Ayliea Awareness Series · CAM-2026-04
Small Business Cybersecurity Checklist
Twelve foundational controls to review during Cybersecurity Awareness Month. Use this for prioritization—not as a certification or formal maturity score.
Identity
- MFA is required for email, administrator, cloud, financial, and remote-access accounts.
- Users have unique accounts; shared credentials are eliminated or tightly controlled.
Passwords
A password manager is available and password reuse is prohibited.
Patching
Operating systems, browsers, applications, network devices, and security tools have an update process.
Backups
Critical data is backed up and at least one restoration test has been completed recently.
Employees know how to report suspicious messages; sensitive requests are verified out of band.
Access
Access to sensitive systems and data follows least privilege and is reviewed when roles change.
Vendors
Third-party and contractor access is documented, limited, and removed when no longer needed.
Incident response
The organization has named contacts, escalation steps, and a basic plan for security incidents.
AI use
Approved AI tools and prohibited/restricted data types are documented.
Training
Security awareness is recurring and includes current phishing/social-engineering examples.
Recovery
Leadership knows which systems are most critical and how operations continue during disruption.