Security planning guide

Small Business Cybersecurity Checklist for Oregon and Washington Companies

A practical checklist for reducing common technology risk without turning cybersecurity into a confusing, oversized project.

Start with the risks that interrupt real work

Small businesses usually do not need a complicated cybersecurity program on day one. They need clear ownership of the basics: employee accounts, Microsoft 365 access, endpoint protection, backups, network equipment, vendor access, and offboarding. When those basics are not documented, one lost laptop, reused password, or former employee account can create a bigger problem than expected.

This checklist is written for businesses in Oregon and Washington that rely on cloud tools, local workstations, Wi-Fi, printers, phones, shared files, and Microsoft 365. It is a practical starting point for leadership teams that want better protection and fewer surprises.

1. Secure Microsoft 365 and email access

  • Require multifactor authentication. Every user should have MFA, especially administrators, mailbox users, and anyone with access to billing, payroll, client data, or shared files.
  • Review admin roles. Keep the number of global administrators low and document who has elevated permissions.
  • Check shared mailboxes and forwarding rules. Unknown forwarding rules, stale shared access, and old aliases can create hidden exposure.
  • Use a repeatable offboarding process. Disable sign-in, preserve needed data, remove sessions, rotate shared passwords, and transfer ownership of files or mailboxes.

2. Protect workstations and endpoints

Workstations are where many security problems become visible. Employees open attachments, install tools, save browser passwords, connect to Wi-Fi, and access cloud data from these devices. Endpoint protection should be active, monitored, and part of normal support rather than something installed once and forgotten.

  • Use managed antivirus or endpoint protection. Make sure alerts are reviewed and not just displayed locally on a user's device.
  • Keep operating systems updated. Unsupported systems and old applications create avoidable risk.
  • Control local administrator rights. Users should not have unnecessary admin access on daily-use workstations.
  • Plan for lost or replaced devices. Know how to revoke access, recover files, and prepare replacement equipment quickly.

3. Make backups visible and testable

A backup that no one checks is more of a hope than a recovery plan. Businesses should know what is backed up, where it is stored, how long it is retained, who can access it, and how a restore would work after accidental deletion, hardware failure, ransomware, or a cloud account issue.

  • Document critical data locations. Include servers, cloud storage, Microsoft 365, accounting platforms, line-of-business applications, and local workstations if needed.
  • Check backup alerts. Failed backups should create a support action, not sit unnoticed.
  • Test restores. A small restore test is often the fastest way to find a weak recovery process before it matters.

4. Clean up network and vendor access

Routers, firewalls, Wi-Fi, switches, remote access tools, phone systems, and vendor accounts can become security blind spots. Businesses should know who manages each system, how credentials are stored, and whether old vendor or employee access still exists.

  • Inventory network equipment. Record router, firewall, switch, access point, and internet provider details.
  • Separate guest Wi-Fi. Guests and unmanaged devices should not share the same access as business systems.
  • Review remote access. VPN, remote support tools, and vendor portals should have named users and strong authentication.

5. Turn security into a recurring process

Cybersecurity improves when it becomes part of normal IT operations. A quarterly review of users, devices, backups, Microsoft 365 settings, vendor access, and recurring incidents can do more for a small business than a one-time security project with no follow-through.

Need a practical security review?

Smart IT Firm can review accounts, endpoints, backups, Microsoft 365, and recurring support risks for your Oregon or Washington business.