ADAM PULSE Knowledge Base
Security · Small Business · MFA · Backups · NIST · CISA

Five inexpensive things you can do today to make your business much harder to hack

Short answer

The five cheapest improvements available to most businesses are:

  1. Turn on multi-factor authentication, starting with email, banking, your identity provider and every administrator account.
  2. Give every person their own account, stop sharing logins, and take administrator rights off ordinary user machines.
  3. Turn on automatic updates for everything — including the firewall, the access points, the printer and the website.
  4. Back up what matters, keep a copy offline, and test a real restore.
  5. Secure the company's public identity — domain registrar, DNS, website, social accounts and email sending domain.

None of them requires buying a security product. All of them are things you already own, configured properly.

<div class="callout"><span class="callout-label">Before you buy anything</span><p>Cybersecurity does not have to start with an expensive product. For most small and midsized businesses the highest-value improvements are configuration changes to technology already in the building. None of these eliminates risk. Together they remove several of the openings attackers rely on most.</p></div>

One warning before the detail. Some very widely repeated advice in this area is now formally contradicted by NIST's own current guidance — in particular "change your password every 90 days" and "require a mix of letters, numbers and symbols." Both are now things NIST says you SHALL NOT do. If your policy still requires them, that section is worth reading carefully.

1. Turn on multi-factor authentication

Cost: usually nothing. It is already included in services you pay for.

What is the single cheapest cybersecurity improvement?

Enabling MFA on the accounts that matter. NIST puts it plainly in its small business quick-start guide:

Enabling multi-factor authentication (MFA) is one of the fastest, cheapest ways you can protect your data. Start with accounts that can access the most sensitive information.

Which accounts should get MFA first?

Do not try to do everything at once. NIST's own priority list for a small business is:

CISA adds the one people forget: every system administrator account. Its guidance for small businesses is blunt about how to do it — "Ensure MFA is mandated using technical controls, not faith." A policy that asks people to turn MFA on is not a control. A setting that requires it is.

Is SMS-based MFA good enough?

This deserves a careful answer, because both extreme positions are wrong.

SMS codes are far better than no MFA. Do not let anyone talk you out of enabling MFA because they read that SMS is weak.

But SMS is officially the weakest tier, and you should plan to move off it. CISA's phishing-resistant MFA fact sheet describes SMS and voice one-time passcodes as "Vulnerable to phishing, SS7, and SIM swap attacks" and says this form "should only be used as a last resort MFA option." NIST's current authentication guidance goes further and classifies out-of-band authentication over the phone network as the guidelines' single restricted authenticator.

The better options, in order:

Do not forget the domain registrar

Businesses think hard about Microsoft 365 and forget entirely about the account that controls their domain name and DNS. That account can redirect your website and your email. It deserves the same protection as your email tenant, and it frequently has none.

2. Give everyone their own account

Cost: nothing to very little.

Should employees share passwords?

No — and the argument that lands with business owners is not a security argument, it is an accountability one.

An office@company.com login known by eight people cannot tell you who did anything. Audit logs become useless, offboarding becomes impossible, and one departure means changing a password that eight people need.

Should every employee have their own account?

Yes, wherever the platform allows it. Then:

What does current password guidance actually say?

This is the part most policies get wrong, and it changed formally in 2025.

NIST's authentication guidance was revised and finalised on 31 July 2025. The previous version was withdrawn on 1 August 2025. The current requirements include:

Those are requirement-level statements, not preferences. If your written policy still mandates 90-day rotation and a symbol, it is now contrary to the standard it probably cites.

The reasoning is straightforward: forced rotation and composition rules push people toward predictable transformations. Password1 becomes Password2.

Should employees be local administrators on their computers?

Generally no. CISA's guidance for small businesses says it in four words: "Remove administrator privileges from user laptops."

Its performance goals go further on separation of duties: "No user accounts always have administrator or super-user privileges. Administrators maintain separate user accounts for all actions and activities not associated with the administrator role."

In practice that means an administrator has two accounts — one for administering, one for reading email.

What should happen when someone leaves?

