Cyber resource center

Cyber resources for small business.

Almost everything a small business needs to get its security in order has already been written, tested, and published for free by the agencies and vendors involved. The problem is finding it. This is the shortlist.

  • Free and vendor-neutral
  • Grouped by publisher
  • Every link checked

How to use this page

You do not have to read all of it.

This is a reference, not a curriculum. Nothing here is behind a paywall, a lead form, or a sales call, and none of it is ours — it is published by federal agencies and by the platform vendors you already pay for. We keep the list because clients ask for it and because the same handful of documents answers most of the questions we get.

If you only have an afternoon, spend it on three things: turn on multi-factor authentication everywhere it is offered, confirm that your backups exist and can actually be restored, and teach whoever handles money how invoice fraud works. Those three account for the overwhelming majority of what actually goes wrong at businesses this size.

If you would rather not work through it alone, that is what we do — but the guidance below stands on its own either way.

Where to start

  • Multi-factor authentication on email first
  • A backup you have tested restoring
  • Anyone who pays invoices trained on wire fraud
  • Every device on a supported, patched version

Federal guidance

SBA, FTC, and NIST.

The plain-language starting points. Written for owners rather than engineers, and free of vendor interest.

01

Strengthen your cybersecurity

The SBA business guide chapter: employee training, network security, updates, multi-factor authentication, and where to get an assessment.

02

Cyber safety tips for owners

A short SBA post covering staff training, securing the network, antivirus, and backing up business data.

03

Three simple things

The shortest useful list in this section: change passwords, update software, train employees. Roughly 43 percent of incidents hit small businesses.

04

FTC cybersecurity for small business

A structured library covering email, remote access, web hosting, vendor security, cyber insurance, and how to respond to an attack.

05

Scams and your small business

The FTC guide to business-targeted fraud: spotting it, verifying payment changes, training staff, and where to report it.

06

NIST cybersecurity basics

A compact set of steps and further resources for managing security risk continuously rather than as a one-time project.

07

CSF 2.0 Small Business Quick-Start Guide

NIST SP 1300. Walks a small business through the framework functions — Govern, Identify, Protect, Detect, Respond, Recover.

  • PDF

FBI

Fraud, ransomware, and reporting.

The FBI pages matter for two reasons: they describe how these crimes actually run, and they tell you where to report one while the money may still be recoverable.

01

Business email compromise

How invoice and wire fraud works, the warning signs, and what to do immediately after a fraudulent payment. The costliest crime on this page.

02

Ransomware

Prevention through updates, scanning, and offline backups, plus the Bureau’s position on paying a ransom and how to report an incident.

03

Spoofing and phishing

Recognizing spoofed senders and phishing, along with the voice, text, and DNS variants — vishing, smishing, and pharming.

04

What businesses should know

Identify your cyber risk, build a response plan that includes contacting the FBI, and report compromises promptly rather than quietly.

05

IC3 industry alerts

Current public service announcements from the Internet Crime Complaint Center. Also the place to file a report.

CISA

The federal cyber defense agency.

CISA’s own summary of why this matters: small businesses have valuable information that cyber criminals seek, and often have fewer resources dedicated to cybersecurity. Their material is the most practical of any agency on this list, and much of it is free service rather than free reading.

01

Cyber guidance for small businesses

Split by who has to act — the owner, whoever runs security, and whoever runs IT. Covers multi-factor authentication, patching, backups, incident response, training, and moving services to the cloud.

02

Cyber Essentials

Six elements of cyber readiness for leaders who are not technical, with a Starter Kit and per-element toolkits.

03

Small and medium businesses

CISA’s hub for this size of organization: tools, alerts, advisories, and regional advisors you can actually contact.

04

No-cost services and tools

A catalog of free cybersecurity services from CISA, other agencies, and the private sector. Worth a look before buying anything.

Payment cards

If you take card payments.

PCI DSS applies to every business that accepts cards, including the smallest. The obligation usually comes through your merchant bank rather than directly.

01

Guide to safe payments

The PCI Council’s small-merchant guide: passwords, terminals, third-party vendors, patching, access control, and encryption.

  • PDF
02

Payment security self-check

Work through your current practices and see where they fall short. Results are for your own use — formal evaluation goes through your merchant bank.

03

Resources for merchants

Tools, short training videos, and FAQs from the council that writes the standard, organized around common payment threats.

04

PCI compliance explained

A third-party walkthrough of merchant levels, self-assessment questionnaires, quarterly scans, costs, penalties, and what changed in version 4.0.

Microsoft 365

Securing the tenant you already pay for.

Most Microsoft 365 subscriptions include far more security than is ever switched on. These are the vendor’s own instructions for switching it on.

01

Zero Trust for small business

Microsoft’s deployment guidance for Business Premium — identity, device, and threat protection, written for the partner doing the work.

02

Security for small and medium business

The product-level comparison: which plans include which security features, device limits, and support.

03

Microsoft Security blog — SMB

Ongoing coverage of threats, Defender, compliance, remote work, identity, and endpoint protection at this scale.

