Strengthen your cybersecurity
The SBA business guide chapter: employee training, network security, updates, multi-factor authentication, and where to get an assessment.
Cyber resource center
Almost everything a small business needs to get its security in order has already been written, tested, and published for free by the agencies and vendors involved. The problem is finding it. This is the shortlist.
How to use this page
This is a reference, not a curriculum. Nothing here is behind a paywall, a lead form, or a sales call, and none of it is ours — it is published by federal agencies and by the platform vendors you already pay for. We keep the list because clients ask for it and because the same handful of documents answers most of the questions we get.
If you only have an afternoon, spend it on three things: turn on multi-factor authentication everywhere it is offered, confirm that your backups exist and can actually be restored, and teach whoever handles money how invoice fraud works. Those three account for the overwhelming majority of what actually goes wrong at businesses this size.
If you would rather not work through it alone, that is what we do — but the guidance below stands on its own either way.
Federal guidance
The plain-language starting points. Written for owners rather than engineers, and free of vendor interest.
The SBA business guide chapter: employee training, network security, updates, multi-factor authentication, and where to get an assessment.
A short SBA post covering staff training, securing the network, antivirus, and backing up business data.
The shortest useful list in this section: change passwords, update software, train employees. Roughly 43 percent of incidents hit small businesses.
A structured library covering email, remote access, web hosting, vendor security, cyber insurance, and how to respond to an attack.
The FTC guide to business-targeted fraud: spotting it, verifying payment changes, training staff, and where to report it.
A compact set of steps and further resources for managing security risk continuously rather than as a one-time project.
NIST SP 1300. Walks a small business through the framework functions — Govern, Identify, Protect, Detect, Respond, Recover.
FBI
The FBI pages matter for two reasons: they describe how these crimes actually run, and they tell you where to report one while the money may still be recoverable.
How invoice and wire fraud works, the warning signs, and what to do immediately after a fraudulent payment. The costliest crime on this page.
Prevention through updates, scanning, and offline backups, plus the Bureau’s position on paying a ransom and how to report an incident.
Recognizing spoofed senders and phishing, along with the voice, text, and DNS variants — vishing, smishing, and pharming.
Identify your cyber risk, build a response plan that includes contacting the FBI, and report compromises promptly rather than quietly.
Current public service announcements from the Internet Crime Complaint Center. Also the place to file a report.
CISA
CISA’s own summary of why this matters: small businesses have valuable information that cyber criminals seek, and often have fewer resources dedicated to cybersecurity. Their material is the most practical of any agency on this list, and much of it is free service rather than free reading.
Split by who has to act — the owner, whoever runs security, and whoever runs IT. Covers multi-factor authentication, patching, backups, incident response, training, and moving services to the cloud.
Six elements of cyber readiness for leaders who are not technical, with a Starter Kit and per-element toolkits.
CISA’s hub for this size of organization: tools, alerts, advisories, and regional advisors you can actually contact.
A catalog of free cybersecurity services from CISA, other agencies, and the private sector. Worth a look before buying anything.
Payment cards
PCI DSS applies to every business that accepts cards, including the smallest. The obligation usually comes through your merchant bank rather than directly.
The PCI Council’s small-merchant guide: passwords, terminals, third-party vendors, patching, access control, and encryption.
Work through your current practices and see where they fall short. Results are for your own use — formal evaluation goes through your merchant bank.
Tools, short training videos, and FAQs from the council that writes the standard, organized around common payment threats.
A third-party walkthrough of merchant levels, self-assessment questionnaires, quarterly scans, costs, penalties, and what changed in version 4.0.
Microsoft 365
Most Microsoft 365 subscriptions include far more security than is ever switched on. These are the vendor’s own instructions for switching it on.
Microsoft’s deployment guidance for Business Premium — identity, device, and threat protection, written for the partner doing the work.
The product-level comparison: which plans include which security features, device limits, and support.
Ongoing coverage of threats, Defender, compliance, remote work, identity, and endpoint protection at this scale.
A community write-up of what Microsoft secures versus what remains yours, and the configuration gaps that catch small tenants out.
