Book a Call
Security and Data Protection

A practical small business cybersecurity checklist for teams that run on cloud tools: MFA, access reviews, backups, offboarding and sensible rules for AI.

Small business cybersecurity checklist showing MFA, access reviews, backups and staff offboarding for cloud tools

Most small business cybersecurity problems do not start with a clever attacker. They start with a reused password, a former employee who still has access to the shared drive, or a backup nobody has tested in two years.

If your business runs on cloud tools such as Microsoft 365, Google Workspace, an accounting package and a CRM, the basics below will close most of the common gaps. This guide is written for owners and operations managers, not IT specialists. It covers what to do first, how to keep it going, and where AI tools now fit into the picture.

Why cloud tools change the security picture

Moving to the cloud removed a lot of old risks. You no longer worry about a server in a cupboard failing or a tape backup going missing. The provider looks after the data centre, the hardware and much of the software patching.

What the provider does not look after is who can log in, what they can see, and what happens to your data once it leaves their platform. That part is yours. Most cloud providers describe this as a shared responsibility model, and it is worth reading the short version for each tool you rely on.

In practice, that means your security now depends far more on accounts and permissions than on firewalls. A single compromised email login can open the door to files, invoices, client lists and password reset links for everything else.

The small business cybersecurity checklist

These are the controls we would put in place first for a business of roughly 10 to 200 people. None of them need specialist software. Most are settings you already pay for.

01

Turn on multi-factor authentication everywhere

Multi-factor authentication (MFA) means a password alone is not enough to log in. Start with email, because email is the reset route for everything else. Then cover your file storage, finance tools, CRM, website admin and any remote access.

Authenticator apps or hardware security keys are stronger than text message codes. Text codes are still far better than nothing, so do not let the perfect option delay the good one.

02

Give each person their own account

Shared logins such as office@ or a single admin account used by three people make it impossible to see who did what, and impossible to remove one person cleanly. Give every person a named account. Where a shared mailbox is genuinely needed, grant access to it from individual accounts rather than sharing a password.

03

Use a password manager for the team

A business password manager lets staff use long, unique passwords without writing them down. It also lets you share the few credentials that must be shared, such as a supplier portal, without pasting them into chat. When someone leaves, you can see exactly what they had access to.

04

Keep admin rights to a small group

Most people do not need admin rights in Microsoft 365, Google Workspace or your accounting software. Keep a short list of administrators, give them separate admin accounts if your platform supports it, and protect those accounts with the strongest MFA you have.

05

Keep devices updated and locked

Turn on automatic updates for operating systems and browsers. Require a screen lock and disk encryption on laptops and phones that hold business data. If staff use personal phones for email, most platforms let you protect business data on that phone without managing the whole device.

06

Back up the data you cannot afford to lose

Cloud tools are not automatically backed up in the way most people assume. Deleted files and emails are usually kept for a limited period, and a ransomware infection on a synced laptop can overwrite cloud copies too. A separate backup of email, files and key business systems gives you a way back.

Access reviews: the control most businesses skip

Permissions grow quietly. Someone needs a folder for one project and keeps access for years. A contractor gets an account and nobody turns it off. An integration is connected with full access because that was the default option.

A simple access review fixes this. Once a quarter, or at least twice a year, go through each important system and ask three questions:

  • Who has an account, and do they still work here or with us?
  • Who has admin or finance permissions, and do they still need them?
  • Which third party apps and integrations are connected, and do we still use them?

Write down what you checked and what you changed. It takes an afternoon the first time and much less after that. It also gives you something concrete to show if a client or insurer asks how you manage access.

Pay particular attention to shared folders and links. A link set to anyone with the link can be forwarded far beyond the people you meant to share it with. Most platforms can produce a report of externally shared files.

Offboarding: closing the door when people leave

Offboarding is where small businesses most often leave gaps, usually because it happens on someone's last busy day. A written checklist makes it routine. Ours usually looks like this:

  1. Disable the main account on the day the person leaves, not a week later.
  2. Sign them out of all sessions and remove their devices from your management tools.
  3. Remove them from the password manager and change any shared credentials they knew.
  4. Transfer ownership of their files, calendars and mailbox to a manager before anything is deleted.
  5. Remove access to finance tools, banking, the CRM, website admin and supplier portals.
  6. Revoke any API keys or integrations they set up under their own account.
  7. Collect company devices and wipe or reassign them.

The same list in reverse works for onboarding. If new starters get access through a defined process, it becomes much easier to remove it later. Some businesses track this in a simple internal tool rather than a spreadsheet, which we cover in our guide to why growing businesses need better internal tools.

