If your business has fewer than 500 employees, you’re operating with cybersecurity resources that rival a Fortune 500 company’s security team from 2010—except the threats have evolved exponentially.
Small and mid-size businesses (SMBs) now face the same attack surface as enterprises, but often with a fraction of the dedicated security staff. The FBI reported that ransomware attacks against SMBs increased 93% between 2022 and 2024, and the average cost of a data breach for a company under 1,000 employees reached $2.75 million in 2025. You don’t need a 40-person security operations center to protect your business, but you do need a structured approach.
Here’s a practical checklist to secure your organization before a breach becomes inevitable.
Start with Multi-Factor Authentication Everywhere
Single-password authentication is dead for businesses that want to stay operational. Employees losing laptops or reusing passwords across work and personal accounts remains the leading entry point for attackers. Multi-factor authentication (MFA) stops 99.9% of automated breach attempts, according to Microsoft security data.
Your implementation plan:
- Deploy MFA on all email accounts first—email is the master key to your entire business.
- Add MFA to any cloud service that stores company data: Salesforce, Slack, Google Workspace, Microsoft 365, QuickBooks, whatever your stack includes.
- Require MFA for remote access tools like VPNs or remote desktop software.
- Set a firm policy: no exceptions. A single unprotected account becomes the breach vector.
Start this week. It takes 30 minutes per employee to set up, and most cloud services now default to MFA enrollment.
Patch Your Systems on a Fixed Schedule
Unpatched software is the second-largest entry point for attackers. Microsoft releases patches every second Tuesday of the month. Apple, Adobe, and all major vendors do the same. You don’t need a sophisticated patch management system—you need a calendar reminder and a process.
Set this in stone:
- Apply Windows patches within two weeks of release. Test on one device first if you can, but don’t delay by months.
- Update all third-party software monthly: browsers, PDF readers, Java, Flash (if it somehow still exists in your environment), antivirus software itself.
- Configure automatic updates for devices that allow it. Windows has built-in Group Policy options; Mac and Linux have equivalent tools.
- Track which devices are running which versions. A simple spreadsheet beats no inventory at all.
Cybersecurity vulnerabilities in unpatched systems are actively exploited within 30 days of public disclosure. Waiting six months to update is inviting a ransomware incident.
Back Up Your Data on a Separate System
Ransomware succeeds because attackers know you’ll pay to recover your files. Backups are your only true defense against total business shutdown. A proper backup strategy means your data exists somewhere disconnected from your network, so attackers can’t encrypt it alongside your live systems.
Your backup checklist:
- Run daily incremental backups and weekly full backups—most backup software handles this automatically.
- Store at least one backup copy offline or air-gapped from your network. This prevents ransomware from spreading to your backup.
- Test your backups quarterly by actually restoring a sample of files. Backups that have never been tested are just hope.
- Document which systems are backed up and which are not. Marketing’s shared drive matters less than your customer database, but both should be covered.
One small business we worked with learned this the hard way: they had backups, but stored them on the same network drive as their active files. When ransomware hit, both the live data and the backup encrypted. Three weeks of downtime and a $180,000 recovery bill followed.
Educate Employees About Phishing and Social Engineering
Your employees are not obstacles to security—they’re your first line of defense or your biggest vulnerability, depending on training. Phishing emails cause 36% of data breaches in SMBs. The attack is usually crude: a fake invoice request, a fake password reset, a fabricated urgent message from leadership.
Build a foundation:
- Send a phishing simulation email to your staff quarterly. Use a legitimate service—Knowbe4, Gophish, or your IT vendor’s built-in tools. Track who clicks malicious links and who opens attachments.
- Do not punish employees for failing simulations. Instead, send them a 5-minute training video immediately.
- Teach your team to verify unusual requests. A CEO asking for an urgent wire transfer should be verified by phone, not email.
- Make it safe to report phishing. If an employee reports a suspicious email, they should get a thank-you, not an investigation.
Employees who receive quarterly training are 65% less likely to fall for phishing attacks than those who receive none.
Document Your Security Responsibilities
Finally, assign clear ownership. Who applies patches? Who manages backups? Who handles breach response? If the answer to any of these questions is “whoever remembers,” you have a security problem waiting to happen.
Create a one-page security responsibility matrix:
- Assign an owner for each critical system or process.
- Set a calendar reminder for recurring tasks (MFA audits, backup tests, patch cycles).
- Document your incident response plan: if a data breach happens tomorrow, who do you call and in what order?
This checklist is not theoretical—it’s what most businesses should have done years ago. If you’re implementing it now, you’re ahead of 60% of SMBs. If you’re unsure where to start, begin with MFA and backups this month.
Have a cybersecurity story or lesson from your own business? LinkedIn Daily accepts guest post submissions from practitioners in this space.