Apple
Apple’s security documentation is good and almost never read. Start with the account pages — a compromised Apple Account is the usual entry point, not malware.
Apple’s guide to social engineering: fake support calls, phony messages, and how to report what you receive.
If you believe an Apple Account has been compromised, change the password immediately. Covers trusted devices, Mac, web, and child accounts.
Apple’s index for account security, purchases, phishing, lost devices, and personal safety concerns.
How the three layers actually work — App Store review, Gatekeeper and notarization, and XProtect remediation.
The running list of security updates by version and device. Useful for confirming a machine is on a still-supported release.
Safety Check and three checklists for situations where someone with physical access may be the risk.
A how-to guide from the Australian Cyber Security Centre, written with Apple: passwords, multi-factor authentication, updates, XProtect, backups, and Safety Check.
Google’s own hardening checklist for a business this size, covering accounts, apps, email, calendar, and file sharing.
2-Step Verification, security keys, keeping admin accounts separate from daily-use accounts, monitoring, and recovery planning.
Consumer-facing but broadly useful: scams, phishing, authentication, device security, and safer browsing.
How Google handles payment data and what merchants are expected to do on their side.
Facebook and Instagram
A hijacked business page is a real and common loss for small businesses, and recovering one is far harder than protecting it.
Meta’s own recommendations for Facebook and Instagram business accounts.
Review login alerts for unrecognized devices, check password strength, and turn on two-factor authentication.
What the common Facebook scams look like and how to avoid handing over an account.
How to report impersonation, scams, and abuse — worth knowing before you need it urgently.
Credentials
Stolen and reused credentials remain the most common way in. This is the one category worth understanding properly rather than just complying with.
Enrollment, sign-in, where keys are stored and synced, and why passkeys resist phishing in a way passwords cannot.
When a long random passphrase is the right choice and when a generated password is — and why reuse is the thing that actually hurts.
Estimates what it would cost an attacker to crack a given password. The fastest way to make the case for a password manager.
A working blog on password managers, two-factor authentication, passphrases, hardware keys, and emergency access sheets.
A free dashboard of privacy tasks with progress tracking, including removing business and personal listings from data brokers.
Everything above is free to read and free to act on. If you would rather have it done and documented, start with a call — the first fifteen minutes are free.
Most security advice quietly assumes you are only willing to make small changes. CISA’s Cyber Guidance for Small Businesses includes a passage that assumes otherwise, and it is worth reading in full because it describes the one move that removes whole categories of risk instead of managing them:
When security experts give cybersecurity advice, they usually assume you are only willing to make small changes to your IT infrastructure. But what would you do if you could reshape your IT infrastructure? Some organizations have made more aggressive changes to their IT systems to reduce their “attack surface.” In some cases, they have been able to all but eliminate (YES, WE SAID ELIMINATE!) the possibility of falling victim to phishing attacks.
One major improvement you can make is to eliminate all services that are hosted in your offices. We call these services “on premises” or “on-prem” services. Examples of on-prem services are mail and file storage in your office space. These systems require a great deal of skill to secure. They also require time to patch, to monitor, and to respond to potential security events. Few small businesses have the time and expertise to keep them secure.
While it’s not possible to categorically state that “the cloud is more secure,” we have seen repeatedly that organizations of all sizes cannot continuously handle the security and time commitments of running on-prem mail and file storage services. The solution is to migrate those services to secure cloud versions, such as Google Workspace or Microsoft 365 for enterprise email. These services are built and maintained using world-class engineering and security talent at an attractive price point. We urge all businesses with on-prem systems to migrate to secure cloud-based alternatives as soon as possible.
The same document makes a second point about endpoints — that Chromebooks and iPads are secure by design in a way general-purpose computers are not, and that moving staff onto them removes a great deal of attack surface, because even a successful attack finds little data sitting on the device.
That will not fit every business, and we will tell you when it does not. But the reason we lean toward Microsoft 365, managed devices, and cloud file storage for clients this size is not preference. It is that the alternative asks a small business to staff a job it cannot staff.