Enabling multi-factor authentication, deploying a password manager, turning on automatic updates, setting up tested backups, auditing user access, migrating to managed cloud services, and building a one-page incident response plan are the seven controls that eliminate the vast majority of cyber risk for small businesses with no dedicated IT staff. You can start the first four this week, and the rest within 30 days, mostly for free or close to it.
Start here, today:
- Enable MFA on every account (email, banking, cloud apps) — 1–2 hours
- Deploy a password manager (Bitwarden, 1Password, or Keeper) for your whole team — 1–2 days
- Turn on automatic updates for operating systems and all software — under 1 hour
- Set up cloud backups and test a restore using the 3-2-1 rule — 1–2 days
- Audit user accounts and remove access that is no longer needed — half a day
- Migrate email and files to a managed cloud service (Microsoft 365 or Google Workspace) — 1–2 weeks
- Write a one-page incident response plan listing who calls whom and what to do first — 2–3 hours
None of these require a security certification. They do require a few hours of focused attention and a willingness to follow through.
Key takeaways
The single most effective approach to managing cyber risk independently is to implement MFA, a password manager, automatic updates, and tested backups in the first 30 days, then build governance and insurance around those foundations.
| Point | Details |
|---|---|
| MFA is the highest-return first step | Enable it on every account; prefer authenticator apps over SMS codes. |
| Tested backups prevent catastrophic loss | Use the 3-2-1 rule and restore a file monthly to confirm backups actually work. |
| Access audits close the most common gap | Review user accounts quarterly and remove stale or excess permissions immediately. |
| Cloud migration reduces your attack surface | Moving to Microsoft 365 or Google Workspace offloads patching and monitoring to the vendor. |
| AccountNext-Nexus covers what DIY cannot | Managed 24/7 monitoring and incident response for businesses ready to outsource the residual risk. |
Table of Contents
- How to reduce cyber risk without an IT team: setting up each control
- Prioritise with the 80/20 rule: your 30/60/90-day plan
- When to outsource and how to choose a low-cost managed option
- A one-page incident response playbook for non-technical teams
- Official resources and free tools you can use right now
- How to train employees on phishing without a training budget
- Vendor and third-party risk: minimum checks before you sign
- How to delegate cybersecurity tasks without an IT team
- Assess your current security posture before making changes
- Cyber liability insurance: what it covers and whether you need it
- What the numbers rarely tell you about DIY cybersecurity
- AccountNext-Nexus: managed cybersecurity for businesses ready to outsource
- Sources
How to reduce cyber risk without an IT team: setting up each control
Multi-factor authentication
Open the security settings of every cloud service your business uses and look for "Two-step verification," "MFA," or "Sign-in security." Enable it for every account, starting with email and anything connected to banking or payroll. Authenticator apps like Google Authenticator, Microsoft Authenticator, or Authy are stronger than SMS codes because SIM-swapping attacks can intercept text messages. Where a service offers FIDO2 hardware keys (like YubiKey), that is the strongest option available. CISA recommends treating SMS-based MFA as a fallback only, not a primary method.
Password manager
Roll out Bitwarden (free for individuals, low-cost for teams) or 1Password Teams across your staff in a single afternoon. Create a shared vault for credentials the team needs collectively, and give each employee their own vault for personal work logins. The admin console lets you see who has access to what without reading anyone's actual passwords. Require a minimum password length of 16 characters generated by the manager itself — no one needs to remember them.
Automatic updates and patching
On Windows, go to Settings → Windows Update → Advanced Options and enable "Receive updates for other Microsoft products." On macOS, go to System Settings → General → Software Update and tick "Install application updates from the App Store" and "Install security responses and system files." For business software that does not auto-update, set a weekly calendar reminder to check. Moving to cloud-hosted apps (Google Workspace, Microsoft 365, Salesforce) is the most effective single change here because the vendor handles patching entirely.
Pro Tip: Use CISA's Known Exploited Vulnerabilities catalogue to prioritise which patches matter most. If a vulnerability is on that list, patch it before anything else.
Backups using the 3-2-1 rule
Keep three copies of your data, on two different media types, with one copy off-site. In practice for a small business: your primary files live in Microsoft 365 or Google Drive (copy 1), an automated backup runs nightly to a cloud backup service like Backblaze or Acronis (copy 2), and a monthly export goes to an encrypted external drive stored off-site (copy 3). The part most businesses skip is the restore test. Once a month, pick a random file or folder and restore it from the backup copy. If it works, you are covered. If it does not, you find out before a crisis forces the issue. For more on backup methods and testing, the practical guidance on incremental versus image backups is worth reading before you choose a tool.

Least privilege and access audits
Pull a list of every user account in your cloud services. For each one, ask: does this person still work here? Do they need admin rights, or would a standard account do? Remove accounts for departed employees immediately and downgrade any admin account that does not genuinely need that level of access. Create a separate admin account used only for administrative tasks, and log in with a standard account for daily work. This takes half a day the first time and about 30 minutes per quarter to maintain.
