Practical guideEN051

Small Business Cybersecurity in 30 Days: A Realistic Action Plan

A practical 30-day plan to strengthen your small business cybersecurity using free resources from CISA and NIST, without needing a dedicated IT team.

You can improve your small business cybersecurity in 30 days without a dedicated security team. This plan focuses on the highest-impact actions: enabling multifactor authentication (MFA), updating software, backing up data, and training your team. It relies on free, authoritative guidance from CISA and NIST, and works even if you have little or no existing security measures. You won't eliminate all risk, but you'll greatly reduce common threats like phishing and ransomware. Start with the most critical tasks, and aim for steady progress rather than perfection.

Week 1: Know Your Assets and Risks

Start by listing what you need to protect: devices (laptops, phones, servers), data (customer info, financial records), and accounts (email, cloud services, banking). The NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide says identifying these is the essential first step for managing risk. Also consider your supply chain: if you share data with vendors, include them in your review. CISA offers supply chain guidance for small businesses.

Understand your most likely threats: phishing, ransomware, and credential theft are common for small businesses. CISA's fact sheet 'Keep Your Business Safe' highlights phishing avoidance, passwords, MFA, and software updates as core defenses. You don't need to track every vulnerability; just identify your top risks now.

  • List all hardware, software, and data, noting where each is stored.
  • Identify who has access to sensitive data.
  • Review any existing security policies or backup procedures.
  • Use CISA's fact sheets to educate yourself on phishing and password basics.
Sources and verification date: [2][1]

Week 2: Implement Essential Technical Controls

Enable MFA on all email, cloud, and financial accounts. MFA greatly reduces account takeover risk. CISA recommends using a password manager to create and store strong, unique passwords. Ensure all software and operating systems are set to update automatically; this patches known vulnerabilities. CISA's fact sheet 'Level Up Your Cybersecurity Defenses' covers these next-level practices.

Set up regular backups using the 3-2-1 rule: three copies of data, on two different media, one offsite (like cloud or external drive). CISA lists backups as a key defense. Test your backups to make sure they work. If you use cloud services, consider CISA's free SCuBA tool to assess and harden your configurations.

  • Enable MFA on every account that supports it, prioritizing email and banking.
  • Set up a password manager and encourage team use.
  • Configure all devices to automatically install updates.
  • Implement the 3-2-1 backup strategy and schedule a test restore.
Sources and verification date: [1][2]

Week 3: Train Your People and Establish Policies

Human error is a leading cause of breaches. Train employees to recognize phishing attempts, avoid suspicious links, and report incidents. CISA offers free online training for small businesses, such as protecting data on devices and using password managers. Create a simple cybersecurity policy covering acceptable use, password rules, and incident reporting. CISA's Cyber Guidance for Small Businesses includes steps for creating an incident response plan.

Encourage a culture where employees feel comfortable reporting mistakes quickly. Use CISA's printable fact sheets to reinforce learning. Remind your team that security is everyone's job, not just IT's. This is vital for small teams where each person's actions can have big consequences.

  • Hold a short cybersecurity awareness session using CISA's free resources.
  • Distribute and discuss a one-page acceptable use policy.
  • Establish a clear process for reporting suspicious emails or incidents.
  • Create a simple incident response plan outlining first steps and contacts.
Sources and verification date: [1][2]

Week 4: Review, Harden, and Plan Ahead

In the final week, review what you've implemented and fill gaps. Use CISA's Cross-Sector Cybersecurity Performance Goals to benchmark progress. Consider CISA's no-cost Cyber Hygiene services for vulnerability scanning, if you're U.S.-based. Encrypt sensitive data on devices and in transit using CISA's encryption guidance.

Plan for the long term: cybersecurity is ongoing. Schedule regular reviews, perhaps quarterly. Subscribe to CISA alerts and advisories. If you work with third-party vendors, apply due diligence by checking their security practices; the U.S. International Trade Administration recommends investigating market conditions and partner reputation. Document your plan and lessons learned so you can improve.

  • Run a self-assessment against CISA's Cybersecurity Performance Goals.
  • Request a free vulnerability scan from CISA if you are a U.S. organization.
  • Encrypt laptops, mobiles, and backup drives, and use HTTPS everywhere.
  • Write a 12-month security roadmap with quarterly checkpoints.
Sources and verification date: [1][2][3]

Free Resources to Use Along the Way

You don't need to spend money on expensive tools. CISA's Small and Medium-Sized Business Resources page links to printable fact sheets, online training, and free tools like SCuBA and Logging Made Easy. NIST's Cybersecurity Framework 2.0 Small Business Quick-Start Guide provides a structured risk management approach, even if you have no prior plan.

These U.S. government resources are accessible globally, but some services, like CISA's free vulnerability scanning, may be limited to U.S. organizations. Always verify you're on official .gov sites. Check if your local government offers similar support. CISA and NIST materials are based on international best practices and can be used anywhere.

  • Bookmark CISA's small business resources page for ongoing use.
  • Download the NIST Small Business Quick-Start Guide (SP 1300).
  • Explore CISA's free training videos on password managers and device protection.
  • Check if your region has a similar government-backed cybersecurity program.
Sources and verification date: [1][2]

What to verify

  • This plan is a general guide and does not guarantee protection against all cyber threats.
  • Some CISA services, like free vulnerability scanning, are only available to U.S.-based organizations.
  • Effectiveness depends on consistent implementation and adaptation to your specific risks.
  • Compliance with specific regulations (e.g., GDPR, HIPAA) may require additional measures not covered here.
  • Always verify current guidance and tools on official CISA and NIST websites, as resources may change.

Questions and answers

Do I really need to do all this in 30 days?

The 30-day plan is a tight schedule, but realistic if you prioritize. If you can't complete everything, focus on MFA, software updates, backups, and phishing training. These handle the most common attacks. After 30 days, keep refining. [1][2]

What if I don't have an IT person or team?

This plan is designed for non-technical owners. Use free tools like CISA's SCuBA and Logging Made Easy. Start with basics like password managers and automatic updates. Consider a managed service provider if budget allows. [1]

Are these resources only for U.S. businesses?

CISA and NIST are U.S. agencies, so some services may be U.S.-only. However, the guidance, fact sheets, and frameworks are freely accessible worldwide. Always check your local regulations and consider local authorities' advice. [1][2]

Sources and verification date

  1. Official source: cisa.govcisa.gov · Checked
  2. Official source: csrc.nist.govcsrc.nist.gov · Checked
  3. Official source: trade.govtrade.gov · Checked

Related reading