Cybersecurity checklist for small businesses
Cybercriminals target even the smallest businesses. Learn the practical steps your business can take to help reduce risk, protect cash flow and improve cybersecurity readiness.
Key takeaways
- No business is too small to be a cybercrime target.
- Top threats include payment fraud, ransomware and account takeover.
- Regular cybersecurity reviews can help identify and address vulnerabilities.
- Multifactor authentication (MFA), phishing training, data backups and an incident response plan are essential defenses.
When it comes to cybersecurity threats, no business is immune. Cybercriminals may target large businesses due to the larger potential financial payoff. But small businesses are often easier to compromise, as they may have fewer cybersecurity resources and controls in place.
“Small businesses may have the mindset that they are too small to be a target for cybercrime, but the reality is that they need to be just as vigilant about guarding against these threats as larger enterprises,” said Jeff Taylor, head of commercial fraud forensics at Regions Bank. “Cybersecurity threats directly impact cash flow, customer trust and business continuity and these are often the biggest concerns for small business owners.”
Top cybersecurity concerns for small businesses
The types of threats that small businesses face fall primarily into three categories:
- Payment fraud and business email compromise (BEC) scams
- Ransomware and data extortion disrupting operations
- Credential theft leading to account compromise
To address each of these, there are concrete steps that business owners can take, which they can identify by doing a regular cybersecurity checkup.
Small business cybersecurity confidence checklist
“Businesses should frequently review the steps outlined in this small business cybersecurity confidence checklist and determine if each item has been completed, needs improvement or has not been implemented,” said Taylor. “The tally of results will help identify the areas where there may be elevated risk to address.”
1. Secure account access and passwords
- Require strong, unique passwords for all business accounts.
- Enable multifactor authentication (MFA) on email, banking, accounting, payroll and cloud applications. Include biometric authentication when possible and include phishing-resistant authentication factors like passkeys.
- Remove access immediately when an employee leaves the company.
- Limit administrator privileges to employees who truly need them.
- Use a password manager for secure password storage.
- Rotate passwords on a regular cadence.
2. Protect email channels and prevent phishing attacks
- Train employees to recognize phishing emails and suspicious links.
- Encourage heightened scrutiny for any payment account changes or requests to authorize transactions.
- Require employees to report suspicious emails immediately.
- Implement email filtering and spam protection tools.
3. Secure and maintain systems, devices and software
- Enable automatic updates on operating systems and business applications.
- Apply security patches promptly.
- Use reputable antivirus/endpoint protection software.
- Replace or decommission unsupported software and hardware.
- Establish and update an inventory of business devices and software.
- Keep Wi-Fi secure with tactics like hiding network name and blocking unapproved personal devices.
4. Protect sensitive data and strengthen backup procedures
- Back up critical business applications and data regularly.
- Store backups separately from production systems.
- Test backup restoration procedures periodically.
- Encrypt sensitive customer and company data.
- Apply principle of least privilege to business assets.
- Filter email with tactics like using security gateways to block phishing attempts, spam and malicious attachments.
5. Safeguard payments and banking transactions
- Use Positive Pay for check processing and payroll.
- Establish a threshold limit on transactions.
- Segregate payment initiation and approval duties.
- Review bank accounts and payment activity daily.
- Verify any changes to vendor banking instructions through a known phone number. STOP – CALL – CONFIRM.
- Verify wire transfers, ACH changes and vendor payment requests through a secondary channel.
- Establish procedures for validating requests involving money movement including segregation of duties.
6. Build cybersecurity awareness across your workforce
- Conduct cybersecurity awareness training at least annually.
- Train employees on ransomware, phishing and business email compromise risks.
- Provide guidance for secure remote work and mobile device usage.
- Encourage employees to report suspicious activity without fear of blame.
7. Manage third-party and vendor cybersecurity risks
- Assess cybersecurity practices of key vendors and service providers through contract reviews.
- Restrict third-party access to only necessary systems.
- Maintain a list of vendors with access to company data.
- Raise vendor portal authentication requirements when they store sensitive company data.
8. Prepare for and respond to cyber incidents
- Maintain a documented cyber incident response plan.
- Identify internal and external contacts to call during a cyber incident.
- Define procedures for ransomware, data breaches and payment fraud.
- Test the response plan periodically.
- Review lessons learned after any security incident.
The basics of cybersecurity defense
While the list of considerations is lengthy, it’s based on four essential questions, according to Taylor.
“Fundamentally, businesses need to be asking if their critical systems are protected by multifactor authentication, if their employees are trained to recognize phishing attempts, if they can restore operations from recent backups, and if they have a documented response plan,” said Taylor. “If the answer to any of these is ‘no,’ that area should become a priority for improvement.”
Ready to help
Learn more about evaluating security measures, staying informed about emerging risks, and adapting controls at regions.com/fraudprevention.
Frequently asked questions
Yes. Small businesses are often targeted because they may have fewer cybersecurity resources and controls in place.
The most significant threats include payment fraud and business email compromise (BEC), ransomware attacks, and credential theft that can lead to account takeover.
A regular cybersecurity review is a good practice for identifying vulnerabilities, tracking improvements, and addressing areas of elevated risk.