Endpoint protection and simple monitoring
Windows Defender, built into Windows 10 and 11, is genuinely adequate for most small businesses when kept updated. On macOS, Malwarebytes Free handles the gaps the built-in XProtect misses. For a step up, Malwarebytes for Teams or Bitdefender GravityZone Small Business runs under $5 per device per month. In your cloud service dashboards (Microsoft 365 Admin Centre, Google Admin Console), turn on login alerts for unusual sign-in locations and failed login attempts. These alerts are free and catch credential-stuffing attacks early.
Prioritise with the 80/20 rule: your 30/60/90-day plan
Lean IT risk management recommends scoring your risks by impact and likelihood, then focusing effort on the top 20% of risks that create roughly 80% of your exposure. Everything else is secondary until those four are solid.
Days 1–30 (high impact, low cost, do these yourself):
- Enable MFA on all cloud accounts — 2 hours, free
- Deploy a password manager for the whole team — a few hours setup, low monthly cost per user
- Enable automatic updates on all devices and move to cloud-hosted apps — 2 hours, included in existing subscriptions
- Set up cloud backups and run your first restore test — 4 hours, $7–$10 per month for Backblaze or similar
- Run a user access audit and remove stale or excess accounts — a few hours, free
Days 31–60 (moderate effort, delegate to a trusted staff member):
- Migrate email and file storage to Microsoft 365 or Google Workspace if not already there — 1–2 weeks, $6–$22 per user per month
- Write and distribute a one-page incident response plan — a few hours, free
- Run a phishing simulation using KnowBe4 Free or Google's Phishing Quiz — 2 hours, free to low-cost
- Review vendor contracts for basic security requirements — a few hours, free
Days 61–90 (governance and insurance):
- Obtain or review a cyber liability insurance policy — 2–4 hours, $500–$2,000 per year depending on revenue and industry
- Use CISA's free vulnerability scanning to identify unpatched systems — 2 hours, free
- Schedule a quarterly access audit and backup test as recurring calendar events — 30 minutes, free
Non-technical staff can handle items 1–5 and 7–8 with written instructions. Items 6 and 11 benefit from a brief consultation with a managed service provider if the migration feels complex.
When to outsource and how to choose a low-cost managed option
Three tiers exist, and the right one depends on your budget and risk tolerance.
Tier 1: Per-task contractors. Hire a freelance IT consultant for a one-time migration, a security audit, or a firewall configuration. Cost is $75–$200 per hour. Good for discrete projects; not a substitute for ongoing monitoring.
Tier 2: Limited managed services. A managed service provider (MSP) handles patching, endpoint monitoring, and backup management for a fixed monthly fee, typically $50–$150 per device. You keep day-to-day operations; they handle the repetitive technical work. This is the right tier for most small businesses once the 30-day basics are in place.
Tier 3: Full managed security (MSSP). Covers 24/7 threat detection, incident response, compliance, and vulnerability management. Costs more, but eliminates the need for any internal security function. Worth it when you handle sensitive customer data, operate in a regulated industry, or have experienced a prior incident.
Questions to ask any provider before signing:
- What is your guaranteed response time for a security incident (SLA)?
- Do you carry cyber liability insurance yourself?
- How do you report to us, and how often?
- What are the exit terms if we want to leave?
- Do your technicians use shared admin accounts across clients? (The answer should be no.)
Red flags: vague SLAs, no written incident response process, shared credentials across clients, and pricing that changes without notice. If a provider cannot answer the SLA question in one sentence, keep looking. For a fuller picture of the benefits of managed security services before committing to a tier, that comparison is worth 10 minutes.
A one-page incident response playbook for non-technical teams
When something goes wrong, the first 30 minutes determine whether a bad day becomes a catastrophic week. Print this and post it somewhere visible.
Immediate containment (first 30 minutes):
- Disconnect the affected device from the network (unplug the ethernet cable or turn off Wi-Fi). Do not turn the device off.
- Revoke or change credentials for any account the affected device had access to.
- Do not delete files or attempt repairs — preserve the state for investigation.
- Notify your designated internal lead (name and phone number go here).
Who to call:
- Your managed service provider or IT contact (name and emergency number go here).
- Report to CISA at 1-888-282-0870 or via their online reporting form.
- Your cyber insurance carrier — call before you spend money on remediation.
- Notify affected customers only after you understand the scope; premature notification creates confusion.
Post-incident recovery:
- Restore data from your most recent clean backup — confirm the backup predates the incident.
- Audit all user accounts and reset credentials across the board.
- Run a lessons-learned review within 72 hours: what happened, how it spread, and what control would have stopped it.
- Update your incident response plan based on what you learned.
For a more detailed incident response checklist with testing cadences, that guide walks through tabletop exercises a non-technical team can run in under an hour.
Official resources and free tools you can use right now
The FTC's cybersecurity guidance for small businesses covers training, backups, patching, and access control in plain language, and points directly to NIST CSF 2.0 as a voluntary framework any business can adopt without a security team. The SBA's cybersecurity planning tools include sector-agnostic checklists and reinforce that no business is too small to be a target.
