Small business IT security checklist: 12 things to fix
Ordered by impact per hour of effort. Most cost nothing beyond licences you probably already own.
Short answer
The highest-impact controls are phishing-resistant MFA everywhere, legacy authentication disabled, separated admin accounts, disk encryption, current patching, and tested backups. Most are already included in Microsoft 365 Business Premium — they're a configuration task, not a purchase. The common failure isn't missing tools; it's paying for controls nobody switched on.
The checklist
1. Multi-factor authentication on every account — no exceptions
Including the owner, including the account "that's only used for the accounting system". Compromised credentials remain the most common entry point, and MFA blocks the overwhelming majority of those attempts. Prefer an authenticator app or hardware key over SMS, which is interceptable by SIM swap.
Effort: an afternoon. Cost: included in any Microsoft 365 business plan.
2. Turn off legacy authentication
Old protocols such as POP, IMAP and SMTP AUTH bypass MFA entirely. Attackers specifically target them because they render step 1 useless. Check for anything still using them first — an old printer or scanner is the usual culprit.
Effort: an hour, plus fixing whatever breaks. Cost: nothing.
3. Separate administrator accounts from daily accounts
Nobody should read email and browse the web from an account holding global administrator rights. One phishing click on an admin account compromises everything at once. Create dedicated admin accounts, used only for administration.
Effort: an hour. Cost: nothing — admin accounts don't need a licence.
4. Create a break-glass account you control
A global administrator account your company owns, with credentials stored somewhere safe and offline, excluded from conditional access policies that could lock it out. This is your recovery path if your provider disappears, an admin leaves badly, or a policy misfires.
Effort: 30 minutes. Cost: nothing.
5. Enable disk encryption everywhere
BitLocker on Windows, FileVault on Mac. A lost laptop is an inconvenience if encrypted and a reportable data breach if not. Store recovery keys centrally, in your tenant rather than on a sticky note.
Effort: an hour with device management. Cost: nothing.
6. Patch on a schedule, and verify it
Operating systems, browsers and applications. Most exploited vulnerabilities have had a patch available for months — the failure is deployment, not disclosure. Verify compliance rather than assuming automatic updates worked.
Effort: ongoing. Cost: nothing, or a management tool.
7. Back up your cloud data
Microsoft 365 is not a backup. Microsoft protects the platform's availability; you're responsible for your content. Accidental deletion, malicious insiders and ransomware all reach cloud data, and retention windows are shorter than most people assume. Test a restore — an untested backup is a hope, not a control.
Effort: an hour to configure. Cost: $2–$5 per user/month.
8. Offboard people properly, the same day
Disable the account, revoke active sessions, reset the password, convert the mailbox, reassign files, wipe or reclaim the device, and remove them from third-party tools. That last one is where things rot — SaaS applications outside your identity provider keep working long after someone leaves. Keep a written offboarding checklist.
Effort: 30 minutes per departure, or automated. Cost: nothing.
9. Use conditional access
Block sign-ins from countries you don't operate in, require compliant devices for sensitive applications, force reauthentication on risky sign-ins. Included in Entra ID P1, which comes with Microsoft 365 Business Premium.
Effort: a few hours to design carefully. Cost: included in Business Premium.
10. Train people on phishing, briefly and often
Short monthly exposure beats an annual hour nobody remembers. Simulated phishing with immediate coaching works better than lecturing. Critically: make reporting a suspected phish easy and never punish someone for clicking — punishment teaches people to hide incidents, which is far more dangerous than the click.
Effort: ongoing. Cost: $2–$4 per user/month.
11. Write down what you have
Devices, accounts, applications, vendors, licences, renewal dates, who has access to what. During an incident, undocumented environments turn a two-hour problem into a two-day one. It doesn't need to be sophisticated — a maintained spreadsheet beats an elegant system nobody updates.
Effort: a day initially. Cost: nothing.
12. Decide in advance who you call
A written page: who to contact for a suspected breach, your insurer's notification number, your legal contact, and who can authorise taking systems offline. The worst time to work this out is at 2am during an incident.
Effort: an hour. Cost: nothing.
What most companies get wrong
Paying twice, protected once
Two patterns recur. Companies on Business Standard buy separate endpoint protection that would be cheaper as a Business Premium upgrade — Premium includes Defender for Business, Intune and Entra ID P1 for roughly $9 more per user. And companies already on Business Premium never switch those controls on, paying for protection they don't have. Before buying any new security product, audit what your existing licences already include.
On cyber insurance
Increasingly required, and often demanded by larger customers as a condition of doing business. One caution: insurers ask specific questions about MFA and monitoring, and there's established case law where failure to maintain the controls described on an application defeated coverage. Answer accurately, keep evidence, and update your insurer if your controls change. An inaccurate application is worse than no policy — you pay premiums and still aren't covered.
A realistic sequence
| When | Do | Cost |
|---|---|---|
| This week | MFA everywhere, break-glass account, separate admin accounts | $0 |
| This month | Legacy auth off, encryption on, offboarding checklist written | $0 |
| This quarter | Backup with a tested restore, conditional access, documentation | ~$5/user/mo |
| Ongoing | Patching, training, quarterly access review | ~$3/user/mo |
Nothing here requires a consultant. It requires someone to own it and work through the list — which is precisely what most small companies lack, and why the list stays undone.
About the author
Raymond Payne is the founder of PCR — Managed IT. Thirty years building and running technology for businesses across more than a dozen countries, and author of Mastering Automation with AI. Last updated 14 August 2026.
Want to know where you actually stand?
We'll audit your Microsoft tenant against this checklist and send written findings — yours to keep whether or not you hire us.