Most ransomware attacks succeed because of one missing habit, not one missing tool.
You don't need a security team to dramatically cut your risk. These are the habits and free frameworks that stop the overwhelming majority of small-business attacks — in the order we'd tackle them with a new client.
Start here, in this order.
Turn on multi-factor authentication (MFA), everywhere
Email, remote access, and admin accounts first. MFA alone blocks the vast majority of account-takeover attempts, even when a password is stolen.
Back up on the 3-2-1 rule — and keep one copy offline
3 copies of your data, on 2 different media, with 1 copy offsite or offline/immutable so ransomware encrypting your network can't reach it too.
Patch operating systems and software on a schedule
Most exploited vulnerabilities have had a patch available for months. Automate updates where you can, and review the rest monthly.
Filter email and train people to distrust it
Most ransomware still starts with a phishing email. Layer spam/malware filtering with real, repeated training — see our free training resources.
Use least privilege, and clean up access on the way out
Give people access to only what their job needs, keep admin accounts separate from daily-use accounts, and disable access immediately when someone leaves.
Deploy endpoint detection & response (EDR), not just antivirus
Traditional antivirus catches known threats. EDR watches for the behavior of an attack in progress — often the difference between an alert and an encrypted network.
The NIST Cybersecurity Framework 2.0, in six words.
You don't have to invent your own security program. The National Institute of Standards and Technology publishes a free framework, and in 2024 added a sixth function specifically because smaller organizations needed help with the "who's actually in charge of this" question.
| Function | In plain English |
|---|---|
| Govern | Decide who owns cybersecurity decisions, and put a basic policy in writing. |
| Identify | Know what devices, data, and accounts you actually have to protect. |
| Protect | Put safeguards in place — MFA, backups, patching, access controls, training. |
| Detect | Have a way to notice when something's wrong, quickly. |
| Respond | Know what to do in the first hours of an incident (see our response guide). |
| Recover | Restore operations from clean backups and get back to business. |
Source: NIST Cybersecurity Framework 2.0: Small Business Quick-Start Guide. More on how this connects to compliance and legal protection on our Compliance Resources and Safe Harbor Laws pages.
Before you consider yourself "prepared"
Work through this list honestly. Most small businesses we assess are missing at least three of these.
Need the actual documents?
Written policies for most of the items above — incident response, backup, password, and more — are in our Free Templates & Policies library.
Get a free, limited assessment against this exact checklist.
We'll walk through where your business stands on MFA, backups, patching, and access — and give you a plain-English list of what to fix first.