1 min read
How MSPs Reduce Downtime and Boost Productivity
If you run a small or mid-sized business, you know that IT issues can hit hard. One unexpected outage or cyber scare can bring everything to a...
11 min read
Published: March 30, 2022 Updated: September 23, 2026
The median time from a phishing email being opened to a user entering credentials is approximately 49 seconds, according to the 2025 Verizon Data Breach Investigations Report. In that window, a small business can lose access to its email accounts, customer data, or financial systems. Cybersecurity for small businesses is an operational risk with a specific cost and a specific set of controls that reduce it.
This guide covers cybersecurity best practices for small businesses in plain terms, organized to help DFW business owners and operations leaders take meaningful action.
When asked what small businesses should prioritize, federal agencies, security vendors, and major research institutions consistently point to the same cybersecurity tips for small businesses:
These five controls don’t prevent every attack, but they stop the vast majority of the attacks that actually target small businesses.
Stolen credentials are the single most common way attackers gain access to small business systems. Phishing accounted for 16% of all initial access vectors in the Verizon 2025 DBIR, and the human element was involved in approximately 60% of all breaches reviewed. Multi-factor authentication (MFA) disrupts credential theft by requiring a second form of verification before granting access. This can be an authenticator app code, hardware key, or biometric.
Microsoft 365, Google Workspace, and most banking portals have native MFA built in. To enable it, you typically only need to change your settings. Combine MFA with a business password manager to eliminate credential reuse across accounts, which remains one of the most exploited vulnerabilities in small business environments. If your team hasn’t enabled MFA on every external-facing account, including email, cloud storage, financial platforms, and remote access tools, that’s the single highest-priority action on this list.
Training is still one of the most effective cybersecurity best practices for small businesses, but the subject matter of that training needs to evolve, especially in the face of AI-generated attacks. The 2025 Verizon DBIR found that the median time from a phishing email being opened to a user clicking the malicious link is 21 seconds, with credential entry occurring a further 28 seconds later. That 49 seconds leaves almost no room for careful judgment.
AI-generated phishing messages now achieve roughly a 54% success rate compared to approximately 12% for human-written phishing, according to CrowdStrike’s 2025 Global Threat Report. Sagiss’ own AI phishing statistics research found that 72% of workers say phishing attempts are more convincing than a year ago because of AI-written language. To train effectively for these threats, employees need quarterly simulated phishing exercises and tighter procedural controls that don’t depend on employees correctly identifying every threat under time pressure.
Unpatched vulnerabilities are one of the most consistent and preventable entry points for attackers. CISA maintains a Known Exploited Vulnerabilities (KEV) catalog, which is a running list of vulnerabilities that threat actors are actively using in real-world attacks. Many of those vulnerabilities have patches available, and organizations that fail to apply them remain unnecessarily exposed.
An effective patch management approach for SMBs should include automatic updates wherever software supports it, and a clear SLA for anything requiring manual review. Critical patches warrant a 24 to 72-hour window. Lower-severity updates can follow a defined monthly cadence. Patch management is also a service a managed IT provider handles on an ongoing basis, which frees internal staff from tracking overhead while maintaining a documented compliance record.
The 3-2-1 backup rule dictates that you should keep three copies of your data, store them on two different media types, and keep one copy offsite or in the cloud. Most small businesses understand the concept, but many don’t actually test whether their backups can be restored when needed.
An untested backup file that has never been through a restore test may be corrupted, incomplete, or stored in a format the recovery environment can’t read. Schedule restore tests at least quarterly and document the results. Your backup strategy needs to consider how quickly and completely the business can restore operations after a loss event. For a fuller treatment of backup architecture and disaster recovery planning, see the Sagiss guide to data backup and disaster recovery.
Least privilege is the principle that users get access only to the systems and data they need for their specific role. Zero Trust extends that further by verifying every user and every device every time they request access, regardless of whether they’re inside the network or connecting remotely. These two principles work together to limit the damage a compromised account or insider threat can do.
