Cybersecurity advice tends to arrive as either a scare story or a forty-page framework. Neither helps you on a Tuesday morning. What helps is a checklist: concrete items you can work through, check off, and revisit each quarter.
This is the checklist we'd hand a small business or local government office in 2026. You don't need to finish it in a week. Work top to bottom — the sections are roughly in order of how often each one turns out to be the thing that would have prevented a real incident.
What's different in 2026
Three things have changed the math for small organizations. First, AI has made phishing cheap, fluent, and personalized, so "spot the bad grammar" is no longer a defense. Second, cyber insurance carriers now routinely require proof of MFA, EDR, and tested backups before they'll write or renew a policy. Third, attackers have shifted toward the smallest targets precisely because they expect the basics below to be missing. The list itself isn't exotic — the stakes for skipping it are just higher.
1. Accounts and access
Most breaches still start with a stolen or guessed password, which is why this section comes first.
- Turn on multi-factor authentication (MFA) everywhere it exists — email, banking, payroll, Microsoft 365 or Google Workspace, and any remote access. Start with email; it's the master key to everything else.
- Deploy a password manager for the whole team and retire the shared spreadsheet of passwords for good.
- Remove admin rights from daily-use accounts. People can still request installs — malware just can't ride along on their permissions.
- Write down an offboarding step: when someone leaves, their accounts are disabled the same day, including email forwarding rules and any shared logins they knew.
- Audit who has access to what once a quarter. Access tends to accumulate; it should expire.
2. Devices and updates
Devices are where work happens and where attacks land. The goal is simple: every machine known, current, and protected — automatically.
- Keep a current inventory of every computer, server, and phone that touches company data. You can't protect what you don't know you own.
- Automate updates for operating systems and third-party apps — browsers, PDF readers, Java, Zoom. Attackers love the apps nobody remembers to update. This is exactly what managed patch management automates.
- Run modern protection on every endpoint — next-gen antivirus paired with endpoint detection and response (EDR), not a consumer antivirus from 2019. Here's what managed endpoint security covers.
- Encrypt every laptop (BitLocker on Windows, FileVault on Mac) so a stolen bag isn't a data breach.
- Enforce screen locks and passcodes on phones that receive company email — and make sure someone can wipe a lost device remotely.
3. Email and the human layer
Phishing remains the most common way in — and in 2026, AI-written phishing emails no longer have the telltale typos.
- Run short, regular security awareness training. A few minutes each month beats an annual hour everyone forgets.
- Set a verification rule for money and credentials: any request to change payment details, buy gift cards, or share a password gets confirmed by phone at a known number. No exceptions — including requests that appear to come from the owner.
- Publish SPF, DKIM, and DMARC records for your domain so criminals can't easily send email as you.
- Add an external-sender banner to inbound mail so spoofed "internal" messages stand out.
4. Backups and recovery
Backups are the difference between ransomware being a bad week and being a business-ending event.
- Follow the 3-2-1 rule: three copies of important data, on two different types of storage, with one off-site or in a separate cloud.
- Back up Microsoft 365 / Google Workspace separately. The provider keeps the service running; retaining your deleted data is your job.
- Test a restore every quarter and time it. A backup you've never restored is a hope, not a plan — managed backup and disaster recovery builds that testing in.
- Keep at least one backup copy offline or immutable so ransomware can't encrypt the backups along with everything else.
- Write a one-page incident plan: who to call, in what order, and where the cyber-insurance policy lives. Print it — if it only exists on the server, it may be encrypted too.
5. Network and Wi-Fi
The network layer is invisible until it isn't. A few settings here remove the easiest ways in.
- Change default passwords on routers, firewalls, and printers — yes, printers.
- Keep firewall and router firmware updated. These devices are patched even less often than PCs, and they face the internet directly.
- Separate guest Wi-Fi from business Wi-Fi. Visitors' devices should never share a network with your file server or point of sale.
- Use a VPN or secure gateway for remote access instead of exposing remote desktop to the internet — exposed RDP is still a top ransomware entry point.
If you do nothing else this quarter
The full list is worth working through, but five items prevent the most damage per hour invested:
- MFA on email and banking
- Automated patching for operating systems and third-party apps
- EDR-grade endpoint protection on every machine
- A tested backup with one copy off-site and offline
- The phone-verification rule for payments and credentials
Print the checklist, put a name next to each item, and put a recurring review on the calendar. Security isn't a product you buy once — it's a short list of habits kept current.
If you'd rather have most of this handled for you — monitored, patched, backed up, and reported on — that's what our managed IT services are built to do, and we're happy to walk the checklist against your current setup.
