Skip to main content
Guide

Cybersecurity for Small Business: Where to Start (2026)

Small-business cybersecurity comes down to three layers: access protection (strong passwords, MFA, updates), data protection (3-2-1 backups, encryption), and fraud protection (SPF/DKIM/DMARC, payment verification). Most small practices need 2-3 weeks and well under $5,000 to reach a sensible level of defense - this guide shows the order that works.

1. Who gets targeted, and why

Most owners of small practices believe they are too small for anyone to bother with. The data says the opposite.

The FBI’s IC3 2025 Annual Report logged 1,008,597 complaints and $20.9 billion in reported losses - up 26% in a year - dominated by phishing, fraud, and extortion. The Verizon Data Breach Investigations Report 2026 found ransomware present in 48% of confirmed breaches, and where the victim’s size was known, 96% were small and medium businesses. Small is not a shield; small is the default victim profile.

Three reasons drive this:

First - automation. Attacking a small business requires no human decision. Bots sweep the entire address space every few hours looking for open RDP ports, unpatched website software, and leaked passwords. If your mail server or website is visible online, you are in the queue.

Second - asymmetry. Encrypting one workstation in a dental office is enough to stop patient scheduling for a week. The ransom is rarely the real cost: downtime, recovery, breach notification, and reputation damage routinely run to several times the demand, according to Sophos’s State of Ransomware research.

Third - trusted connections. Small firms connect to bigger ones - payroll providers, banks, corporate clients. That makes them an ideal bridge to a larger target, and supply-chain incidents like SolarWinds (2020) and MOVEit (2023) showed attackers walking in through exactly that smaller, weaker link.

The most-targeted small-business sectors are the ones that hold sensitive data and depend on systems being up every day: healthcare practices (dental, med spa), accounting and tax firms, retail, and law offices. Our own external scans of small dental, aesthetic, and accounting practices back this up: not one earned a grade above C, and 83% scored a D or F. If you are asking “is my business a target,” the honest answer is: you have already been scanned - you just didn’t see it. The full threat-by-threat picture is in our guide to cyber threats for business.

2. The three layers of defense

Three layers of cyber defense for small business Layer 1 Access MFA everywhere Password manager Patches in 7 days Layer 2 Data 3-2-1 backup Disk encryption Monthly restore test Layer 3 Fraud SPF + DKIM + DMARC Payment verification Training + simulations

Each layer can be built in-house or outsourced. Together, the three deliver roughly 80% of the risk reduction for 20% of the cost of an enterprise-grade stack. This is the model we apply in every assessment we run for small dental, accounting, and aesthetic practices.

Layer 1 - Access

Control question: if an employee typed their work password into a fake login page, could the attacker get into your email, banking, payroll, and practice software as easily as that employee can?

If yes, you don’t have an access layer.

Three building blocks:

MFA everywhere it’s possible. Microsoft reports that multi-factor authentication blocks over 99% of automated attacks on accounts. It is the single best return on effort in all of security. Rollout order: business email, banking, payroll, accounting software (QuickBooks, Xero), practice management, website admin panel, marketing tools. In practice: 2-4 hours of admin work for a 10-person firm.

A password manager. Bitwarden Teams, 1Password Business, or Keeper, at a few dollars per user per month. It eliminates passwords saved in browsers on shared computers, the “passwords.xlsx” file, and one password reused across every service. A business setup lets the team share credentials without ever emailing them.

Patches within 7 days for critical vulnerabilities. The overwhelming majority of successful intrusions exploit known flaws for which a fix had been available for months - CISA’s Known Exploited Vulnerabilities Catalog is the running list of the ones being used right now. Microsoft’s Patch Tuesday (second Tuesday of the month) is a good rhythm for workstations; for servers and routers, subscribe to vendor alerts and patch outside working hours.

If you have remote staff, add endpoint management (Microsoft Intune, Jamf) to this layer. Without it, you don’t know whether the bookkeeper’s laptop at home has disk encryption turned on.

Layer 2 - Data

Control question: if ransomware encrypted every company computer tonight, how much data would the business lose for good - and how long would it take to reopen?