CISA's benchmark is stricter than most businesses realise. Its performance goal requires a defined, enforced process applied to all departing employees by the day of their departure, revoking physical access and disabling all user accounts and access to organisational resources.

Not "within a week." Not "when IT gets to it." The day they leave.

A written offboarding checklist should at minimum cover: email, VPN, Microsoft 365 or Google Workspace, CRM, Zoom or your phone system, firewall administration, the password manager, social accounts, the website, cloud storage and financial applications.

3. Turn on automatic updates for everything

Cost: usually nothing.

What devices does a small business need to keep patched?

Anything connected to the network or the internet. People hear "software updates" and think Windows. The real list is longer:

Laptops, phones, browsers, Microsoft 365 or Google Workspace applications, the firewall, wireless access points, the router, VPN appliances, the website CMS and its plugins, network-attached storage, cameras, and printers.

Your five-year-old network printer, the forgotten access point above the ceiling tile, and the WordPress plugin nobody has touched since installation are all still software, and all still reachable.

How urgent is patching, really?

CISA's small business guidance frames it in terms of what a vulnerability gives away — access to files or accounts — and recommends installing updates promptly. The practical version for a small business: turn automatic updates on wherever the platform supports it, and put a recurring calendar reminder against the handful of devices that cannot update themselves.

4. Back up the business, and test the backup

Cost: usually modest against the value of the data.

If everything is in Microsoft 365 or Google Workspace, do we still need backups?

This is the question worth teaching people to answer for themselves rather than giving a flat yes or no. Separate five different things:

Cloud storage gives you the first four to varying degrees. Whether you need the fifth depends on your recovery requirements — and on the scenario where the thing you are recovering from is an account compromise or a malicious deletion inside the tenant.

What should we actually back up?

Customer records, accounting data, contracts, CRM data, the Microsoft 365 or Google Workspace estate, the website, configuration files, firewall and network device configurations, employee files, and databases.

That last-but-one is the one people miss. Firewall and switch configurations are rarely backed up and are painful to rebuild from memory at two in the morning.

What does the guidance say about how to hold backups?

The joint federal ransomware guidance is specific:

Maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of backups in a disaster recovery scenario.

And on why offline matters: "many ransomware variants attempt to find and subsequently delete or encrypt accessible backups to make restoration impossible unless the ransom is paid."

On immutable cloud storage, the same guidance is more cautious than most vendors are: use it "with caution as it does not meet compliance criteria for certain regulations and misconfiguration can impose significant cost."

Note that the "3-2-1 rule", widely attributed to CISA, does not appear in that guidance. The actual requirement is offline, encrypted, stored separately from the source systems, and tested.

How often should backups be tested?

CISA's performance goal sets a floor of at least once a year for both backup and restore testing. Treat that as a floor rather than a target. The useful question is not "do we have backups" but:

If nobody can answer the last one, you do not know whether you have backups. You know you have backup jobs.

5. Secure the company's public identity

Cost: mostly nothing.

This is the one that differentiates a real answer from a generic listicle. Cybersecurity is not confined to the office network.

What counts as the company's digital identity?

These deserve the same discipline as the internal network: MFA enabled, ownership documented, former employees removed, administrators limited, website software patched, DNS reviewed, domain expiry monitored, email authentication configured, and a clear answer to who controls each one.

The question to ask in the next management meeting

If our web developer disappeared tomorrow, could we still access our domain, DNS, website and hosting?

If the answer is no, that is not only a security problem. It is a business continuity problem, and it is one of the most common single points of failure in a small business.

The same question applies to the person who set up the social accounts, and to whoever registered the domain in their own name a decade ago.

The fifteen-minute business cybersecurity check

Answerable without any tooling. If you cannot answer one of these, that is where to start.

Where this guidance comes from

Two things worth knowing about the source material, because the landscape moved recently.

NIST's flagship small-business document is now SP 1300, the Cybersecurity Framework 2.0 Small Business Quick-Start Guide, published February 2024. The older NISTIR 7621 is still published but dates from 2016 and should not be presented as current best practice. NIST also has a 2026 draft aimed specifically at owner-only firms.