In many small businesses, the biggest challenge is access that accumulates over time. An employee hired into one role gains permissions relevant at the time, moves into a different position, and retains all of their original access. The same goes for former employees when their accounts remain active after they leave. That gives the attackers a ready-made entry point that no one is monitoring. An access audit that reviews user permissions against current roles and deactivates accounts for departed employees is a low-cost cybersecurity best practice for small business control with significant impact.
The assumption that small businesses are too small to attract serious threat actors is one of the more costly misconceptions in cybersecurity. The 2025 Verizon Data Breach Investigations Report found that ransomware appeared in 88% of SMB breaches reviewed, compared to 39% for large organizations. IBM’s 2025 Cost of a Data Breach Report put the US average breach cost at a record $10.22 million, which shows just how expensive a single incident can be for any organization.
Attackers target SMBs precisely because small business data security practices tend to be limited. A successful phishing campaign against a 30-person company requires the same attack infrastructure as one aimed at a company with 3,000. The return on effort is often higher with smaller targets because there are fewer technical controls to bypass and less likelihood of a 24/7 security operations center catching the intrusion before damage is done.
Supply chain dynamics also have to be considered. A small accounting firm or law office that serves larger enterprise clients represents a potential entry point into those clients’ systems. Criminals who want access to a large organization will sometimes target its smaller vendors first. For a comprehensive breakdown of how the threat landscape plays out by company size and industry, see the Sagiss review of cybersecurity statistics for Dallas small businesses.
The National Institute of Standards and Technology Cybersecurity Framework 2.0 (NIST CSF 2.0), released in February 2024, organizes cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. NIST SP 1300, the Small Business Quick-Start Guide published alongside CSF 2.0, maps each function directly to SMB-scale actions. The table below translates those functions into a simple small business cybersecurity checklist. The sections that follow break down what each function looks like in a small business context.
|
NIST CSF 2.0 Function |
Key SMB Actions |
Quick Win? |
|
Govern |
Write an acceptable use policy; build an incident response contact list; create a vendor risk checklist |
Yes — one-time setup |
|
Identify |
Audit every device, cloud account, and user account on your network; run a shadow IT scan |
Yes — start with a device inventory |
|
Protect |
Enable MFA everywhere; deploy EDR; implement email security gateway; encrypt devices; enforce patch cadence |
Yes for MFA; staged rollout for others |
|
Detect |
Deploy log aggregation or SIEM; enable EDR alerting; establish 24/7 monitoring |
Requires tooling or MSSP |
|
Respond |
Document an incident response plan with a defined communication tree; establish pre-incident relationships with IR firm and legal counsel |
Yes — document now |
|
Recover |
Define RTO and RPO; test restores quarterly; carry cyber insurance as the financial recovery layer |
Yes for insurance; restore tests are ongoing |
Govern is the newest addition to the NIST CSF, added in the February 2024 release. It calls for small businesses to have written policies in place before an incident forces improvisation. A written acceptable use policy defines how company devices and accounts can be used. An incident response contact list names who to call and in what order. A vendor risk checklist applies consistent security questions to any partner with access to your systems. Get these documented before you need them.
The incident response contact list is particularly important. When a breach is in progress, the worst time to determine who your cyber insurance carrier is or whether you have a relationship with outside legal counsel is during the first hour of the event. A one-page document with those contacts, stored somewhere accessible without the affected systems, costs nothing to create and saves significant time when it matters most.
You can’t protect what you haven’t inventoried. A current, accurate list of every device, software application, cloud account, and user account connected to your business is the prerequisite for every other security function. Could you list every device on your network right now? Many businesses can’t.
Shadow IT only makes the problem worse. Employees adopt cloud tools like file sharing apps, messaging platforms, and AI services without involving IT. A shadow IT scan, run as part of a security assessment, reveals the tools and accounts that exist outside your documented environment. Those are the entry points attackers will find whether you know about them or not.
The Protect function covers the technical controls that keep attackers out of systems you’ve already identified. MFA and least privilege access are addressed in detail in the section above. The additional controls at this tier include endpoint detection and response (EDR), which actively monitors device behavior for signs of malicious activity rather than relying on signature-based detection. An email security gateway filters phishing attempts before they reach the inbox. Device encryption via BitLocker on Windows or FileVault on macOS protects data on devices that go missing. Encrypted Wi-Fi using WPA3 secures network traffic at the connection level.
Detection matters because prevention is never perfect. The average attacker moves laterally through a network for weeks before triggering a visible event. A business without visibility into its own environment can’t know a breach is happening until the damage is already significant.
At SMB scale, detection starts with a SIEM or log aggregation tool that centralizes activity data from across the environment, paired with EDR software that generates alerts when endpoint behavior matches known attack patterns. The challenge for most small businesses is 24/7 monitoring. Logs and alerts don’t produce value if no one is watching them. This is where managed security services provide a function that’s difficult for SMBs to replicate in-house. An MSSP provides continuous monitoring without requiring internal staff to be on call around the clock.
A written incident response plan doesn’t need to be long, but it does need to answer a clear set of questions. Who gets notified internally when something goes wrong? Who are the external contacts, including the cyber insurer, legal counsel, and breach coach? What system is isolated and in what order? Who is authorized to make decisions on behalf of the business? Establish those cybersecurity best practices before an incident.
Texas-specific note: under SB 768, effective September 1, 2023, businesses must notify the Texas Attorney General within 30 days of a breach affecting 250 or more Texas residents. That deadline runs from discovery, not from the end of the incident. Having a response plan that accounts for regulatory notification timelines avoids adding a compliance failure to an already expensive event.
Recovery is distinct from backup. A backup strategy defines how data is protected. A recovery strategy defines how quickly and completely the business can restore operations. Recovery Time Objective (RTO) measures how long restoration takes; Recovery Point Objective (RPO) defines how much data loss the business can tolerate. Both require testing against realistic scenarios to produce numbers anyone can actually rely on.
Cyber insurance plays a specific role in financial recovery as well. Coverage typically extends to incident response costs, ransomware negotiation, business interruption losses, and in some cases regulatory fines. The requirements to qualify have tightened considerably, since insurers now ask for documented MFA, EDR, tested backups, and security awareness training before issuing or renewing a policy. For businesses that experience a significant incident without it, the out-of-pocket exposure can be severe.
The most common cybersecurity mistake small businesses make isn’t a single technical oversight. The human element has consistently been involved in a majority of the attacks cited in Verizon’s DBIR year after year. That’s because of how attacks work, and it’s not a problem that resolves as employees become more security-aware.
The human element plays a role in phishing clicks, credential reuse, misconfigured cloud storage, and inadequate offboarding. Workers making fast decisions in a high-volume communication environment are the target, and AI-generated phishing is purpose-built to exploit that dynamic. For a full breakdown of how AI is changing phishing and what the data shows about employee behavior, see the Sagiss guide to AI phishing statistics.
Effective security awareness training doesn’t just teach employees to identify red flags. It establishes procedural controls that reduce the weight of individual judgment calls under pressure. Out-of-band verification for high-stakes requests, dual approval for wire transfers, and clear escalation paths for suspicious messages all reduce the impact of a human mistake without depending on perfect human performance in every situation.
National cybersecurity resources rarely cover Texas-specific compliance obligations. DFW businesses operate under a set of state and federal requirements that carry real penalties for non-compliance, and understanding them is part of maintaining adequate security.
Texas Business and Commerce Code Section 521 requires businesses to notify affected individuals within 60 days of a data breach. Under SB 768, effective September 1, 2023, businesses must also notify the Texas Attorney General within 30 days when a breach affects 250 or more Texas residents. Civil penalties under Section 521.151 can reach $250,000 per violation. The 30-day AG notification window starts from the day of discovery.