How to train employees on phishing without a training budget
Phishing causes the majority of small-business breaches, and training does not require a paid platform to be effective. Google's Phishing Quiz takes five minutes and teaches staff to spot the visual cues attackers use. KnowBe4 offers a free tier with basic phishing simulations you can send to your team. Run one simulation per quarter, review who clicked, and follow up with a brief conversation rather than public shaming — the goal is awareness, not punishment.
Establish one clear reporting channel. A dedicated email address like security@yourdomain.com or a Slack channel called #report-suspicious gives staff a low-friction way to flag something odd. Acknowledge every report, even false alarms, because the cost of ignoring a real threat far exceeds the cost of investigating a false one. For a deeper look at common employee cybersecurity vulnerabilities and how to track training participation, that guide covers the patterns that show up most often in small-business environments.
Vendor and third-party risk: minimum checks before you sign
Every vendor with access to your systems or data is a potential entry point. Before granting access, ask three questions: Do they have a written security policy? Do they encrypt data in transit and at rest? Have they had a breach in the last two years, and if so, how did they handle it?
In contracts, require vendors to notify you within 72 hours of any security incident affecting your data, maintain their own cyber liability insurance, and agree to your right to audit or request a SOC 2 report. Remove vendor access immediately when a project ends. For a structured overview of third-party cybersecurity risk types, that guide covers the vendor categories that carry the highest exposure for small businesses.
How to delegate cybersecurity tasks without an IT team
Assign one person as your "security owner" — not a technical role, just someone responsible for checking that the basics are done. Their job is to run the monthly backup restore test, review the user access list quarterly, confirm that updates are current, and be the first call when something looks wrong. Rotate the role annually so knowledge spreads across the team.

Create a one-page security checklist posted in a shared drive. Weekly: confirm backups ran. Monthly: test a restore, review login alerts. Quarterly: audit user accounts, run a phishing simulation. Annually: review your incident response plan and cyber insurance policy. Written checklists turn security from an abstract concern into a concrete task with a checkbox.
Assess your current security posture before making changes
Before adding new tools, spend 30 minutes answering these questions honestly. The gaps you find here are your priority list.
- Do all accounts use MFA? (Yes / No / Partial)
- Does every employee use a password manager? (Yes / No / Partial)
- Are all devices set to auto-update? (Yes / No / Partial)
- Do you have backups, and have you tested a restore in the last 30 days? (Yes / No)
- Have you audited user accounts in the last 90 days? (Yes / No)
- Do you have a written incident response plan? (Yes / No)
- Do you have cyber liability insurance? (Yes / No)
- Have you reviewed vendor contracts for security requirements? (Yes / No)
Any "No" answer is a gap to close. Any "Partial" answer is a gap to finish. A free security audit checklist walks through this assessment in more detail and helps you score your current posture before deciding where to spend time or money.
Cyber liability insurance: what it covers and whether you need it
Cyber liability insurance covers costs that arise from a breach: notification expenses, legal fees, regulatory fines, ransomware payments (in some policies), and business interruption losses. Premiums for small businesses typically run $500–$2,000 per year depending on revenue, industry, and the controls you already have in place. Insurers ask about MFA, backups, and patch management during underwriting — having those controls in place lowers your premium and increases the likelihood of a claim being paid.
A policy does not replace controls; it covers the residual risk after controls are in place. If you handle customer payment data, health information, or operate in a regulated industry, cyber insurance is not optional. For everyone else, it is a low-cost safety net worth the annual premium once the 30-day basics are complete.
What the numbers rarely tell you about DIY cybersecurity
The standard advice is correct: MFA, backups, patching, and a password manager stop the overwhelming majority of attacks on small businesses. What the checklists understate is the execution gap. Most breaches at small businesses happen not because the owner did not know about MFA, but because they enabled it on their own account and forgot to require it for the three contractors who also have admin access to the cloud environment.
The controls are simple. The discipline of applying them consistently, to every account, every vendor, and every new hire, is where most businesses fall short. A quarterly 30-minute review of who has access to what, and whether every account has MFA enabled, catches the gaps that attackers exploit. That review does not require a security team. It requires a calendar reminder and someone willing to follow through.
The other underrated move: migrating on-premises mail and file systems to Microsoft 365 or Google Workspace. CISA identifies this as one of the highest-impact single changes a small business can make, because it offloads patching, monitoring, and secure default configurations to a vendor with a full security team. You are not outsourcing your security; you are buying a platform where security is already built in.
AccountNext-Nexus: managed cybersecurity for businesses ready to outsource
For businesses that have worked through the 30-day basics and want a professional layer on top, AccountNext-Nexus provides 24/7 threat detection and managed IT services without the cost of an in-house security team. The model is straightforward: real-time monitoring, incident response on retainer, vulnerability management, and compliance support under a single fixed-fee contract.

Onboarding for a small business typically takes two to four weeks. In the first 30 days, the team conducts a baseline security assessment, closes the most critical gaps, and establishes monitoring and alerting. By day 60, you have documented policies, tested backups, and a named incident response contact available around the clock. Pricing is transparent and contract terms are clear, including exit terms. To find out what a managed engagement looks like for your business, book a discovery call with the AccountNext-Nexus team.