If you don’t know the answers, you don’t have a data layer.

The industry standard is the 3-2-1 backup rule: three copies of your data, on two different media, one copy off-site. Modern ransomware deliberately hunts down and deletes local backups, so the last element - an offline copy or immutable cloud storage - matters more today than ever. Some vendors extend this to 3-2-1-1-0: one immutable copy, zero errors in restore tests.

A concrete setup for a 10-person practice: originals on workstations or an office file server, a local NAS (Synology, QNAP) taking daily copies, and cloud backup with object lock (Backblaze B2, Wasabi, or Microsoft 365 Backup) keeping 30+ days of snapshots.

The second element is encryption. BitLocker on Windows Pro laptops, FileVault on MacBooks, biometric lock on work phones. This is the minimum that HIPAA’s Security Rule expects for devices holding patient data - and most cyber-insurance policies require it regardless of your sector.

The third element is a restore test. A backup you haven’t tested is not a backup - it’s a hope. Restore one file monthly and one full machine or database quarterly. Industry estimates put roughly one in five backups as failing to restore correctly, and companies usually discover it during a real crisis.

Total: a 4-bay NAS ($500-1,000 one-time), a cloud backup subscription ($10-40 a month), and an hour of setup. Less than one billable day of your accountant’s time, against a risk that costs orders of magnitude more. How the attack itself unfolds - and why backups decide the outcome - is in our ransomware guide and the case study of one open port.

Layer 3 - Fraud

Control question: if someone emailed your bookkeeper this morning “from you,” asking for an urgent transfer to a vendor’s new account number - would it get paid?

If the answer is “yes” or “I’m not sure,” you don’t have a fraud layer.

Business email compromise (BEC) is the most expensive scam class aimed at small firms: the FBI’s IC3 counted over $3 billion in reported BEC losses in 2025 alone, from fewer than 25,000 complaints. Accounting and CPA firms are exposed most, because they run other people’s payments - one convincing spoofed email can cost tens of thousands of dollars.

Three defenses:

The full email authentication stack: SPF + DKIM + DMARC. SPF says which servers may send mail from your domain. DKIM signs messages cryptographically. DMARC ties both together and tells receiving servers what to do with fakes - and only a quarantine or reject policy blocks anything. Setup is 2-4 hours with whoever manages your DNS: start DMARC at p=none to collect reports, and after 4-8 weeks of clean traffic move to p=reject. The step-by-step walkthrough is in SPF, DKIM and DMARC for accounting firms.

A second-channel payment verification procedure. Every change of a vendor’s bank details, every wire above an agreed threshold, every “urgent” instruction from the boss gets verified by phone on a number you already had - never the one in the email. Five minutes of calling saves a five-figure loss. Put it in writing and make sure the team knows it.

Phishing training and simulations. Short 15-30 minute sessions quarterly, plus simulated phishing monthly. The working target: a click rate under 5% after 12 months. Training without simulations doesn’t stick; simulations without training just frustrate people. They only work together - the full playbook is in our phishing guide.

One newer vector deserves a mention: AI voice deepfakes. Sixty seconds of a manager’s voice from a public video is enough to clone it and call the bookkeeper. The defense is the same second-channel verification, plus a pre-agreed passphrase for payment instructions.

3. What you can skip

Most small-business security articles were written by people who work at enterprises. The advice lands on a 12-person practice with no IT department and tells it to deploy things designed for a bank with 5,000 seats.

Skip the following until the three layers above are in place.

SIEM or SOC-as-a-Service. Log correlation platforms make sense above roughly 50 employees, when someone actually has time to react to alerts. In a 10-person firm, a SIEM without an analyst generates 200 alerts a day that nobody reads - the same outcome as no SIEM, plus a monthly invoice.

SOC 2. Worth it when a corporate client demands it in a contract, or when you are losing deals specifically because a competitor has the report. Without one of those reasons, the audit and preparation costs have no business justification for a small practice.

