An employee receives an urgent email that appears to come from a familiar supplier. It requests a change to banking details before the next invoice is paid. The message looks routine, the deadline feels real, and the employee wants to keep business moving. But if the request is fraudulent, one ordinary decision can become a serious financial loss.
This hypothetical scenario illustrates a central cybersecurity lesson: protecting a business depends on more than buying security software. It requires clear ownership, reliable processes, protected accounts, maintained systems, and the ability to recover when something goes wrong.
The NIST Cybersecurity Framework 2.0 organizes that work into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. For business leaders, these translate into practical questions: What matters most? Who is responsible? How do we prevent avoidable problems? How will we recognize trouble, contain it, and restore operations?
1. Know What Matters—and Who Owns the Risk
Start with the business, not the technology. Identify which activities must continue for your organization to serve customers, pay employees, meet commitments, and generate revenue. Then identify the systems, information, accounts, and providers supporting those activities.
A useful starting inventory includes:
- Critical systems: Email, accounting, payroll, customer records, operational software, and websites.
- Sensitive information: Employee data, payment details, customer information, contracts, and intellectual property.
- Important accounts: Administrator accounts, financial accounts, and accounts that can reset other users’ access.
- External dependencies: Cloud platforms, managed service providers, payment processors, and other essential vendors.
Assign an owner to each critical system and a leader responsible for security decisions. An IT provider may perform the work, but leadership remains responsible for deciding which risks the business can accept.
For example, if your accounting platform becomes unavailable, who contacts the provider, determines whether payroll is affected, and authorizes an alternative process? Answering that question before a disruption is governance in practice.
2. Protect Accounts Before Adding More Tools
Compromised accounts can give attackers access to conversations, documents, payment workflows, and other systems. Begin with email, banking, accounting, and administrator accounts, then expand protections across the organization.
Use Unique Passwords and a Password Manager
Every account should have a unique password. Reusing passwords means a compromise at one service can expose accounts elsewhere. A password manager helps employees create and store strong passwords without relying on memory or shared spreadsheets.
Use individual accounts where possible. When shared credentials are unavoidable, control access through an approved system and update access when employees change roles or leave.
Choose Strong Multifactor Authentication
Enable multifactor authentication, or MFA, wherever available. It adds protection beyond a password, but methods differ significantly.
NIST’s authentication guidance distinguishes phishing-resistant methods from methods attackers can trick people into completing. FIDO2 passkeys with user verification support phishing-resistant authentication because authentication is bound to the legitimate service. Manually entered authenticator codes and SMS codes are not phishing-resistant.
Prefer phishing-resistant options where supported. Other MFA methods can still reduce risk compared with passwords alone, but employees should never share codes or approve unexpected prompts. No authentication method makes an account unhackable; device security, recovery settings, and access management still matter.
3. Verify Requests Involving Money or Access
Attackers often exploit familiar business processes rather than technical weaknesses. A request may impersonate an executive, a supplier, or a support representative. It may even arrive from a genuinely compromised account.
The strongest response is a repeatable verification rule: independently confirm unexpected payment requests, changes to banking details, and requests for credentials or sensitive information.
The FBI’s guidance on business email compromise recommends verifying changes in account numbers or payment procedures with the requester. Use a previously established phone number or one located independently—not contact information supplied in the questionable message.
For example, if a supplier emails new bank details, pause the payment and call the supplier using your existing records. Replying to the email does not independently verify the request.
- Document the verification process so employees do not have to improvise.
- Require a second approver for sensitive payment changes.
- Make clear that urgency and executive seniority do not override the process.
Do not rely solely on poor spelling or awkward wording to identify fraud. A polished message is not proof of authenticity.
4. Maintain Systems and Limit Access
Security fundamentals become less effective when devices go unpatched, default passwords remain unchanged, or former employees retain access. The FTC’s small-business cybersecurity guidance highlights practical safeguards such as software updates, encryption, and access restrictions.
Translate those safeguards into routine responsibilities:
- Keep software supported and updated. Enable automatic updates where appropriate. For critical systems, establish a maintenance process that accounts for compatibility and downtime.
