Small-business cybersecurity becomes easier to discuss when it is connected to specific work. Start with the accounts that control the business, the devices used to reach them and the information that would be difficult to replace. Then assign responsibility for maintaining those arrangements and responding when something looks wrong.

Know what the office depends on
Make an inventory of business applications, work devices and the accounts used to administer them. Include subscriptions created for a short project and equipment kept for an occasional task. A system that is rarely used can still hold business information or provide access to another service.
For each item, record an internal owner and a review question. Who still needs this account? Is this device receiving supported updates? Does this application contain information that should have been removed? A list that answers these questions is more useful than an equipment count without responsibilities.
Give accounts clear owners and limits
Use individual accounts for routine work where the application supports them. Keep administrative access separate from ordinary work, and record how emergency access can be recovered. Review multi-factor authentication settings for business accounts, including the method used when a person replaces a phone or loses a sign-in device.
A password manager can help organize unique credentials, but its own ownership and recovery arrangements need attention. Decide how shared business credentials are granted and withdrawn. Do not make the whole office dependent on a personal account whose recovery method belongs to someone who may leave.
- Identify who can approve access to each important application.
- Document the steps for a new starter, a role change and a departure.
- Review old accounts and temporary permissions on a stated schedule.
- Keep a record of exceptional access and its intended end date.
Make device upkeep a visible routine
Assign responsibility for operating-system updates, application updates and endpoint protection. Record equipment that cannot follow the normal process, with the reason and the person deciding what happens next. A device used for a specialist instrument may need coordination with the application's owner before a change; that is a reason for a documented plan.
Choose a routine for checking unsuccessful updates and devices that have stopped reporting. Avoid assuming that a setting means a task completed. Ask what evidence would show the difference between a device waiting for a restart and a device that has been disconnected for months.
Write a simple response to an unusual request
A message that asks for a password, urgent payment or an unexpected change deserves a separate verification step. Give staff a familiar way to raise the question without using the details supplied in the suspicious message. The office procedure should identify which internal role can pause a payment or review an account alert.
Use a practice scenario: an apparently familiar sender asks for a bank-detail change during a busy afternoon. Ask where the request would be checked, who can authorize it and what record would be kept. The purpose is to expose uncertainty in the process before a real decision has to be made.
Prepare for a lost device or compromised account
Write down who coordinates the response, who can disable account access and where recovery instructions are stored. Keep a usable copy of essential procedures outside the system they describe. If the only response document is in an account that cannot be opened, it will be difficult to use at the moment it is needed.
Separate restoring ordinary work from deciding whether an incident requires specialist investigation or legal advice. Record known facts, affected systems, decisions and times; avoid guessing about the cause. The recovery guide explains how to prepare usable restoration exercises.
Use official guidance to deepen the review
The FTC small-business cybersecurity materials provide further education. The NIST small-business resource collection is another starting point; CISA also publishes public security guidance. For implementation questions, connect this review to the network boundary checklist and the responsibilities in an ongoing support arrangement.