Guerrero Technology Call (929) 779-3188

The 12-point security checklist for small businesses

No jargon, no product pitch. Twelve things that decide whether a bad day stays a bad day. Most take an afternoon; three of them prevent the majority of what actually happens to businesses your size.

  1. Multi-factor authentication everywhere it can be turned onEmail first, then remote access, then banking and payroll. Password-only email is the single most common way a small business gets breached.
  2. A separate administrator account for every personShared logins mean you can never answer the question of who did what, and one leaver takes the keys with them.
  3. A backup that has actually been restored fromPick a file at random, restore it, time how long it takes. If nobody can do this, you do not have a backup — you have a hopeful subscription.
  4. An off-site copy that ransomware cannot reachBackups on a drive plugged into the same network get encrypted along with everything else. One copy must be off-site and not permanently connected.
  5. Automatic updates on every machine, including the forgotten oneThere is always one — the reception PC, the machine running the old label printer. That is the one that gets in.
  6. Staff accounts closed the day someone leavesWrite it into your offboarding process alongside collecting the keys. Check quarterly for accounts that never got closed.
  7. Guest Wi-Fi on its own networkCustomers, contractors and personal phones should never sit on the same network as your payment terminals, servers or shared files.
  8. A business-grade firewall with its default password changedThe same applies to cameras, door systems, printers and anything else with a web login that shipped with admin/admin.
  9. Encryption switched on for every laptop and phoneA stolen laptop with full-disk encryption is a hardware loss. Without it, it is a data breach with notification duties attached.
  10. A written rule for verifying payment changes by voiceAny request to change bank details gets confirmed by calling a number you already had — never one in the email. This single rule prevents most wire fraud.
  11. Fifteen minutes of phishing training, twice a yearNot an hour-long video nobody watches. Show your team three real examples aimed at your industry and tell them who to forward suspicious mail to.
  12. A one-page list of what you would do if everything stoppedWho to call, where backups live, how to take payments manually, which systems come back first. Print it. A plan that exists only on the server is no plan.

Get the printable version

A one-page PDF you can put on the wall or hand to whoever manages your systems.

One email with the PDF. No newsletter unless you ask for one.

Questions about the list

Is this really free?

Yes. You get the PDF by email, and you are welcome to work through it yourself or hand it to whoever currently looks after your systems. If you would rather not give an email address, the full list is on this page above.

We can't do all twelve. Where do we start?

Items one, three and four — multi-factor authentication, a tested restore and an off-site backup copy. Those three prevent or survive the large majority of what actually happens to small businesses. The rest can follow over a few months.

Does this cover HIPAA, PCI or the FTC Safeguards Rule?

It overlaps with all of them but replaces none. These twelve are the practical foundation every small business needs. Regulated businesses need documented risk assessments and written policies on top, which is what the industry pages cover.

Would you rather someone just did it?

The free assessment goes through all twelve on your actual systems and gives you a written summary of where you stand — whether or not you hire me.

Call or text

(929) 779-3188

Same-day response on business days. Existing clients get an emergency number for evenings and weekends.

Request a free IT assessment

About an hour, on-site or remote. You get a written summary of what I found and what I would fix first — whether or not you hire me.

Or call (929) 779-3188. No answer means I am on a call — leave a message and you will hear back the same day.