The Small Business Security Playbook
A Four-Category Framework for Owners Without an IT Team
A plain-English security programme for the owner who is also the IT department: the first five fixes that close the most common doors, then four control categories with a maturity model (what to do, in what order, and how to tell it is working).
You are the owner. You are also the IT department.
Nobody ever explained what "do something about cybersecurity" is supposed to mean. Most of the advice you can find is written either for companies that already have a security team, or as a list of frightening statistics that ends in a sales pitch. Neither tells you what to do on Monday morning.
This is a working framework for the business owner who has no IT staff and no intention of becoming a security specialist. Four categories cover the ground that matters: who can get in (accounts, passwords, multi-factor authentication, and what happens to access when someone leaves); what they can take (knowing which of your data would actually hurt to lose, and how long you are keeping it); how you survive a bad day (backups that have been tested, and a plan for the morning something is encrypted or gone); and how your own software stops being the way in (updates, patching, and the tools your team signed up for without telling you).
Three businesses run through the book: a 22-person consulting firm, a merchant selling through Shopify, and a four-person clinic. They have different budgets, different regulators, and different things worth stealing. One of them will look like yours.
The back of the book is the part most people use twice: a sixteen-question assessment you score yourself; ten security policy templates, written to be edited rather than admired; six tabletop exercises with scripts, practice runs where you talk a bad day through as a team before you have one; a vendor security questionnaire for checking who you are about to trust; a worksheet for finding the apps your team signed up for without telling you; a checklist for locking down the personal phones and laptops your team works from; and a phishing card to pin by the desk.
Three more chapters cover what to do in the first 48 hours of an incident, how to work out which rules actually apply to you, and what to do when you are the entire company.
Plain English throughout. No certifications required, no budget assumed, and no pretending that any book makes you secure.
Sylvan Press is the security imprint of Sylvan Assurance, LLC.
Companion to the SMB Security Assessment toolkit: the assessment and ready-to-use templates that put this book to work.
From the blog: You are the owner. You are also the IT department. · The first security baseline for a small team. Essay-length previews of the same ground this book covers, free.
Read Chapter 1 free
The sample is the real typeset front matter and full first chapter, the same pages you would hold in print.
Book details
Swipe sideways to see the full table →
| Format | Pages | Language | Price |
|---|---|---|---|
| Paperback & hardcover (6 × 9 in) & EPUB | 386 | British English | Paperback $34.99 · Hardcover $44.99 · Ebook $12.99 |
| Depth | 16 chapters | ||
Where to buy
The Small Business Security Playbook is available now in paperback, hardcover, Kindle ebook and EPUB ebook. The print and Kindle buttons go to the retailer, which sells and ships the book. The ebook button buys directly from us: you get the PDF and the EPUB straight away, and nothing is shipped.
Paperback Hardcover Kindle ebook Ebook direct (PDF + EPUB)
Prices shown are our retail list prices; for print and Kindle the retailer sets the price you actually pay. The ebook is sold by us through Lemon Squeezy, our payment provider and merchant of record.
If the book helped, a short review on Amazon helps the next owner find it.
Where a review helps
If this book helped, an honest review on Amazon does more for a small independent press than anything else. We never ask for a rating and never offer anything for one.