Active Incident? 24/7 Response →
Witness

For Small Business

Small Business Cybersecurity Checklist (Under 50 Employees)

Most small business cybersecurity guides are vendor checklists in disguise. This one is what we actually tell clients to do, in priority order.

All articles·10 min read·April 22, 2026

The order matters more than the list

Most small-business cybersecurity advice is a giant pile of equally-weighted bullets, and the result is that owners do nothing. Below is what to actually do, in the order that moves the security needle the most for the least money. If you do steps 1-5 and stop, you will be ahead of 80% of small businesses your size.

1. Identity, before anything else

2. Email — the attack surface that pays attackers the most

3. Endpoints — workstations and laptops

4. Backups

5. People

6. The legal/insurance layer (do this before incident, not during)

What you can ignore for now

If you'd rather buy this as a service

We deliver this checklist (and the ongoing operations behind it) as managed cybersecurity for SMB clients, with a vCISO as the leadership layer when the program starts pushing past 30 employees.


Related services

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded Witness in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Small-business cybersecurity: frequent questions

Certified Expertise

GIAC · AWS · Splunk · CompTIA

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management