- Remove default credentials. Change factory passwords on devices and services before putting them into use.
- Encrypt sensitive information. Protect data on laptops and other storage, and use secure methods when transmitting it.
- Apply least privilege. Give people only the access needed for their work. Separate everyday accounts from administrator accounts.
- Review access changes. Remove unnecessary permissions when roles change and promptly disable access when someone leaves.
Include new applications in this process. An employee should not upload confidential business information to an unapproved AI tool simply because it makes a task easier. Establish clear rules for which services may handle sensitive data.
5. Decide How You Will Recognize Trouble
Prevention is essential, but detection closes the gap between something going wrong and someone taking action. Decide which warning signs matter and who will review them.
Useful signals include unexpected MFA prompts, unfamiliar account sign-ins, unexplained mailbox forwarding rules, unusual administrator changes, failed backups, and unexpected financial activity.
Where supported, enable relevant security alerts and retain logs that can help investigate an incident. Ask your IT team or service provider who receives alerts, how they are assessed, and when leadership is notified.
Give employees a simple reporting channel for suspicious messages and unusual device behavior. Encourage early reporting—even after someone clicks a link. A culture of blame can turn a quickly contained mistake into a prolonged incident.
6. Make Recovery a Tested Capability
A backup is useful only if the business can restore what it needs. A successful backup notification does not prove that files are intact, applications can run, or recovery will happen quickly enough.
Start by defining how long critical operations can be unavailable and how much recent data the business can afford to lose. Use those requirements to guide backup frequency and recovery planning.
- Back up essential data and the configurations needed to restore important systems.
- Keep protected copies that a compromised everyday account cannot easily alter or delete.
- Test restoration regularly and after significant system changes.
- Check backup integrity before restoring data following an incident.
- Document dependencies, recovery steps, and access to necessary credentials.
For example, restoring an invoice spreadsheet is not enough if employees still cannot access the accounting platform required to process payments. Test the business activity, not just the file.
The practical test of resilience is whether your business can resume essential work—not whether a backup dashboard shows green.
7. Prepare a Short Incident-Response Plan
A useful response plan should be easy to find and follow under pressure. It does not need to begin as a lengthy manual.
Document who coordinates the response, who provides technical support, which operations take priority, and who can authorize emergency spending. Include contact details for relevant providers, your insurer if applicable, legal counsel, and financial institutions. Keep a securely accessible copy outside your primary business systems.
Plan how to communicate if email is unavailable or compromised, and how essential work can continue while systems are investigated. Avoid sending sensitive response discussions through an account suspected of compromise.
For suspected payment fraud, contact the financial institution immediately to ask about stopping or recalling the transaction. The FBI also advises reporting the incident to its Internet Crime Complaint Center. Preserve relevant messages and transaction details.
Work with qualified responders on containment and evidence preservation. Avoid wiping devices or deleting suspicious messages before receiving guidance. Periodically rehearse a realistic scenario and update the plan when gaps emerge.
A Seven-Day Cybersecurity Starter Checklist
This proposed checklist creates momentum; it does not make a business fully secure in a week.
- Day 1: Inventory critical systems, accounts, information, and providers.
- Day 2: Review MFA coverage, prioritizing sensitive and administrator accounts.
- Day 3: Establish an independent payment-change verification procedure.
- Day 4: Review software updates, unsupported systems, and unnecessary access.
- Day 5: Test restoration of an important backup and record the result.
- Day 6: Write down incident contacts, response responsibilities, and alternative communication methods.
- Day 7: Assign owners and review dates for unfinished work.
Make Cybersecurity a Leadership Habit
Cybersecurity is an ongoing management discipline, not a one-time purchase. These fundamentals reduce risk, but they do not eliminate attacks, guarantee compliance, or replace an assessment tailored to your business.
Start today by naming a security owner and scheduling a review of your most critical accounts and systems. Then turn identified gaps into assigned tasks, tested procedures, and regular leadership conversations. Consistent execution—not a promise of perfect protection—is what builds a more resilient business.