Backups you have actually tested

A backup you have never restored is a hope, not a plan. Decide what you would need to keep trading if a system disappeared tomorrow: client records, invoices, contracts, project files, email. Then check how each one is protected.

Good backups for a small business usually have these features:

  • Separate from the source. Stored with a different provider or in a separate account, so one compromised login cannot delete both.
  • Versioned. You can go back to a copy from before a problem started, not just yesterday's copy.
  • Automatic. Nobody has to remember to run them.
  • Tested. At least twice a year, restore a real file or mailbox and time how long it takes.

Do not forget data that lives outside the obvious places. Custom databases, website content and older spreadsheets that still run part of the business often fall through the gaps. If key records are scattered across files, our data migration and management work often starts by finding out where everything actually lives.

Phishing is still the most common way in

Most account takeovers begin with a convincing email or text asking someone to log in, approve a payment or change bank details. Agree a simple rule: any request to change payment details or send money is confirmed by phone using a number you already hold, never one from the message.

AI tools and your business data

AI assistants are now built into email, documents and meeting software, and staff are using standalone chat tools as well. This is useful, and it also creates a new question: where does your data go when someone pastes it in?

A few practical steps cover most of the risk:

  • Know which tools are in use. Ask the team. You will probably find more than you expected.
  • Prefer business plans. Business and enterprise versions of AI tools usually give you clearer terms about whether your data is used for training, plus admin controls. Check the terms for each tool rather than assuming.
  • Set clear rules on sensitive data. Client personal data, health information, financial details and anything under a confidentiality agreement need explicit guidance.
  • Watch connected AI apps. AI add-ons that ask to read your whole mailbox or drive deserve the same scrutiny as any other integration.

A short written AI usage policy helps staff use these tools with confidence instead of guessing. When AI is built into your own systems, the same principles apply at the design stage: limit what data the AI can see, log what it does and keep people approving anything important. That is how we approach AI solutions and automation projects.

If you run custom software or a client portal

Off the shelf cloud tools handle a lot of security for you. Custom software, internal tools and client portals put more of it in your hands, or in the hands of whoever built them. Questions worth asking your developer or supplier:

  • Who is responsible for security updates to the code and its dependencies?
  • Does it support MFA and individual accounts with role based permissions?
  • Where is data hosted, how is it encrypted and how is it backed up?
  • Is there an audit log of who viewed or changed records?
  • Who holds the admin credentials and the hosting account, and do you own them?

If those answers are vague, that is worth fixing before it becomes urgent. Our security and data protection service covers reviews like this, and ongoing patching and monitoring sit under DevOps, security and maintenance. For context on how connected systems share data, see how software integrations connect business systems.

Common mistakes to avoid

  • Turning on MFA for staff but leaving the admin or owner account without it.
  • Keeping a former employee's account active "just in case" someone needs their emails.
  • Assuming the cloud provider keeps full backups of everything indefinitely.
  • Approving integrations with full access because it was quicker than reading the permissions.
  • Treating security as a one off project rather than a short routine that repeats.

Security frameworks published by national cyber security agencies are a good free reference if you want to go further. Many have small business guides written in plain language.

Questions and answers

What should a small business do first for cybersecurity?

Turn on multi-factor authentication for email and every admin account, then remove accounts belonging to people who have left. Those two steps close the gaps behind a large share of common account takeovers.

Do we need backups if everything is in the cloud?

Usually, yes. Cloud platforms protect against hardware failure, but deleted or encrypted data is often only recoverable for a limited period. A separate, versioned backup gives you a way back from mistakes, ransomware and account compromise.

How often should we review who has access to our systems?

Quarterly is a sensible target for important systems such as email, file storage, finance and your CRM. Twice a year is the minimum. Also review access whenever someone changes role or leaves.

Is it safe for staff to use AI tools with company data?

It can be, with the right tools and rules. Use business plans with clear data terms, decide which types of data must never be pasted in, and review AI apps that request access to your mailbox or files.

Do small businesses need a dedicated IT security person?

Not always. Many businesses of this size assign security ownership to an operations lead and bring in outside help for reviews, custom systems and incidents. What matters is that someone is clearly responsible.

Where to start this week

Pick one hour this week. Check MFA on email and admin accounts, then list everyone with access to your finance tools and remove anyone who should not be there. Book the first access review in the calendar so it actually happens.

None of this is complicated, and it does not need to be perfect on day one. A business that does these basics consistently is a much harder target than one with expensive tools and no routine.