CISA's current front door for small business is Secure Our World, with its "Secure Your Business" page, and a deeper technical companion in Cyber Guidance for Small Businesses. The Cyber Essentials material that still circulates dates from 2019.

Frequently asked questions

What are five inexpensive ways to improve a company's cybersecurity?

Turn on multi-factor authentication starting with email, banking, your identity provider and all administrator accounts; give every person their own account and remove administrator rights from ordinary laptops; turn on automatic updates for everything including network equipment and the website; back up critical data with an offline copy and test a real restore; and secure the company's public identity including the domain registrar, DNS, website and social accounts. None requires buying a security product.

What is the first cybersecurity improvement a small business should make?

Multi-factor authentication on the accounts holding the most sensitive information. NIST describes enabling MFA as one of the fastest and cheapest ways to protect business data and advises starting with the accounts that can access the most sensitive information.

Which business accounts should have MFA first?

NIST's small business list is banking, accounting and tax, merchant accounts, your Google, Microsoft or Apple ID account, email, password managers and website accounts. CISA adds every system administrator account, and says MFA should be mandated using technical controls rather than relying on people to enable it themselves.

Is SMS multi-factor authentication good enough?

It is much better than no MFA, so never let SMS scepticism stop you enabling it. But it is the weakest tier. CISA describes SMS and voice one-time passcodes as vulnerable to phishing, SS7 and SIM-swap attacks and says the method should only be used as a last resort. NIST's current guidance classifies out-of-band authentication over the phone network as a restricted authenticator. Prefer passkeys or FIDO2 security keys, then an authenticator app with number matching.

Should employees share passwords?

No. Beyond the security exposure, a shared login destroys accountability: audit logs cannot attribute activity, offboarding becomes impossible, and one person leaving forces a password change on everyone who used it.

How often should business passwords be changed?

They should not be changed on a schedule. NIST's current authentication guidance, finalised on 31 July 2025, states that verifiers shall not require users to change passwords periodically. A change is forced only where there is evidence the password has been compromised. The previous version of that guidance was withdrawn on 1 August 2025.

Should passwords require a mix of letters, numbers and symbols?

No. NIST's current guidance states that verifiers shall not impose composition rules such as requiring mixtures of different character types. The rationale is that such rules push people toward predictable transformations. Length matters more: the current minimum is 15 characters for a password used on its own, with support for at least 64 so passphrases work.

Should employees have administrator privileges on their computers?

Generally no. CISA's guidance for small businesses says to remove administrator privileges from user laptops, and its performance goals state that no user account should always hold administrator or super-user privileges. Administrators should hold a separate ordinary account for work not requiring those rights.

What accounts should be disabled when an employee leaves?

All of them, and CISA's benchmark is that it happens by the day of departure through a defined and enforced process. A practical checklist covers email, VPN, Microsoft 365 or Google Workspace, CRM, the phone system, firewall administration, the password manager, social accounts, the website, cloud storage and financial applications.

What devices should a small business keep patched?

Anything connected to the network or the internet. That includes laptops and phones, but also the firewall, wireless access points, the router, VPN appliances, the website CMS and its plugins, network storage, cameras and printers. An old network printer or a forgotten access point is still software and still reachable.

Does a small business need backups if everything is in Microsoft 365 or Google Workspace?

It depends on your recovery requirements, and the useful approach is to separate five things: availability, retention, versioning, recycle-bin recovery and an independent backup. Cloud storage provides the first four to varying degrees. The scenario that argues for the fifth is one where the thing you are recovering from is an account compromise or a malicious deletion inside the tenant.

How should backups be stored?

Federal ransomware guidance calls for offline, encrypted backups of critical data, stored separately from the source systems, with regular testing of availability and integrity. Offline matters because many ransomware variants specifically seek out and delete or encrypt reachable backups. Immutable cloud storage is an option but the same guidance advises caution, noting it does not meet compliance criteria for certain regulations and that misconfiguration can be costly.

How often should a company test its backups?

CISA's performance goals set a floor of at least once a year for testing both backups and restores. Treat that as a floor. The question that matters is when you last completed a successful restore, not whether backup jobs are running.