04

Where shared responsibility sits

A community write-up of what Microsoft secures versus what remains yours, and the configuration gaps that catch small tenants out.

Apple

Macs, iPhones, and iPads.

Apple’s security documentation is good and almost never read. Start with the account pages — a compromised Apple Account is the usual entry point, not malware.

01

Recognize and avoid phishing

Apple’s guide to social engineering: fake support calls, phony messages, and how to report what you receive.

02

Change your Apple Account password

If you believe an Apple Account has been compromised, change the password immediately. Covers trusted devices, Mac, web, and child accounts.

03

Get help with security issues

Apple’s index for account security, purchases, phishing, lost devices, and personal safety concerns.

04

Protecting against malware in macOS

How the three layers actually work — App Store review, Gatekeeper and notarization, and XProtect remediation.

05

Apple security releases

The running list of security updates by version and device. Useful for confirming a machine is on a still-supported release.

06

Personal Safety User Guide

Safety Check and three checklists for situations where someone with physical access may be the risk.

07

Protect your small business: Apple

A how-to guide from the Australian Cyber Security Centre, written with Apple: passwords, multi-factor authentication, updates, XProtect, backups, and Safety Check.

  • PDF

Google

Google Workspace and Google accounts.

01

Security checklist, 1–100 users

Google’s own hardening checklist for a business this size, covering accounts, apps, email, calendar, and file sharing.

02

Administrator account best practices

2-Step Verification, security keys, keeping admin accounts separate from daily-use accounts, monitoring, and recovery planning.

03

Google security tips

Consumer-facing but broadly useful: scams, phishing, authentication, device security, and safer browsing.

04

Payments center security

How Google handles payment data and what merchants are expected to do on their side.

Facebook and Instagram

Business accounts and pages.

A hijacked business page is a real and common loss for small businesses, and recovering one is far harder than protecting it.

01

Keeping business accounts secure

Meta’s own recommendations for Facebook and Instagram business accounts.

02

Security Checkup

Review login alerts for unrecognized devices, check password strength, and turn on two-factor authentication.

03

Spam, scams, and phishing

What the common Facebook scams look like and how to avoid handing over an account.

04

Reporting content

How to report impersonation, scams, and abuse — worth knowing before you need it urgently.

Credentials

Passwords, passphrases, passkeys, and MFA.

Stolen and reused credentials remain the most common way in. This is the one category worth understanding properly rather than just complying with.

01

How passkeys work

Enrollment, sign-in, where keys are stored and synced, and why passkeys resist phishing in a way passwords cannot.

02

Password vs. passphrase

When a long random passphrase is the right choice and when a generated password is — and why reuse is the thing that actually hurts.

03

Password cracking calculator

Estimates what it would cost an attacker to crack a given password. The fastest way to make the case for a password manager.

04

Password Bits

A working blog on password managers, two-factor authentication, passphrases, hardware keys, and emergency access sheets.

05

Operation Privacy

A free dashboard of privacy tasks with progress tracking, including removing business and personal listings from data brokers.

Want help putting any of this in place?

Everything above is free to read and free to act on. If you would rather have it done and documented, start with a call — the first fifteen minutes are free.

On aiming higher than the baseline

Most security advice quietly assumes you are only willing to make small changes. CISA’s Cyber Guidance for Small Businesses includes a passage that assumes otherwise, and it is worth reading in full because it describes the one move that removes whole categories of risk instead of managing them:

When security experts give cybersecurity advice, they usually assume you are only willing to make small changes to your IT infrastructure. But what would you do if you could reshape your IT infrastructure? Some organizations have made more aggressive changes to their IT systems to reduce their “attack surface.” In some cases, they have been able to all but eliminate (YES, WE SAID ELIMINATE!) the possibility of falling victim to phishing attacks.

One major improvement you can make is to eliminate all services that are hosted in your offices. We call these services “on premises” or “on-prem” services. Examples of on-prem services are mail and file storage in your office space. These systems require a great deal of skill to secure. They also require time to patch, to monitor, and to respond to potential security events. Few small businesses have the time and expertise to keep them secure.

While it’s not possible to categorically state that “the cloud is more secure,” we have seen repeatedly that organizations of all sizes cannot continuously handle the security and time commitments of running on-prem mail and file storage services. The solution is to migrate those services to secure cloud versions, such as Google Workspace or Microsoft 365 for enterprise email. These services are built and maintained using world-class engineering and security talent at an attractive price point. We urge all businesses with on-prem systems to migrate to secure cloud-based alternatives as soon as possible.

The same document makes a second point about endpoints — that Chromebooks and iPads are secure by design in a way general-purpose computers are not, and that moving staff onto them removes a great deal of attack surface, because even a successful attack finds little data sitting on the device.

That will not fit every business, and we will tell you when it does not. But the reason we lean toward Microsoft 365, managed devices, and cloud file storage for clients this size is not preference. It is that the alternative asks a small business to staff a job it cannot staff.