Last reviewed 2026-09-07 · ~6 min read

You are the owner. You are also the IT department.

Somewhere in the last year, someone told you to "do something about cybersecurity". An insurer, a customer's questionnaire, an accountant, a nephew. Nobody said what that means for a business your size, and the advice you can find divides into two kinds.

The first kind is written for companies that already have a security team. It assumes a person whose job this is, a budget line, and a vocabulary you do not have. The second kind is a list of frightening statistics that ends in a sales pitch. Neither tells you what to do on Monday morning, and both leave you feeling that the honest answer is "hire someone", which you cannot.

There is a third way to think about it, and it fits on one page. Security for a small business is four questions. Answer them honestly and you know where you stand; work on the weakest one and you are doing the right thing in the right order.

Who can get in

Every account your business runs on, and every person who can sign in to it. Email first, because email resets everything else. The questions under this heading are ordinary: is two-step login turned on for everyone, are passwords unique and kept in a manager rather than a spreadsheet, and what happens to access on the day someone leaves.

That last one is where small businesses are most exposed and least aware of it. A former employee with a live login to your email, your accounting software or your customer list is not a hypothetical risk; it is the most common way an insider incident starts. "Done" here looks like a short list of who has access to what, and a habit of closing accounts on the leaver's last day, not the following month.

What they can take

Not everything you hold matters equally. Some of it would be an inconvenience to lose. Some of it would hurt: customer payment details, health information, staff records, the contract with your biggest client. The exercise is to name the handful of things that would actually hurt, know where they live, and decide how long you are keeping them.

Most owners have never made that list. Once you have, the rest of your decisions get easier, because you know what you are protecting and can stop trying to protect everything at once. "Done" is a one-page list and a retention rule you follow.

How you survive a bad day

At some point something will be encrypted, deleted or gone. Ransomware, a failed drive, a mistaken click, a supplier that folds. The question is not whether you have backups; almost everyone believes they do. The question is whether you have restored from them, recently, and whether the copy that matters is somewhere the same bad day cannot reach.

"Done" is a backup you have tested by actually bringing a file back, and a plan for the morning after that fits on a card: who you call, in what order, and what you do first. Writing the card takes an hour. Not having it costs a week.

How your own software stops being the way in

The last question is about the tools you already use: the operating systems, the browsers, the accounting package, the plugins on the website, and the apps your team signed up for without telling you. Most break-ins do not use anything clever. They use a known hole in software that had a fix available and was never updated.

"Done" looks like automatic updates turned on wherever they exist, a monthly glance at the things that do not update themselves, and a list of the services your business actually depends on. The list is usually longer than the owner expects, and that surprise is the point.

Monday morning

You do not need to answer all four questions today. You need to know which one you are weakest on, and start there. The free assessment on this site asks twelve plain-English questions across these four areas and gives you a scored, area-by-area picture in about five minutes. It runs in your browser and your answers never leave your device, so there is nothing to sign up for and no one to call you afterwards.

If you would rather read before you do anything, the book below works each of the four questions all the way through, for exactly this reader: the owner who is also the IT department, with no intention of becoming a security specialist. Three businesses run through it, a consulting firm, an online shop and a small clinic, and one of them will look like yours. The back of the book is the part most people use twice: a sixteen-question version of the assessment, ten policy templates written to be edited rather than admired, six practice runs for a bad day, and a questionnaire for checking who you are about to trust.

No certifications required, no budget assumed, and no pretending that any book, or any assessment, makes you secure. It makes you know where you stand, which is where every sensible programme starts.


When you want this ready to use

Sylvan Assurance's SMB Security Assessment is the toolkit version of the same four questions: a sixteen-question assessment, a prioritised roadmap, and the policies, checklists and practice runs to work through each area in order. The book explains the judgement; the toolkit does the work with you.

Prefer the long form? The companion Sylvan Press title, The Small Business Security Playbook, covers the same ground in depth.

See where you stand

Twelve questions, four areas, about five minutes. It runs entirely in your browser; your answers never leave your device.

Take the free SMB security assessment