Start with the basics
A useful baseline for one person or a small firm.
This is an awareness checklist, not a compliance standard or a self-implementation guide. It follows the practical themes in current CISA guidance for small and medium-sized businesses: protect accounts, keep software current, use backups, and help people recognize suspicious messages.
Each item is something a business owner should be able to ask about, understand, and have someone responsible for managing.
A domain name the business owns and can access
Registration, renewal contact, and recovery details should remain visible to the business. This helps make ownership clear when a website, email, or vendor arrangement changes.
Hosted business email
A business email service such as Microsoft 365 gives the organization a distinct work identity and a practical place to manage accounts, access, and email settings. It is one part of the broader cloud and identity foundation.
MFA for important accounts
Email, file storage, remote access, and administrator accounts deserve an extra verification step beyond a password. The strongest practical option depends on the account and the business environment.
Supported, updated, protected devices
Devices should be able to receive security updates, and the organization should know who keeps operating systems, business software, and endpoint anti-malware protection current.
Resilient backups of the work that matters
The business should know what is backed up, where a recovery copy lives, and who is responsible for checking it. A backup is most useful when the business can retrieve the information it needs after a disruption.
A business-grade firewall
Network equipment should be appropriate for the business rather than relying only on ISP-supplied equipment. A business-grade firewall gives the organization a clearer starting point for managing the network it depends on.
Sensible password and access practices
Individual accounts, no shared credentials, timely access removal, and a password manager are practical topics for the owner and provider to review together.
A simple inventory of devices, accounts, and ownership
A basic list of laptops, phones, software services, key accounts, and responsible people makes it easier to see what needs updates, access review, or follow-up.
A shared phishing-awareness and reporting practice
People should know how to pause on a suspicious message, use a known contact method to verify a request, and report it internally. A short shared practice is more useful than asking people to guess alone.
