Small Business Cybersecurity Checklist for 2026
This checklist is for freelancers, solopreneurs and small teams with no security department. Quick answer: secure your email first, use a password manager, turn on multi-factor authentication (MFA) everywhere and use passkeys where offered, keep software updated, learn to spot phishing, and keep tested backups following the 3-2-1 rule. Most small-business attacks exploit basics, not sophisticated tricks.
Quick checklist
| Area | Do this | Effort |
|---|---|---|
| Accounts | Password manager plus unique passwords; MFA on all important accounts | 1 to 2 hours |
| Sign-in | Passkeys or hardware security keys for email, cloud and finance | 30 minutes |
| Devices | Automatic updates, disk encryption, screen lock | 30 minutes per device |
| Phishing | Verify requests through a second channel; report and delete suspicious messages | Ongoing habit |
| Backups | 3-2-1 backups with one offline or immutable copy; test a restore | 1 hour setup |
| Response | One-page plan: who to call, what to disconnect, how to restore | 30 minutes |
1. Lock down email and key accounts first
Your email account is the master key: password resets for almost everything else flow through it. List your critical accounts: email, domain registrar, website host, cloud storage, banking and payment processors, social and ad accounts, accounting software. Protect these before anything else. Remove old employees, contractors and unused apps from them, and check that recovery phone numbers and addresses are current.
2. Use a password manager and unique passwords
Reusing passwords means one leaked site can unlock your others. A password manager generates and stores long unique passwords so you only remember one strong master passphrase. CISA's Secure Our World guidance recommends long, random, unique passwords and a password manager. Pick a reputable product with a clear security track record, protect the vault with MFA and keep an emergency recovery method stored safely. For teams, choose a manager with shared vaults so credentials are not passed around in chat.
- Use a long passphrase for the manager itself.
- Do not store the recovery key in the same vault.
- Change any password you suspect has been exposed, using a breach checker such as Have I Been Pwned.
3. Turn on MFA, and prefer phishing-resistant methods
MFA adds a second proof of identity, so a stolen password alone is not enough. CISA lists text or email codes, authenticator apps and biometrics as common methods. Not all are equal.
Strength of common MFA methods
- Strongest: passkeys and hardware security keys (FIDO2). They are bound to the real website, so a fake login page cannot capture them.
- Good: authenticator apps with one-time codes, or push approvals with number matching.
- Better than nothing: SMS codes. They can be intercepted through SIM swapping or tricked out of you, so move off them where you can.
Prioritise MFA on email, finance, cloud admin and your password manager.
4. Adopt passkeys where they are available
A passkey is a cryptographic credential stored on your device or in a password manager and unlocked with your fingerprint, face or device PIN. The FIDO Alliance, which develops the standard, describes passkeys as a phishing-resistant replacement for passwords. Major services such as Google, Microsoft and Apple accounts support them; check each service's settings for the current options.
Practical tips
- Register passkeys on at least two devices or in a manager that syncs, so losing one phone does not lock you out.
- Keep a recovery option for each account and know how it works.
- For accounts that do not support passkeys, keep a unique password plus app-based MFA.
- Consider two hardware security keys (one spare, stored safely) for the most critical accounts.
5. Spot phishing and fraud requests
Phishing remains a leading way in. Messages create urgency: unpaid invoice, account locked, a boss asking for gift cards, a supplier changing bank details. AI tools can now produce polished, error-free messages, so bad grammar is no longer a reliable sign.
Habits that work
- Do not click links in unexpected messages; open the site yourself or use a saved bookmark.
- Verify any payment or bank-detail change by calling a known number, not one in the message.
- Check the sender's real address and the link's true destination by hovering.
- Be wary of unexpected attachments and QR codes.
- Agree a rule with your team: no urgent payment without a second confirmation.
- Passkeys help here because they will not work on a lookalike site.
If you clicked or entered details, change the password from a clean device, revoke active sessions, check mailbox forwarding rules and tell anyone affected.
6. Keep everything updated
Attackers routinely exploit known flaws in software that was never patched. Turn on automatic updates for your operating system, browser, router firmware, apps, plugins and your website's CMS. Replace devices and software that no longer receive security updates; for example, Microsoft ended regular support for Windows 10 in October 2025, so check whether any of your PCs still depend on it and consult Microsoft's current guidance on extended security updates or upgrading. Also encrypt laptops (BitLocker on Windows, FileVault on macOS) and use a screen lock.
7. Back up with the 3-2-1 rule and prepare for ransomware
The 3-2-1 rule is a long-standing guideline: keep 3 copies of your data, on 2 different types of storage, with 1 copy offsite. Many security agencies now add that at least one copy should be offline or immutable, so ransomware cannot encrypt or delete it.
A simple 3-2-1 setup for a small team
- Copy 1: your working files on your computer or cloud workspace.
- Copy 2: an external drive or NAS you connect only when backing up, or disconnect afterwards.
- Copy 3: an encrypted cloud backup service with versioning, ideally with immutable or delayed-delete options.
Automate it, then test a restore at least twice a year. A backup you have never restored is a hope, not a plan. Remember that syncing tools like shared drives are not backups: deleted or encrypted files can sync too unless version history is on.
Ransomware basics
Ransomware encrypts your files and demands payment, often after stealing a copy of the data. Common entry points are phishing, stolen credentials, exposed remote-access services and unpatched systems. Your defenses are the ones above: MFA, updates, least-privilege access and offline backups. If you are hit, disconnect affected devices from the network, do not wipe evidence blindly, contact your IT help, insurer or an incident-response professional, and report it to your national authority. In the US that includes CISA and the FBI's IC3. Law enforcement generally advises against paying, since payment does not guarantee recovery.
8. Write a one-page response plan
- Who you call first (IT contact, bank, insurer).
- Where the password manager emergency access and backups are.
- How to disconnect a device and revoke access.
- Who talks to customers if their data is involved, and what laws on breach notification apply to you.
Common mistakes and what to check
- Protecting social accounts but not the domain registrar or email.
- Sharing one login among the whole team.
- Relying only on SMS codes for critical accounts.
- Keeping the only backup on a drive that is always plugged in.
- Never removing access when a contractor leaves.
- Using personal and work browsers and profiles on the same login.
- Ignoring update prompts for months.
Review the checklist every quarter. Official starting points: CISA's Secure Our World and small-business resources, and your national cyber agency if you are outside the US. Using cloud services? See our cloud computing guide for small business for the shared-responsibility basics.
FAQ
Are passkeys better than passwords plus MFA?
For most people, yes, because passkeys resist phishing and are simpler to use. Keep a recovery plan and use app-based MFA where passkeys are not offered.
Is a password manager safe to use?
Reputable managers encrypt your vault so the provider cannot read it, and they are generally safer than reuse or notebooks. Protect it with a strong master passphrase and MFA.
Is SMS MFA still worth using?
Yes if it is the only option, since it blocks many automated attacks. Use an authenticator app, passkey or security key when available.
Does cloud storage count as a backup?
Not by itself. Sync can spread deletions and ransomware. Use a backup service with version history, or add an offline copy.
Should I pay a ransom?
Authorities generally advise against it. Payment does not guarantee data return and can encourage further attacks. Restore from backups and seek professional help.
Last reviewed: October 2026.