SMALL BUSINESS CYBERSECURITY

Simple, Easy to Follow Help
For the Small Business

Certified Information Systems Security Professional
ISC2 CISSP #473513 Since 2013

Home Credentials Coaching Contact

Clean Definitions

What is Cyber

What is Risk

What is a Threat

What is a Framework

What is the Cloud

What is a CISO or BISO

What is a decent Plan?

What is AI?



Resources

Measuring and Manageing Information Risk,
a FAIR Approach
1st Edition

Authors: Jack Freund and Jack Jones
Published by: Butterworth-Heinemann, Oxford, UK
2015
ISBN: 978-0-12-420231-3 (Paperback)

How to Measure Anything in Cybersecurity Risk

Authors: Douglas W. Hubbard and Richard Seiersen
Published by: John Wiley and Sons, Inc., Hoboken, New Jersey, USA
2023
ISBN: 978-0-11-1989230-4 (Hardback)
ISBN: 978-0-11-1989232-8 (ePDF)
ISBN: 978-0-11-1989231-1 (ePub)

A Basic Plan for Information Security

The following list is in a somewhat priority order for what a small business might consider doing to begin to secure their information and compute environment. Start at the top and work your way down. Move these into any order that seems correct for your business. Though this list is long, most things are fairly simple to implement.Those things marked with an astrisk (*) are more difficult to do if you are not very computer technical.


  • Do not allow personal use of company resources.
  • Do not allow company information to be taken home.
  • Do not allow company information on personal storage devices.
  • Use at least the "Professional" version for Windows workstations.
  • Patch operating systems and software applications at least monthly.
  • Label documents and information with a consistent sensitivity level labeling systems.
  • Use company credentials for all access to anything business.
  • Do not use shared accounts.
  • Create administrative accounts specific to the device or information being administered.
  • Do not give administrator permissions to normal user accounts.
  • Never user administrative credential unless the task at hand requires it
  • Log out of every administrative session as soon as the task the administrative task is completed.
  • Use long, complex, individually chosen, password phrases.
  • Have users lock or logout of their workstations if unattanded.
  • Add information security to the agenda of all meetings.
  • Create written standards for all requirements.
  • Create and conduct employee training.
  • Lock paper files in cabinets or safes.
  • Do not allow testing of anything new on the production network.
  • Test your tests to be sure they won't hurt your production services.
  • Restrict what can be installed on company computers.
  • Encrypt hard drives on all computers.
  • Encrypt all removable storage devices.
  • Install anti-malware on all computers.
  • Use a least privilege model for all access to devices and information.
  • Use a reputable, mainstream, site firewall.*
  • Segment the networks.*
  • Use spam filtering on all email systems.*
  • Use host firewalls on all computers.*
  • Have a central computer and system log server.*
  • Centralize and standardize all controls on all systems.*
  • Run endpoint detection and response.*
  • Run network detection and response.*
  • Use role based access control for people.*
  • Use network access control for devices.*
  • Use a centralized directory service (like Active Directory or Entre ID) for credentials.*
  • Use Multi-Factor authentication.*
  • Have a third-party vendor and partner security evaluation program.*
  • Require secure coding practices for all tools and software.*
  • Implement a Zero-Trust framework initiative.*
  • Follow a NIST, CISA, ISO, GDPR and/or HITRUST type of framework of standards.*
  • Create a Security Operations Center to watch for rogue behavior.*

Again, the steps in this plan are suggestions in a suggested order of importance. But the order will be unique for every business applying it. You do not have to do all steps, ever. You can pick one, two, three or more and spread them out over days, weeks, months and years. It's up to you. You should at least make reasonable progress over time so that you can show on paper that your plan makes financial sense for your business to be where it is in the plan at any given time. That is for liabiltiy reasons for your business should something go bad along the way.

Also, in most circumstances, I will be able to setup and configure whatever your business would need done, but I'd rather train your IT personnel to do that and to maintain it in the future. For a little cost, I can prepare system security plans, diagrams and manuals, specifically about your environment and how it is setup so that you have assurance for the future that you can continue to grow and adapt without much cost for someone to figure out or relearn what you have.

Testimonials

NULL at the moment.

Please email ronald@weist.net to schedule an appointment to talk about your data (or, cyber if you must) security.