Skip to main content

    No Business Is Too Small for Real Security

    By Joseph HolkoAugust 11, 2026Security4 min read

    You have six people, a shared drive, and a router the internet company dropped off four years ago. Every security article you find seems to be written for a company with a security team and a budget line to match. So you close the tab and get back to work.

    That reaction makes sense. It is also built on a picture of American business that does not match the real one.

    Almost every business in this country is small

    The Census Bureau counted 30.4 million business locations in 2023 with no paid employees at all. That is 78.4% of every business location in the United States. Among the businesses that do have employees, 55.7% have fewer than five people, according to the 2022 County Business Patterns.2

    The Small Business Administration puts the total at 36.2 million small businesses, or 99.9% of all firms in the country.3

    Read those numbers again. Security guidance that only works for large companies is guidance that works for almost nobody. Small is the normal case in American business.

    Someone already wrote you a guide, and it is nine pages

    NIST is the federal agency that writes the technology standards most industries end up following. In February 2024 it published the Cybersecurity Framework 2.0 Small Business Quick-Start Guide.1 The guide is free. It was written for businesses with modest or no security plan in place.

    It sorts everything into six areas: Govern, Identify, Protect, Detect, Respond, and Recover.

    It opens with questions, not products

    Here is the part most people miss. Protect is the third of those six areas. Before the guide recommends a single tool, it asks you to answer two things first.

    Govern asks what your business does, and what would stop it from doing that.

    Identify asks what you actually have. NIST wants an inventory of your hardware, software, systems, and services. One of its questions is worth reading twice: "What technologies or services are personnel using to accomplish their work? Are these services or technologies secure and approved for use?"

    Most small offices cannot answer that question. The list grew one signup at a time over several years, and nobody was ever asked to keep score.

    The floor, in four parts

    With that inventory in hand, here is a reasonable minimum for a small office.

    1. A business-grade firewall. This is the box that sits between your office and the internet. The one your internet provider handed you is built to deliver internet service. Inspecting what comes in and goes out is a different job, and a different piece of equipment. Business-grade firewalls stopped being expensive several years ago, and the gap between one of those and a consumer router is large.

    2. A password manager, for everyone. NIST names this directly, alongside turning on multi-factor authentication anywhere it is offered. The guide even includes a starter checklist of accounts: banking, accounting, merchant services, your Microsoft or Google account, email, the password manager itself, and your website.

    3. A business-grade Microsoft or Google plan. The entry-level plans give you email and documents. The business-grade plans add the security pieces. You get control over company data on staff phones and laptops, encryption on the hard drives, stronger filtering on incoming mail, and a way to see what happened when something goes wrong. Plenty of offices already pay for a plan that includes all of this and have never switched it on.

    4. An honest look at what you have and how you work. This is the one people skip. It is also the one NIST puts first.

    Why the fourth one carries the most weight

    You can buy every item above and still be exposed.

    A firewall still running the password it shipped with. A password manager that half the staff never finished setting up. A Microsoft plan with the security features sitting switched off because nobody knew they came with it. Backups that have been running for two years and have never once been restored to check that they work.

    Every one of those is a gap between what a business bought and how that business actually operates.

    A tool protects you when it is configured correctly and matches the way your team works. Otherwise it is a line item on a credit card statement. Finding that gap is an evaluation, and it is the very first thing the NIST guide asks for.

    What to do this week

    Download the NIST Small Business Quick-Start Guide. It costs nothing and it takes about twenty minutes to read.

    Then turn to the Protect page and work through the multi-factor authentication checklist one account at a time, starting with banking and email. After that, open a spreadsheet and start listing every service your business pays for or depends on.

    Those two steps will tell you more about where you stand than any product you could buy this month. The essential security baseline for small business covers what belongs on that list once you have it.

    Get an independent read

    Not sure where your security actually stands? Our free Technology Confidence Assessment looks at your protection, your backups, and how well your current provider is covering you, and tells you in plain English what we would fix. No pressure, no jargon.

    Book your assessment

    Get Professional Guidance

    Schedule a free Technology Confidence Assessment to get personalized recommendations for your business.

    Book your assessment