A small business cybersecurity checklist should start with the controls that stop the most common attacks: multi-factor authentication on every account, endpoint detection and response on every device, tested offline backups, patched systems, and staff who can recognize a phishing email. The 20 controls below are grouped into six areas and ordered so the first items in each group are the ones cyber-insurance carriers and regulators ask about first. Print it, check what you have, and start at the top of whatever is missing.
How to use this small business cybersecurity checklist
You do not need every item on day one. Businesses we work with across Vero Beach, Port St. Lucie, and Stuart typically have six to eight of these in place when we first meet them and close the rest over one to two quarters. Items marked insurer priority are the ones that show up on nearly every cyber-insurance application and on HIPAA, PCI, and CMMC questionnaires; missing them can mean a declined policy or a higher premium.
Identity and access
- 1. Multi-factor authentication everywhere (insurer priority). Email, remote access, cloud apps, banking, and admin accounts. Prefer an authenticator app or passkeys over text messages.
- 2. A business password manager. Unique passwords for every system, shared credentials stored in a vault instead of a spreadsheet, and instant revocation when someone leaves.
- 3. Separate admin accounts. Nobody browses email with an account that can also install software on every machine. Local administrator rights are removed from daily-use accounts.
- 4. Documented onboarding and offboarding. A checklist that creates and removes access the same day, every time, including the door code, the alarm, and the accounting system.
Devices and endpoints
- 5. Endpoint detection and response on every device (insurer priority). Traditional antivirus is no longer enough; EDR watches behavior and can isolate a machine automatically. Insurers now ask for it by name.
- 6. Automatic patching for operating systems and applications. Windows, macOS, browsers, PDF readers, and line-of-business software, with reporting so you know what did not install.
- 7. Full-disk encryption on laptops and phones. A stolen laptop with BitLocker enabled is an inconvenience; without it, it can be a reportable breach.
- 8. Retire unsupported systems. Old Windows versions and end-of-life servers are the easiest doors in the building. If a legacy application requires one, isolate it on its own network segment.
- 9. Mobile device management. The ability to require a PIN, enforce encryption, and wipe company data from a lost phone, whether the phone is company-owned or personal.
Email and collaboration
- 10. Advanced email filtering. Link scanning, attachment sandboxing, and impersonation protection beyond the default spam filter.
- 11. SPF, DKIM, and DMARC on your domain. Stops criminals from sending mail that appears to come from you, which protects your customers and your reputation.
- 12. External forwarding blocked and inbox rules monitored. The two settings that stop business email compromise from operating quietly inside a hijacked mailbox.
Backup and recovery
- 13. Backups that ransomware cannot reach (insurer priority). Immutable or offline copies with separate credentials, kept for at least 30 days, with one copy outside the region. Florida businesses should treat this as hurricane planning as much as cyber planning.
- 14. Tested restores. A file restore monthly and a full system restore at least quarterly, with the time recorded. Our backup and disaster recovery service builds this schedule in.
- 15. Microsoft 365 or Google Workspace backup. The cloud provider protects its infrastructure, not your deleted or encrypted data.
Network
- 16. Business-grade firewall with active subscriptions. Intrusion prevention, web filtering, and geo-blocking, with firmware kept current. A consumer router from the internet provider does not qualify.
- 17. Network segmentation. Guest Wi-Fi, printers, cameras, thermostats, and medical or shop equipment separated from the network where your data lives.
- 18. Secure remote access. No Remote Desktop exposed directly to the internet. Use a VPN with MFA or a zero-trust access tool.
People and process
- 19. Security awareness training with phishing simulations (insurer priority). Short, regular training beats an annual video. Track results and coach, do not punish.
- 20. A written incident response plan. Who to call, in what order, what to unplug, and where the cyber-insurance policy number is. Rehearse it once a year at a lunch meeting. A plan on paper is what turns a bad day into a manageable one, and our incident response team will help you write it.
Which cybersecurity controls do insurers require first?
If you only have budget for four things this quarter, cyber-insurance applications make the priority order clear: multi-factor authentication, endpoint detection and response, immutable and tested backups, and security awareness training. Carriers have learned that these four controls account for most of the difference between a claim and a non-event. Regulators tend to add encryption, access logging, and written policies to that list. Doing these first means the rest of the checklist can be paced without leaving you exposed or uninsurable.
Treasure Coast specifics worth adding
- Verify backups and generator or UPS runtime before June, not during a storm watch.
- Seasonal staff and part-time bookkeepers need the same offboarding discipline as full-time employees.
- Waterfront and warehouse Wi-Fi often reaches the parking lot; segment guest networks and hide equipment networks.
- Medical and dental offices should map each checklist item to the corresponding HIPAA safeguard so the work counts twice.
How to turn the checklist into a plan
Score yourself honestly, one point per item. Under 8 means you are relying on luck. From 8 to 14 is typical for a small office that has never had a security review; you are one project away from a much better position. Above 15, focus on testing and documentation, because the gap is now proving that controls work rather than installing them.
Most owners cannot tick these boxes with confidence because nobody has ever shown them the evidence. That is fixable. MainSail Data provides a free cybersecurity assessment for Treasure Coast businesses that walks through all 20 controls and shows you exactly where you stand. Call (772) 794-1194 or learn more about our cybersecurity services and book a review.

