The SMB Cyber Security Checklist: 15 Controls Every Small Business Must Have in 2026
A practical, actionable cyber security checklist for small and medium businesses. These 15 controls cover the most critical security gaps that lead to breaches, ransomware, and compliance failures — with specific implementation steps for each.
Checklist Overview
Small businesses are the #1 target for cyber attacks — not because they are valuable, but because they are accessible. According to recent threat intelligence, 43% of all cyber attacks target small businesses, and 60% of those businesses close within 6 months of a major breach.
The good news: the controls that prevent most breaches are not complicated. This cyber security checklist covers the 15 most impactful security controls a small business can implement — many of which cost nothing beyond the time to configure them.
Sentrivox automatically checks and monitors 8 of these 15 controls on every Windows endpoint — giving you continuous visibility into your security posture without manual audits.
The 15-Control SMB Cyber Security Checklist
Enable Windows Firewall on All Profiles
CriticalEndpoint HardeningEnsure Windows Firewall is active on Domain, Private, and Public network profiles on every device. A disabled firewall is an open door for lateral movement after initial compromise.
Enable & Update Windows Defender
CriticalEndpoint HardeningWindows Defender must be enabled with real-time protection active and definitions updated within the last 24 hours. Outdated definitions cannot detect recent malware variants.
Disable SMBv1 Protocol
CriticalEndpoint HardeningSMBv1 is the vulnerability exploited by WannaCry ransomware and should be disabled on all Windows endpoints. Check via PowerShell: Get-SmbServerConfiguration | Select EnableSMB1Protocol
Disable or Delete Guest Accounts
HighAccess ControlGuest accounts on Windows endpoints provide unauthenticated local access and should be disabled or deleted. Enabled guest accounts were present in 23% of SMB breaches analyzed in 2025.
Enforce Multi-Factor Authentication
CriticalAccess ControlMFA should be required for all remote access, email, and cloud services. MFA blocks 99.9% of automated account compromise attacks according to Microsoft's data.
Enforce Password Complexity Policy
HighAccess ControlRequire minimum 12-character passwords with complexity requirements. Enable account lockout after 5 failed attempts. Use group policy to enforce across all Windows endpoints.
Require NLA for Remote Desktop
HighRemote AccessNetwork Level Authentication (NLA) for RDP requires valid credentials before establishing a full RDP session, preventing pre-authentication exploits like BlueKeep.
Set RDP Encryption to High
HighRemote AccessConfigure RDP Security Layer to "SSL (TLS 1.0)" minimum and Encryption Level to "High" or "FIPS Compliant" to protect session data in transit.
Automate Windows Updates
CriticalPatch ManagementConfigure Windows Update for automatic download and installation of security patches. Unpatched systems are the #1 vector for ransomware in SMB environments.
Track Missing Patches by CVE
HighPatch ManagementKnow which CVEs are unpatched across your fleet and prioritize by CVSS score and EPSS exploit probability. Not all patches are equally urgent — triage by actual risk.
Maintain a Complete Asset Inventory
CriticalAsset ManagementYou cannot protect what you cannot see. Use automated IT asset management software to continuously discover and track every device on your network.
Track All Installed Software
HighAsset ManagementInventory all installed applications including version numbers. Unknown or outdated software on endpoints creates vulnerability exposure that is invisible without software asset management.
Implement the 3-2-1 Backup Rule
CriticalBackup & Recovery3 copies of data, on 2 different media types, with 1 copy offsite (cloud). Test your backups quarterly — a backup you have never tested is not a backup.
Generate Monthly Security Reports
MediumComplianceRun compliance reports monthly against your policy framework (ISO 27001, CIS, or internal). Monthly reviews catch drift before it becomes an audit finding or a breach.
Document an Incident Response Plan
HighIncident ResponseHave a written incident response plan that covers: detection, containment, eradication, recovery, and post-incident review. Practice it with a tabletop exercise at least annually.
Automate 8 of These 15 Controls with Sentrivox
Sentrivox automatically monitors controls #01–08 (Firewall, Defender, SMBv1, Guest Account, Password Policy, RDP NLA, Auto-Update, and RDP Encryption) on every Windows endpoint — running checks on every 15-minute heartbeat and flagging failures instantly on your dashboard.
The remaining 7 controls (MFA, patch management, asset inventory, software tracking, backup, compliance reporting, and incident response) are covered through Sentrivox's IT asset management module, compliance reports, and integrations.
