Cyber resource center

Cyber resources for small business.

Almost everything a small business needs to get its security in order has already been written, tested, and published for free by the agencies and vendors involved. The problem is finding it. This is the shortlist.

  • Free and vendor-neutral
  • Grouped by publisher
  • Every link checked

How to use this page

You do not have to read all of it.

This is a reference, not a curriculum. Nothing here is behind a paywall, a lead form, or a sales call, and none of it is ours — it is published by federal agencies and by the platform vendors you already pay for. We keep the list because clients ask for it and because the same handful of documents answers most of the questions we get.

If you only have an afternoon, spend it on three things: turn on multi-factor authentication everywhere it is offered, confirm that your backups exist and can actually be restored, and teach whoever handles money how invoice fraud works. Those three account for the overwhelming majority of what actually goes wrong at businesses this size.

If you would rather not work through it alone, that is what we do — but the guidance below stands on its own either way.

Where to start

  • Multi-factor authentication on email first
  • A backup you have tested restoring
  • Anyone who pays invoices trained on wire fraud
  • Every device on a supported, patched version

Federal guidance

SBA, FTC, and NIST.

The plain-language starting points. Written for owners rather than engineers, and free of vendor interest.

03

Three simple things

The shortest useful list in this section: change passwords, update software, train employees. Roughly 43 percent of incidents hit small businesses.

FBI

Fraud, ransomware, and reporting.

The FBI pages matter for two reasons: they describe how these crimes actually run, and they tell you where to report one while the money may still be recoverable.

02

Ransomware

Prevention through updates, scanning, and offline backups, plus the Bureau’s position on paying a ransom and how to report an incident.

CISA

The federal cyber defense agency.

CISA’s own summary of why this matters: small businesses have valuable information that cyber criminals seek, and often have fewer resources dedicated to cybersecurity. Their material is the most practical of any agency on this list, and much of it is free service rather than free reading.

01

Cyber guidance for small businesses

Split by who has to act — the owner, whoever runs security, and whoever runs IT. Covers multi-factor authentication, patching, backups, incident response, training, and moving services to the cloud.

Payment cards

If you take card payments.

PCI DSS applies to every business that accepts cards, including the smallest. The obligation usually comes through your merchant bank rather than directly.

Microsoft 365

Securing the tenant you already pay for.

Most Microsoft 365 subscriptions include far more security than is ever switched on. These are the vendor’s own instructions for switching it on.

Apple

Macs, iPhones, and iPads.

Apple’s security documentation is good and almost never read. Start with the account pages — a compromised Apple Account is the usual entry point, not malware.

Google

Google Workspace and Google accounts.

Facebook and Instagram

Business accounts and pages.

A hijacked business page is a real and common loss for small businesses, and recovering one is far harder than protecting it.

Credentials

Passwords, passphrases, passkeys, and MFA.

Stolen and reused credentials remain the most common way in. This is the one category worth understanding properly rather than just complying with.

Want help putting any of this in place?

Everything above is free to read and free to act on. If you would rather have it done and documented, start with a call — the first fifteen minutes are free.

On aiming higher than the baseline

Most security advice quietly assumes you are only willing to make small changes. CISA’s Cyber Guidance for Small Businesses includes a passage that assumes otherwise, and it is worth reading in full because it describes the one move that removes whole categories of risk instead of managing them:

When security experts give cybersecurity advice, they usually assume you are only willing to make small changes to your IT infrastructure. But what would you do if you could reshape your IT infrastructure? Some organizations have made more aggressive changes to their IT systems to reduce their “attack surface.” In some cases, they have been able to all but eliminate (YES, WE SAID ELIMINATE!) the possibility of falling victim to phishing attacks.

One major improvement you can make is to eliminate all services that are hosted in your offices. We call these services “on premises” or “on-prem” services. Examples of on-prem services are mail and file storage in your office space. These systems require a great deal of skill to secure. They also require time to patch, to monitor, and to respond to potential security events. Few small businesses have the time and expertise to keep them secure.

While it’s not possible to categorically state that “the cloud is more secure,” we have seen repeatedly that organizations of all sizes cannot continuously handle the security and time commitments of running on-prem mail and file storage services. The solution is to migrate those services to secure cloud versions, such as Google Workspace or Microsoft 365 for enterprise email. These services are built and maintained using world-class engineering and security talent at an attractive price point. We urge all businesses with on-prem systems to migrate to secure cloud-based alternatives as soon as possible.

The same document makes a second point about endpoints — that Chromebooks and iPads are secure by design in a way general-purpose computers are not, and that moving staff onto them removes a great deal of attack surface, because even a successful attack finds little data sitting on the device.

That will not fit every business, and we will tell you when it does not. But the reason we lean toward Microsoft 365, managed devices, and cloud file storage for clients this size is not preference. It is that the alternative asks a small business to staff a job it cannot staff.