Texas HB 300 (Texas Medical Records Privacy Act) applies to covered entities more broadly than HIPAA. It includes any business that handles patient health information, not just direct healthcare providers. Penalties for PHI misuse can reach $250,000, with a pattern of violations potentially reaching $1.5 million. Any DFW business that handles patient data, such as a billing service, law firm with healthcare clients, or a business process outsourcer, should evaluate its exposure under HB 300, not just HIPAA.
The FTC Safeguards Rule now applies to a broader range of non-financial SMBs than many business owners realize, including auto dealers, tax preparers, accountants, and mortgage brokers. It requires nine documented safeguards and breach notification to the FTC within 30 days for incidents affecting 500 or more consumers, with an effective date of May 2024. Civil penalties can reach $50,120 per violation.
These regulations establish minimum requirements. A business that treats compliance as the finish line remains exposed to attacks. Legal counsel should review your specific obligations before you finalize a compliance program. For industry-specific guidance relevant to DFW businesses, see the Sagiss resource on cybersecurity tips for Dallas small businesses.
The most consistent question small business owners ask when evaluating cybersecurity is what it costs. To make a fair comparison, you have to measure the cost of security tools against the cost of a breach.
Security-only managed services typically run $35 to $65 per user per month, covering continuous monitoring, threat detection, and incident response support. Fully managed IT and security bundles, where the provider handles the complete technology environment, typically run $125 to $220 per user per month. Cybersecurity typically represents 10 to 13% of an organization’s overall IT budget, though businesses in regulated industries or high-risk sectors often spend toward the higher end.
IBM’s 2025 Cost of a Data Breach Report puts the US average breach cost at $10.22 million. A 30-person DFW business paying $50 per user per month for managed security spends $18,000 annually on protection. Cyber insurers recognize their value, and often require documented MFA, EDR deployment, tested backups, and security awareness training as standard requirements before a policy is issued. A business that can’t demonstrate those controls may find it difficult to obtain coverage at any price.
The five highest-impact controls are enabling MFA on every account, training employees continuously to recognize phishing, keeping software and hardware patched, following the 3-2-1 backup rule with tested restores, and limiting access using least privilege principles. These controls address the most common attack vectors documented across major breach research, including the Verizon DBIR. Implementing all five establishes a meaningful security baseline for most small businesses.
Failing to enable MFA is the most consistently cited single control gap noted in federal guidance and security research. Password reuse across accounts and skipping patch updates follow closely behind. The human element was involved in approximately 60% of breaches reviewed in the 2025 Verizon DBIR, which means the most common mistake is often a behavior like clicking a phishing link or reusing a compromised password.
Continuous monitoring is the goal. At minimum, a quarterly review of user access and patch status keeps the environment current, along with an annual third-party vulnerability assessment or penetration test. Certain events should trigger an immediate review outside that schedule, including adding a new employee with system access, offboarding a departing employee, adding a new cloud tool, or learning of a breach at a vendor or software provider the business uses.
Yes, and the requirements to qualify have tightened significantly. Insurers now document MFA enrollment, EDR deployment, tested backup procedures, and security awareness training as standard conditions before issuing or renewing a policy. Coverage typically includes incident response costs, ransomware negotiation, business interruption losses, and regulatory fines. For businesses that experience a significant incident without coverage, the out-of-pocket exposure can be severe. The Sagiss cyber liability insurance resource covers what to look for in a policy and how to evaluate coverage for a small business.
Ready to evaluate your security posture? Schedule a free consultation with Sagiss.
1 min read
If you run a small or mid-sized business, you know that IT issues can hit hard. One unexpected outage or cyber scare can bring everything to a...
1 min read
Businesses have an endless list of needs but may not have the resources to satisfy all their needs in-house. That's why many businesses outsource...
1 min read
For years, you may have assumed that cybercriminals only target large corporations with deep pockets. After all, why would hackers go after a small...