Cybersecurity Baseline for SMBs: 10 Controls You Should Have This Quarter
A no-fluff cybersecurity baseline for business owners and operations leaders: the ten controls that provide immediate risk reduction without enterprise complexity.
Cybersecurity Baseline for SMBs: 10 Controls You Should Have This Quarter
Cybersecurity doesn't need to start with expensive tools or complex frameworks. It starts with consistent, proven controls applied across your environment and reviewed regularly.
For a small or mid-sized business in Southern California, these ten areas provide a practical review baseline. Priority and timing should follow the organization's systems, data, users, threats, and confirmed requirements.
Here's the baseline, with practical detail on how to implement each one.
1) Multi-Factor Authentication Everywhere
MFA is the single highest-impact security control you can deploy. Enable it for every system that supports it:
- Microsoft 365, enforce through conditional access policies, not just security defaults
- VPN and remote access, every remote connection requires a second factor
- Line-of-business applications, accounting software, EHR, CRM, project management tools
- Admin consoles, firewall management, DNS, domain registrar, hosting panels
Set a documented MFA scope for supported user, administrative, remote-access, and service accounts. Record technical exceptions, compensating controls, owners, and follow-up decisions.
For the full implementation approach, see our guide to zero trust security principles, which builds on MFA as the first layer.
2) Endpoint Detection & Response (EDR)
Traditional antivirus checks files against a list of known threats. It misses anything new. EDR watches for suspicious behaviors, unusual process execution, lateral movement, credential harvesting, file encryption patterns, and can isolate a compromised device in seconds.
Deploy managed EDR on every endpoint: workstations, laptops, and servers. "Managed" means someone is reviewing the alerts, not just collecting them. If internal staff cannot review and escalate alerts during the needed coverage window, compare that gap with the contracted scope of a managed detection and response service.
Key requirements for your EDR solution:
- Covers Windows, Mac, and Linux
- Provides remote isolation capability
- Includes ransomware rollback or protection
- Integrates with your RMM or security platform
- Generates actionable alerts, not just noise
3) Patch Management with SLA Targets
Unpatched software can create avoidable exposure. Define patch priorities using vendor guidance, known exploitation, severity, internet exposure, asset criticality, compatibility testing, and any confirmed requirement. Include supported operating systems, browsers, productivity tools, remote-access software, and other applications.
Don't forget network devices. Your firewall, switches, and access points need firmware updates too, and these are often the most exposed to the internet. An unpatched firewall vulnerability is how many ransomware attacks begin.
Track patch status against the approved policy. Review overdue devices, failed deployments, exceptions, and unsupported systems on an agreed cadence.
4) Least Privilege Access
Separate routine user activity from privileged administration where the environment supports it. This can limit what a compromised user session is able to change.
Implementation steps:
- Audit current admin access, confirm each assignment has a current business owner and need
- Remove local admin rights from all standard user accounts
- Create a separate admin account for IT staff that's only used for administrative tasks
- Review privileged access monthly, when people change roles, their permissions should change too
- Implement just-in-time access for activities that occasionally require elevated permissions
This ties directly into your IT management practice. Access control isn't a one-time project, it's an ongoing discipline.
5) Immutable or Protected Backups
Standard backups can be encrypted or deleted by ransomware if the attacker reaches them. Immutable backups cannot be modified once written, not by users, not by admins, not by ransomware.
Requirements:
- At least one backup copy uses immutable storage (write-once, read-many)
- Backup credentials are separate from domain admin credentials
- Backup data is replicated offsite or to the cloud
- Recovery procedures are documented and tested quarterly
This is the difference between a ransomware attack being a nuisance and a business-ending event.
6) Email Security Hardening
Email is the #1 attack vector. Your defenses need to go beyond basic spam filtering:
- Anti-phishing policies with impersonation protection for executives and key vendors
- Attachment sandboxing, files are executed in an isolated environment before delivery
- Safe links, URLs are checked at time of click, not just at delivery
- DMARC, DKIM, and SPF, these DNS records prevent attackers from spoofing your domain
We cover the full approach in our guide to email security beyond spam filters. Microsoft 365 capabilities vary by license and configuration. Verify current entitlements and dependencies before treating a feature as available.
7) Security Awareness Training
Your employees are both your biggest vulnerability and your best detection layer. Run recurring phishing simulations and awareness micro-trainings:
- Monthly phishing simulations with realistic, industry-relevant scenarios
- Short training modules (3-5 minutes) after each simulation for anyone who clicked
- Quarterly deeper training on BEC, social engineering, and physical security
- Immediate private feedback, not public shaming, when someone falls for a simulation
Track click rates and report rates monthly. The report rate (employees flagging suspicious emails) matters more than the click rate. See our full guide on building training that actually changes behavior.
8) Network Segmentation
A flat network can give a compromised device more paths to systems it does not need. Segmentation should follow business workflows, device trust, administration needs, and recovery design.
Basic segmentation separates your network into zones:
- Corporate devices, managed workstations and laptops
- Servers, restricted access from corporate zone only
- IoT devices, cameras, printers, smart devices, isolated from everything else
- Guest Wi-Fi, internet access only, zero internal access
This doesn't require expensive equipment. A managed switch and a properly configured firewall handle it. Read our network segmentation guide for implementation details.
9) Incident Response Runbook
Early decisions during a suspected incident matter. Document authority, contacts, communication alternatives, evidence handling, and recovery priorities before the team is under pressure.
Document:
- Who does what, incident commander, technical lead, communications lead, executive sponsor
- Contact list, cyber insurance carrier (claims number, not general support), legal counsel, forensics vendor, law enforcement (FBI IC3), your MSP's emergency line
- Containment procedures, how to isolate affected systems, disable compromised accounts, preserve evidence
- Communication templates, pre-drafted messages for employees, clients, and partners
- Recovery sequence, which systems come back first, from what backup, using what credentials
Run tabletop exercises on a cadence appropriate to the organization's risks and requirements. Walk through a scenario ("it's 2 PM Tuesday and accounting reports they can't open any files") and make sure everyone knows their role.
10) Continuous Monitoring and Reporting
Security controls must be measured, reviewed, and improved, not set and forgotten. Establish a monthly security review that covers:
- Patch compliance percentage across all endpoints
- EDR alert volume and resolution status
- MFA coverage and enrollment completeness
- Phishing simulation results and training completion
- Backup success rates and test outcomes
- Privileged access review status
- Open vulnerability count and remediation timeline
Agree on which measures a cybersecurity provider will report, who reviews them, and how frequently decisions are revisited.
Common Gap We See
A business may have some of these tools deployed but still lack process discipline. EDR is installed but nobody reviews alerts. Backups run but nobody tests restores. Policies exist but nobody acknowledges them annually. MFA is "available" but not enforced for every account.
Security improves when owners and leadership teams require a recurring review cadence, clear ownership, and measurable metrics. The tools are table stakes, the discipline is the differentiator.
A Phased Execution Plan
If you're starting from scratch or resetting after a gap, here's a practical sequence:
- Confirm scope: Inventory identities, endpoints, applications, network devices, data, and current owners.
- Close access gaps: Review MFA, privileged access, inactive accounts, and remote access.
- Validate operations: Review patching, endpoint coverage, backup alerts, recovery tests, and documented exceptions.
- Exercise response: Update the incident runbook and run a tabletop scenario with decision-makers.
Sequence and timing should reflect business risk, dependencies, staffing, and change-control needs. Then set an ongoing review cadence.
Bottom Line
A practical baseline beats a perfect plan that never ships. These ten areas map to common security practices, but the exact implementation should be validated for the business. Start here, execute consistently, and improve from there.
Need help validating your current security posture? Request a free IT assessment with our team. We work with businesses throughout the Victor Valley and High Desert to build practical security baselines that connect back to ongoing managed IT services.
