can walk through if those login details ever leak. Set aside an hour and walk through every service you use. Open the user list. Remove anyone no longer with you. Flag accounts you do not recognise. Downgrade any admin access that does not strictly need to be admin. The rule of thumb: if they left, cut access the same day — and if that did not happen at the time, do it now.
Fix 3 — Adopt a password app (this week, 2–3 hours to set up)
Reused passwords sit behind a large share of small-business break-ins. When a service your team uses is breached, attackers take the leaked logins and try them everywhere else. A breach at one site becomes a breach at your accounting software if the passwords match. A password app (one that remembers them for you) fixes the cause: each account gets a long, random, one-of-a-kind password the app creates and stores, and your team only remembers one master password. Pick one app, get the whole team on it, and let it create a fresh password each time you log into something over the next two weeks. Within a month, most of your important accounts will have strong, unique passwords.
Fix 4 — Build an offboarding checklist (this afternoon, 30 minutes to construct)
Fix 2 is the cleanup. Fix 4 keeps you from needing it again next year. The usual reason ex-employees keep access is not malice — it is the lack of a written process. The work falls to whoever happens to notice, and if nobody notices, it does not happen. A bare-minimum checklist: suspend the email account and route it to the manager for 30–90 days; walk every service and remove access; change any shared passwords the person knew; move key files out of personal accounts; collect company hardware; wipe company data from personal devices. Then give the checklist a named owner who runs it within 24 hours of any departure — "everyone is responsible" means no one is. Do one dry run on a made-up leaver. You will find at least one step that does not work, and you want to find it now.
Fix 5 — Verify your backups are actually recoverable (this week, 2 hours)
The first four fixes lower the chance an attack succeeds. This one lowers the damage if one does. Most small businesses have backups of some kind. Most have never restored from them — never confirmed the login still works, never timed a recovery. A backup you have never restored from is not a backup; it is hope. This week, pick your most critical system (usually email plus financial data), confirm where its backup lives and which login reaches it, and check the one thing that most often fails in a real disaster: whether the backup uses a different login from your main accounts. A backup in the same cloud account, behind the same login, will likely get locked right alongside your data when software locks your files for ransom. Then delete one unimportant file, restore it, and time the whole thing. For most small businesses the right answer is a separate backup service on its own login — ideally one where saved copies cannot be changed or deleted — ask the backup provider whether they offer this; it is sometimes labelled Write-Once-Read-Many storage.
What these five do, and don't, cover
These five cover the attack paths most likely to be used against a small business. They are not a complete programme, and they do not replace a structured look at your own risks. What they do: in one focused afternoon plus a week of follow-through, they move you from several common weak spots to a much smaller set of rarer ones. A fair target is all five done within two weeks. After that, the natural next step is a structured assessment — starting with a list of what you actually have — to surface what else needs attention.
When you want this ready to use
Sylvan Assurance's SMB Security Assessment turns this into a guided programme: setup guides for two-step login and backups, a recovery playbook for a taken-over account, a solo access-management playbook, and a card for spotting scam emails — with the team edition adding a 12-question assessment, step-by-step guides across the four control areas, pre-built Excel workbooks, awareness training decks, and guided practice drills. Editions from $49; the toolkit page has the full breakdown.
The free SMB security readiness assessment at sylvanassurance.com/free/smb-security walks your situation and returns a tailored guide. It runs entirely in your browser; your answers are never sent anywhere.
Prefer the long form? The companion Sylvan Press title, The SMB Security Playbook, covers the same ground in depth.
See where you stand
Want to know where your business actually stands on these basics? The free assessment scores you across identity, data, backups, and patching in about five minutes. It runs entirely in your browser — your answers never leave your device.