Back to Resources

Cybersecurity Guide

A practical small-business cybersecurity checklist.

Security improves when basic controls are applied consistently. This checklist focuses on the areas that commonly create preventable risk without assuming every business needs the same security stack.

Small-business cybersecurity can become confusing because security products are often presented as the solution. Tools matter, but tools work best when identity, patching, access, backups, devices, and human processes are also under control.

No checklist can guarantee that a business will never experience a security incident.

The objective is to reduce preventable exposure, improve visibility, limit the impact of a compromise, and make recovery more realistic.

Start with the controls that affect the whole environment

1. Protect identities

Require multi-factor authentication where supported, remove unused accounts, avoid shared administrator credentials, and limit administrative access to people who actually need it.

2. Keep systems patched

Maintain supported operating systems and applications and use a repeatable update process. Known vulnerabilities become more dangerous when updates are delayed indefinitely.

3. Protect endpoints

Use business-appropriate endpoint protection and maintain visibility into laptops, desktops, and other managed devices.

4. Back up what matters

Know which data and systems the business must recover, keep appropriate retention, and make sure at least one recovery path is not dependent on the same live environment.

5. Secure email and accounts

Use strong authentication, review forwarding and mailbox rules when suspicious activity occurs, and train employees to verify unusual payment or credential requests.

6. Control remote access

Know which remote-access tools exist, who can use them, and whether old or ad-hoc access methods should be removed.

7. Document onboarding and offboarding

Create and remove access consistently when employees join, change roles, or leave. Old accounts and forgotten privileges create avoidable exposure.

8. Know your critical vendors

Understand which outside providers can access systems or data and how to contact them during an incident.

9. Plan the first hours of an incident

Decide who should be contacted, which systems may need isolation, where clean communication can happen, and how recovery priorities will be determined.

What should a small business review regularly?

A quarterly or scheduled review can catch gradual drift before it becomes a major problem. Useful questions include:

  • Are terminated employees and old vendor accounts disabled?
  • Are administrative accounts still limited and protected with MFA?
  • Are supported devices receiving operating-system and application updates?
  • Are endpoint-security agents installed and healthy on the devices that should have them?
  • Are backups completing, and has the business verified that important data can actually be restored?
  • Have new remote-access tools or unmanaged applications appeared?
  • Are critical business systems still supported by their vendors?
  • Does leadership know who to contact if an employee reports suspicious activity?

Where should a business spend first?

The answer depends on the environment, but foundational controls usually deserve attention before specialized products. If accounts can be taken over easily, patches are months behind, former employees retain access, or backups are unreliable, adding another dashboard does not solve the underlying problem.

Valhalla IT approaches business cybersecurity as part of the operating environment: endpoints, identity, patching, access, backup readiness, and support practices have to work together.

Security should be proportional to the risk

A five-person professional office and a multi-location organization may need different controls, monitoring, and response capabilities. The right security plan considers the information being protected, business impact, regulatory or contractual obligations, available internal capacity, and the realistic threats the organization faces.

Want to review your current security posture?

Start with the gaps that create the most practical risk.

We can look at the environment, identify priority areas, and determine which controls make sense without assuming the answer is another product.

Discuss Cybersecurity