A full-time security hire. Sensible above 30-50 employees. Below that, better options are an annual independent external assessment, an MSSP retainer if you are in a regulated niche, or a slice of your existing IT provider’s time explicitly dedicated to security.

Enterprise EDR with 24/7 monitoring. CrowdStrike, SentinelOne, and Sophos MDR are excellent products priced for organizations that need round-the-clock response. For a 10-person practice, Microsoft Defender for Endpoint - included in Microsoft 365 Business Premium at roughly $22 per user per month, together with email and Office - is enough.

A full framework program. Adopting the entire NIST CSF, or preparing for CMMC, belongs to companies with government contracts or dedicated compliance staff. Your regulator-driven baseline - HIPAA Security Rule or the FTC Safeguards Rule - is covered by the three layers plus documentation, which we map in the data security compliance guide.

A penetration test in year one. A pentest makes sense after the three layers exist. Before that, it produces a long list of weaknesses you have no time to fix, plus a feeling of futility. First a vulnerability assessment, then - after remediation - a pentest.

“Don’t do this” is often worth more than “do that” - it saves dozens of hours and thousands of dollars spent on the wrong priorities.

4. The 30-60-90 day plan

30-60-90 day plan for a 10-person business 1-2 Weeks 1-2 Inventory + MFA 3-4 Weeks 3-4 Backup + password manager 5-8 Weeks 5-8 Email SPF/DKIM/DMARC 9-12 Weeks 9-12 Scan + fixes

The plan assumes a 5-20 person business, one founder as the decision-maker, and either an outside provider or time to work through guides yourself.

Weeks 1-2: Inventory and MFA everywhere

List every business account: email, banking, payroll, accounting software, practice management, hosting, website admin, marketing tools, file storage. Turn on MFA for each. Prefer authenticator apps (Microsoft, Google) or hardware keys (YubiKey) for the critical accounts; SMS is the last resort because of SIM swapping. Check your domain against Have I Been Pwned - any old company addresses in breaches mean password resets plus MFA. And get the outside view for free: book a PreScan to see what an attacker sees before ever touching your systems.

Weeks 3-4: Backup and password manager

Choose and deploy 3-2-1 backup - for most practices, an office NAS plus immutable cloud storage. Run the first restore test (one file, one database) and put a monthly repeat in the calendar. Roll out the company password manager and migrate shared credentials (Wi-Fi, admin panels, shared logins). BitLocker or FileVault on every laptop.

Weeks 5-8: Email security

Configure SPF and DKIM for the company domain (your hosting or email admin does this). Start DMARC at p=none and collect reports - dmarcian, Postmark DMARC, and similar tools make them readable. After four weeks of analysis and fixes, move to p=quarantine, then p=reject. Write down the second-channel payment verification procedure. Run a short team session (30 minutes) and the first phishing simulation (Gophish self-hosted or a commercial tool) to get a baseline click rate.

Weeks 9-12: External scan and remediation

Run an external vulnerability assessment - that is exactly what our external vulnerability assessment does, with a plain-English report and CVSS priorities in 5 business days. Fix critical findings within 7 days and high ones within 30 - the standard remediation rhythm. Put an annual external assessment in the calendar: HIPAA’s Security Rule requires a periodic risk analysis, and the FTC Safeguards Rule requires regular testing of your safeguards - once a year is the defensible minimum for both. Close the quarter with a short written security policy: who is responsible for what, and what happens when something breaks.

After 90 days the business has three layers of defense, documentation that stands up to HIPAA or Safeguards scrutiny, an incident plan, a calendar of recurring tasks, and one person who knows exactly where the company stands. That is more than most small practices ever get to.

5. Budget

Realistic annual figures for a 10-person practice, in USD, as of 2026.

$0 (time only). MFA on every account, basic SPF/DKIM/DMARC, BitLocker/FileVault, a written policy, manual payment verification, regular patching. Delivers roughly 60-70% of the protection for 20-40 hours of work in the first month. Every business should have this tier - without it, further spending buys less.

Under $1,000 a year. A password manager (a few dollars per user monthly), free DMARC reporting tools, a self-hosted phishing simulator (Gophish), and the free PreScan. Still firmly in DIY territory.

$1,000-4,000 a year. Microsoft 365 Business Premium (~$22 per user per month - includes Defender for Endpoint, enforced MFA, and conditional access), a NAS with disks ($500-1,000 one-time) plus cloud backup ($10-40 a month), managed DMARC ($50-150 a month). This is where most small practices land after their first year.

$4,000-10,000 a year. An annual external vulnerability assessment (see pricing), a commercial phishing-simulation platform, and a small-business cyber-insurance policy. The tier for regulated practices, firms with corporate clients, or anyone who has already had an incident.

Above $10,000 a year. A SOC retainer, MSSP, annual penetration tests, a dedicated SIEM. This is the world of 50+ employee companies and regulated industries - most small practices never need to drive here.

A useful benchmark: a typical 10-person firm spends about 0.5-1.5% of annual revenue on its complete security stack. The first implementation wave (weeks 1-12 above) runs from $0 to about $5,000.

6. FAQ

Does a 10-person practice really need to deal with this?

Yes. Per Verizon’s DBIR 2026, ransomware is present in 48% of confirmed breaches, and where the victim’s size was known, 96% were small and medium businesses. Bots don’t choose targets - they scan everything visible online, including the smallest practice.

Where do we start if we’ve done nothing so far?

Turn on MFA for your email and banking accounts today. It takes about 30 minutes per account, and Microsoft reports that multi-factor authentication blocks over 99% of automated account attacks. Then follow the 30-60-90 day plan above.

Does HIPAA or the FTC Safeguards Rule apply to my practice?

If you handle patient health information - dental office, med spa - HIPAA applies, including its Security Rule risk analysis. If you handle client financial data - CPA, accounting, tax - the FTC Safeguards Rule applies and requires a written information security program. The full map is in the data security compliance guide.

What should we do if we suspect an attack right now?

Disconnect affected systems from the network, but do not power them off - you would lose volatile evidence. Preserve logs. File a complaint at ic3.gov. If patient or client data may be exposed, notification clocks start: HIPAA allows up to 60 days, the FTC Safeguards Rule 30 days for incidents affecting 500 or more consumers, and state laws add their own.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment maps weaknesses - what is exposed and how to fix it. A penetration test checks exploitation - whether a weakness can actually be used to get in. Most small businesses start with an assessment and move to a pentest after fixing what it found.

Is free antivirus enough in 2026?

No. The standard is EDR (Endpoint Detection and Response), which watches process behavior instead of just matching signatures. Microsoft Defender for Endpoint, included with Microsoft 365 Business Premium, is enough for most small practices - no extra product needed.

Can we just pay the ransom if ransomware hits us?

First check whether a free decryptor exists in the No More Ransom database. In Sophos’s State of Ransomware research, only a small minority of paying victims got all their data back. Paying funds the next attack and is the last option, not the first - what actually decides the outcome is a tested, separated backup, as we show in the ransomware guide.

What about AI-powered attacks?

The real 2026 problems are AI-written phishing - clean language, convincing context - and voice deepfakes in wire-fraud calls. The defense doesn’t change: phishing-resistant MFA (hardware keys, passkeys), verification of payment changes on a second channel, and short, regular training.

How long does basic cyber hygiene take to implement?

The 30-60-90 day plan assumes 2-4 hours a week for three months, plus one 5-business-day external assessment. That is realistic for a 10-person practice run by a single decision-maker.

Do we have to encrypt company laptops?

Yes. BitLocker on Windows Pro laptops, FileVault on MacBooks, biometric lock on work phones. HIPAA’s Security Rule expects it for devices holding patient data, most cyber-insurance policies require it, and setup takes about 15 minutes per device.

7. Next step

The simplest way to learn where you stand today is the free PreScan: a passive external assessment that shows what an attacker sees before ever touching your infrastructure. Results within 24 hours, no obligation, nothing installed on your side.

Book the free PreScan

If you already know you need a full assessment, check the pricing page or write to us directly via the contact page.

Neighboring guides: