Cybersecurity June 2, 2026

The 20-Minute Security Checklist Every Small Business Should Run Monthly

Published by SOETech LLC | Written by the SOETech AI Team

Key Takeaways

  • Enforce MFA on every account touching money, email, or customer data — not just where it is offered.
  • Test-restore a backup every month and keep at least one copy offline or disconnected.
  • No machine more than 30 days behind on security updates, and nothing stuck pending a reboot.
  • Run a real password manager and retire shared, emailed, or default passwords.
  • Keep router firmware current, admin credentials unique, and Wi-Fi on WPA2/WPA3.

Here's the honest truth about small-business cybersecurity: it's not about expensive tools or a security team. It's a handful of basic habits, done consistently, that stop the vast majority of real-world problems. Ransomware, stolen email accounts, and "the server just died and we lost everything" incidents almost always trace back to one of five gaps — and all five can be checked in about 20 minutes a month.

No fear-mongering, no jargon. Just a checklist. Put it on your calendar for the first Tuesday of the month and run through it. One-person shop or 15 employees — this is for you.

1. MFA Coverage Check (~4 minutes)

Multi-factor authentication is the single most effective protection for your accounts, and it's free on nearly every service you already use [1]. The question isn't "do we have MFA?" — it's "do we have it everywhere that matters?"

What to do:

  • Confirm MFA is enforced (not just offered) on: email (Microsoft 365 or Google Workspace), your banking portal, accounting software (QuickBooks, etc.), payroll, and any cloud tools holding customer data.
  • Check for accounts set up without it — new hires, contractors, or that employee who "keeps meaning to get around to it."
  • Confirm a backup sign-in method exists per critical account (a second code app, hardware key, or printed recovery codes in a safe). SMS-only 2FA is better than nothing, but worth upgrading.
  • On Microsoft 365 Business, turn on number-matching in the Authenticator app — it defeats the "accidentally tap approve" trick [2].

Pass condition: Every account with access to money, email, or customer data requires a second factor.

2. Backup Test-Restore (~5 minutes)

A backup you've never restored is a hope, not a backup. This is the step most small businesses skip, and it's the one that decides whether an incident is an inconvenience or a catastrophe.

What to do:

  • Pick one important file (a spreadsheet, a document) and one folder. Restore them from your backup system to a different location and actually open them.
  • If your data lives on a server or NAS, verify the backup job completed successfully since last month — check the log, not just the icon.
  • Confirm you have at least one backup copy that's offline or disconnected (cloud version history, a rotating external drive that's unplugged between runs). This is your defense against ransomware, which encrypts anything it can reach — including connected drives [3].
  • Check the retention: can you get back a version from 30+ days ago? Some problems don't get noticed for weeks.

Pass condition: You restored real files this month and opened them. If the restore failed or the backup hasn't run, that's your top priority this week — not next month.

3. Patch & Update Status (~4 minutes)

Most breaches exploit vulnerabilities that were fixed months or years ago [4]. Patching is boring, and that's exactly why it works.

What to do:

  • On every Windows 11 PC, open Settings → Windows Update and confirm "You're up to date." Note anything that says "restart required" — those patches aren't applied until the machine reboots.
  • Check any servers (Windows Server 2019/2022/2025) the same way, and confirm scheduled maintenance reboots actually happen.
  • Update the unglamorous stuff people forget: browsers (Edge, Chrome), Adobe Reader, printers' firmware, and any point-of-sale or line-of-business software.
  • If machines are skipping updates because "it's annoying," set Active Hours and a weekly restart policy so it stops being a negotiation.

Pass condition: No machine is more than 30 days behind on security updates, and nothing is stuck pending a restart.

4. Password Manager Audit (~4 minutes)

If your team is keeping passwords in a Word doc, a notebook, a browser's saved-list with a shared login, or — we see this one a lot — a sticky-note photo on someone's phone, this item is for you.

What to do:

  • If you already use a password manager (Bitwarden, 1Password, Keeper, etc.): open the admin console, check that no team passwords are stored outside it, and use the built-in security report to flag reused or weak passwords. Fix the top three offenders this month.
  • If you don't use one yet: pick one, get a family/teams plan, and start with your five most critical logins — email, banking, accounting, payroll, domain registrar. Doing it all at once is how these projects die; doing five accounts takes an afternoon.
  • Rotate any password that was shared over email or text recently, and any default password on equipment (routers, cameras, printers).

Pass condition: Critical business logins live in a password manager with unique, strong passwords, and nobody is emailing credentials around.

5. Router & Firmware Check (~3 minutes)

Your router is the front door to your network, and it's the device everyone forgets exists until it stops working.

What to do:

  • Log into your router/modem (usually 192.168.1.1 or 192.168.0.1) and check the firmware version. If there's an update, apply it — ideally after hours or on a lunch break, since it restarts the network.
  • Confirm the admin password isn't the factory default. Default router passwords are published on the internet; if yours is "admin/admin," you're effectively leaving the door unlocked.
  • Verify Wi-Fi uses WPA2 or WPA3 (not the old WEP/WPA) [5], and that any guest network is separate from the network your business systems run on.
  • If your router is more than 5–6 years old and hasn't received a firmware update in over a year, budget for a replacement — old routers stop getting security fixes.

Pass condition: Firmware is current, admin credentials are unique, and Wi-Fi encryption is WPA2/WPA3.

Why This Matters Locally

Businesses across the Great Lakes Bay Region — manufacturers in Saginaw, shops in Bay City, offices in Midland — run lean, usually without a dedicated IT person. That's exactly who these attacks target: not because anyone's picking on us, but because attackers automate their attempts and under-defended small businesses are the easiest marks.

The good news: everything on this list is free or cheap, and 20 minutes a month puts you ahead of most businesses your size.

If Something Fails the Checklist

Don't panic, and don't ignore it. Most checklist failures are an afternoon of work to fix, and fixing them before an incident costs a fraction of fixing them after one. If you hit a step you're not sure how to complete — a restore that won't work, a server you're nervous about patching, a router you can't log into — that's exactly the kind of thing we help Great Lakes Bay Region businesses with every week.

SOETech LLC provides IT support, security hardening, and backup setup for small businesses and home users in Saginaw, Bay City, Midland, and across Michigan. Visit soetechllc.com to get in touch — we'll run the full checklist with you and handle anything that needs more than 20 minutes.

Sources

  1. CISA — More Than a Password (MFA guidance)
  2. Microsoft Entra ID — Number matching for multifactor authentication
  3. CISA/FBI — #StopRansomware Guide (offline and disconnected backups)
  4. CISA — Known Exploited Vulnerabilities Catalog
  5. Wi-Fi Alliance — WPA3 security

SOETech LLC | Web Development & AI Integration | soetechllc.com
© 2026 SOETech LLC. All rights reserved.

Share this post: