Most small businesses do not get breached by sophisticated hackers. They get breached by preventable basics: a reused password, a missing update, no second factor on email. The good news is that a modest, unglamorous baseline stops the overwhelming majority of real-world attacks. Here is that checklist - in priority order.

1. Turn on multi-factor authentication everywhere

MFA is the single highest-return security control there is. Even if a password is stolen, the attacker cannot get in without the second factor. Enable it on email first (email is the master key that resets everything else), then on every account that offers it. If you do one thing on this list, do this.

2. Get backups you have actually tested

Ransomware and simple mistakes both end the same way: data gone. Backups are the difference between an incident and a catastrophe - but only if they work. Follow the rule of three copies, on two types of media, with one off-site, and test a restore. An untested backup is a guess, not a safety net.

3. Keep everything patched and updated

Most exploited vulnerabilities have a fix available - the victim just had not applied it. Automatic updates on operating systems, browsers, and key applications close the holes attackers rely on. This is boring and it is decisive.

4. Control who has access to what

People should have the access they need for their job and no more. When someone leaves, remove their access the same day. Use unique accounts, not shared logins, so you know who did what. Review admin rights - they should be rare.

5. Use a password manager

Reused passwords mean one breached site compromises everything. A password manager makes every login unique and strong without anyone needing to remember them. It removes the single most common cause of account takeover.

6. Secure and separate your email

Email is the top target because it unlocks everything else. Beyond MFA, watch for phishing, be cautious with attachments and links, and make sure account recovery cannot be trivially hijacked.

7. Protect and segment your network

Keep guest Wi-Fi separate from business systems, change default equipment passwords, and keep firmware current. A visitor's laptop should never share a network with your critical systems.

8. Write down what to do when something goes wrong

A simple, written plan - who to call, how to isolate a machine, where the backups are - turns a panic into a procedure. You do not want to be figuring this out during the incident.

Right-sized, not enterprise theater

You do not need an enterprise security budget or controls that make daily work miserable. You need the baseline done properly and kept current - which is exactly the gap that continuous security management fills, and part of what proactive managed IT keeps healthy so it does not quietly lapse.

Not sure where you stand? Ask us for a baseline review and we will tell you what is solid and what needs attention - in plain language, right-sized for your business.