Does CISA recommend the 3-2-1 backup rule?

That phrase does not appear in the joint federal ransomware guidance. What the guidance actually calls for is offline, encrypted backups, stored separately from source systems and tested regularly. Attribute the specific wording rather than the popular shorthand.

What should a small business back up?

Customer records, accounting data, contracts, CRM data, the Microsoft 365 or Google Workspace estate, the website, configuration files, firewall and network device configurations, employee files and databases. Network device configurations are the commonly missed item and are painful to rebuild from memory during an outage.

How do you protect a company's domain name?

Treat the registrar account as critical infrastructure. Enable multi-factor authentication on it, document who owns it, ensure more than one person can get in, monitor the expiry date, and review DNS records. Businesses routinely secure Microsoft 365 while leaving unprotected the account that can redirect both their website and their email.

What is the most common cybersecurity mistake small businesses make?

Treating cybersecurity as a product to buy rather than a set of configuration decisions in technology they already own. The runner-up is forgetting that the company's public identity, meaning the domain, DNS, website and social accounts, needs the same discipline as the internal network.

What cybersecurity can a company implement without buying new software?

All five items in this article. Multi-factor authentication, individual accounts and least privilege, automatic updates, backup testing, and securing the public digital identity are configuration changes to services and equipment already in place.

What is least privilege?

The principle that each account has only the access needed for its typical tasks, and no more. In practice for a small business it means removing administrator rights from ordinary laptops, giving administrators a second everyday account, and periodically reviewing who still needs access to what.

Is NISTIR 7621 still current guidance for small businesses?

It remains published but dates from November 2016 and is no longer NIST's flagship small business document. The current one is NIST SP 1300, the Cybersecurity Framework 2.0 Small Business Quick-Start Guide, published February 2024. NIST also has a 2026 draft aimed specifically at owner-only firms.

References

NIST and CISA only, and current editions. Where this article contradicts widely repeated advice — password rotation in particular — the reference is the document that supersedes it.

  1. NIST SP 1300 — Cybersecurity Framework 2.0 Small Business Quick-Start Guide— February 2024, NIST's current flagship small business publication. Source for the MFA priority list and the backup and default-password recommendations.
  2. NIST — Small Business Cybersecurity Corner— the hub, including quick-start guides and guidance by sector and topic.
  3. NIST SP 800-63B-4 — Digital Identity Guidelines: Authentication and Authenticator Management— finalised 31 July 2025. Source for the 15-character minimum, the prohibition on composition rules, and the prohibition on periodic password change. Supersedes SP 800-63B, which was withdrawn on 1 August 2025.
  4. CISA — Secure Our World: Secure Your Business— CISA's current small business campaign and its five named actions.
  5. CISA — Cyber Guidance for Small Businesses— the deeper technical companion, organised by role. Source for "Ensure MFA is mandated using technical controls, not faith" and "Remove administrator privileges from user laptops."
  6. CISA — Implementing Phishing-Resistant MFA— October 2022. Source for the assessment of SMS and voice one-time passcodes as a last-resort option vulnerable to phishing, SS7 and SIM-swap attacks.
  7. CISA — Cross-Sector Cybersecurity Performance Goals— source for changing default passwords (2.A), separating user and privileged accounts (2.E), revoking departing employee credentials by the day of departure (2.D), and backup testing (2.R).
  8. CISA, FBI, NSA and MS-ISAC — #StopRansomware Guide— source for offline encrypted backups, regular restore testing, and the caution on immutable storage.
  9. CISA — More than a Password— on prioritising your most-used accounts, FIDO/WebAuthn as the only widely available phishing-resistant method, and number matching as an interim measure.
Prepared by ADAM Pulse (USA Telecom Consulting LLC)

Managed network and security services, SDVOSB. Most of this article is work a business can do itself, and we would rather you did. Where we help is the part that needs someone to own it: the inventory of what is actually on the network, monitoring and logging that produces evidence rather than noise, and firewall and circuit management for organisations without an internal team. CAGE 9QJS2 · UEI NJ7FKBV9X6L1. Support: (888) 989-4872 · support@adampulse.us