Small-business cybersecurity is a set of ongoing responsibilities, not a single software purchase. Your Expert Tech can discuss the environment and help identify which protections and operating processes need attention.
Start with what the business relies on
Inventory essential accounts, devices, applications, and service providers. Identify who administers each system and who can authorize changes. Include remote workers and shared accounts that may have developed informally.
Include the places where important work happens outside the main office. A cloud application, a remote employee’s device, or an account managed by another supplier can introduce responsibilities that are easy to overlook. Begin with a practical inventory and record uncertain ownership as an open question rather than assuming someone else has it covered.
Address basic protections
Review strong authentication, software updates, access control, backups, and staff reporting. CISA's Secure Our World guidance provides a starting point for password practices, multifactor authentication, phishing awareness, and updates. The right implementation still depends on your systems and responsibilities.
| Responsibility | Question to settle |
|---|---|
| Accounts | Who grants, reviews, and removes access? |
| Devices | Who manages updates and records exceptions? |
| Reporting | Where do staff send a concern? |
| Recovery | Who maintains and checks recovery arrangements? |
Define monitoring and response
Ask who reviews alerts, what happens after a suspicious event, and when the business is contacted. Clarify support hours, escalation, vendor involvement, and excluded work. A tool installed on a device does not establish that someone is actively handling every alert.
Ask what the service actually does after a concern is identified. Does it notify a named person, investigate within an agreed scope, or coordinate another specialist? Confirm the process and coverage in the service terms. These distinctions make it possible to compare proposals without treating every mention of monitoring as the same commitment.
Verify and maintain
Test selected controls, review access when staff change, and confirm that recovery can be performed as planned. Keep unresolved gaps visible with owners and decisions. Avoid treating any service as a guarantee that incidents cannot occur.
Use a review meeting to check open responsibilities and changes in staff, systems, or suppliers. For example, a departing employee may affect several applications with different administrators. Record which owners have completed their part and what remains outstanding. Verification should produce a usable record and follow-up, rather than a general claim that the business is now completely protected.
Use the cybersecurity checklist to prepare, then request a discussion about the scope your business needs.

