All Posts

The Small Business Security Baseline: Six Controls, and How to Check Each One

Security advice aimed at small businesses tends to arrive as a list of twenty things, none of them ranked, most of them expensive. That is not useful when you have a business to run.

Here is the shorter version: six controls, in the order they actually matter, and a way to check each one yourself.

1. Multi-factor authentication on email, first

If you do one thing, do this. The overwhelming majority of small business compromises we see start with someone getting into a mailbox — not with malware, not with a firewall exploit. A password alone is one leaked credential away from being someone else's.

How to check: in Microsoft 365, open the admin centre and look at which users have MFA enforced. The number that matters is not “most.” It is “all,” including the owner, who is usually the exception someone made years ago and forgot.

2. Email authentication, so nobody can send mail as you

This is the control almost nobody has and almost everybody needs. Without an enforced DMARC policy, anyone can send email that appears to come from your domain — to your clients, your suppliers, your own staff — with no access to your systems whatsoever.

Depending on the sample, somewhere between two thirds and four fifths of domains have no effective DMARC protection. Large enterprises have largely closed this gap; small businesses have not.

How to check: run dig +short TXT _dmarc.yourdomain.com, or use our free domain exposure report. If you get nothing back, or a record saying p=none, you are not protected. We wrote up the full check and the staged fix separately.

3. Behavioural endpoint protection, not just antivirus

Signature-based antivirus compares files against a list of known threats. It cannot, structurally, catch something written last week, which is why ransomware kits now generate a fresh variant per target.

EDR watches behaviour instead — a process encrypting files in sequence, something reading stored credentials — and can isolate the machine from the network mid-attack. That containment window is the difference between an afternoon of work and a closed business.

How to check: ask whoever manages your IT two questions. Can a machine be isolated from the network remotely, and who gets called when a detection fires at 2am? If the answer to the second is “a ticket is created,” you have detection without response. The longer explanation is here.

4. Patching, measured rather than assumed

Unpatched software remains one of the most reliable ways into a network, and nearly every provider will tell you they handle patching. Far fewer can tell you what percentage of your machines are currently up to date.

How to check: ask for the compliance number. Not “is patching enabled” — the percentage of your fleet that is current, this month. If nobody can produce it, patching is running on hope.

The machine that cannot be patched deserves an honest answer rather than silence. Older workstations running imaging or line-of-business software often cannot be updated because the vendor never certified a newer operating system. That machine needs network isolation and behavioural monitoring, not an exemption.

5. Named accounts, so the logs mean something

Shared logins are the most common shortcut in a small office and the most expensive one. When every log entry shows the same username, you permanently lose the ability to answer “who did that?” — and you cannot disable a departing employee's access without disrupting everyone still there.

How to check: count your shared accounts. Then ask whether you could prove who changed a specific record last Tuesday. More on fixing this without slowing anyone down.

6. Backups you have actually restored

Everyone has backups. Far fewer have restored one recently, and an untested backup is a belief rather than a control. The common failure modes are dull and fatal: the backup drive sits next to the server, so a fire or a ransomware infection takes both; or the job has been silently failing for months and nobody reads the emails.

How to check: restore something. Pick one file from three months ago and ask for it back. How long that takes, and whether it works at all, is your real recovery capability.

What about security awareness training?

Worth doing, and worth being realistic about. Training reduces how often people click, it does not reduce it to zero, and a security posture that depends on nobody ever making a mistake is not a posture. Train the team and build controls that survive somebody having a bad Tuesday.

Where to start

If all six are missing, do them in the order above. One and two are cheap and fast; three, four and six are what a managed plan is for; five is mostly configuration and patience.

We bundle patching, monitoring, EDR and identity threat detection into Endpoint Protection at $32 per device per month, and one-off cleanup work comes out of prepaid support hours. If you would rather see what we would find before spending anything, the external security assessment is free.

Want this handled for you?

Fix It Mobile manages endpoints, patching, and threat detection for South Florida businesses — and sells prepaid support hours when you just need a hand.