
Small and medium businesses are not “too small to target.” They use valuable email accounts, payment channels, customer records, cloud platforms and social profiles—often with less time and specialist support than a large organisation.
This checklist adapts the practical priorities in the NIST Cybersecurity Framework 2.0 small-business guide and CISA’s small-business resources into actions a Nepal business can own, measure and improve.
The first five controls: establish a safe baseline
1. Assign one accountable security owner
Someone must know who approves access, who receives alerts, where backups are stored and who coordinates during an incident. The owner may use an external specialist, but accountability should remain clear inside the business.
2. Inventory critical systems, accounts and data
List email, banking, accounting, customer databases, websites, domains, cloud services, social accounts, devices and important suppliers. Mark what would stop revenue, expose customers or damage trust if unavailable.
3. Require multifactor authentication
Start with email, cloud administration, remote access, banking, accounting, domain registration and social media. Prefer phishing-resistant methods when available and remove old recovery numbers or accounts.
4. Use a business password manager
Each account should have a unique password. Shared passwords in chat, spreadsheets or browsers make access difficult to revoke and incidents difficult to investigate.
5. Keep supported software patched
Enable automatic updates where practical. Track operating systems, browsers, routers, firewalls, plugins, website platforms and business applications that require manual updates.
Controls six to ten: protect operations and recovery
6. Maintain isolated, tested backups
Keep at least one backup that cannot be changed by a compromised everyday account. Define what must be restored first, how long the business can wait and who has tested the recovery steps.
7. Limit administrator access
Use everyday accounts for normal work and separate administrator accounts for changes. Remove access promptly when staff or vendors leave, and review privileged accounts every quarter.
8. Secure email and business domains
Configure SPF, DKIM and DMARC, protect the domain registrar with MFA and monitor lookalike domains or fake social profiles. Email and public identity are often the shortest path to fraud.
9. Protect endpoints and networks
Use centrally managed endpoint protection where possible, encrypt laptops, change default router credentials, separate guest Wi-Fi and restrict remote administration from the public internet.
10. Configure cloud services deliberately
Review sharing links, public storage, administrator roles, third-party app permissions and security alerts. Cloud platforms are powerful, but insecure defaults and unmanaged access can expose data quickly.
Controls eleven to fifteen: manage people, suppliers and response
11. Train staff with realistic examples
Teach employees how to verify payment changes, unusual executive requests, password-reset messages and suspicious attachments. Provide a simple reporting channel that rewards early reporting rather than hiding mistakes.
12. Assess important suppliers
Record who can access your data or systems, what security commitments exist, how incidents will be reported and how access will be removed when the relationship ends.
13. Turn on useful logs and alerts
At minimum, retain sign-in, administrator, email-forwarding, cloud-sharing and endpoint alerts. Decide who reviews them and what activity requires escalation.
14. Write a one-page incident response plan
Include emergency contacts, decision makers, technology providers, insurance, legal support, priority systems and a rule for preserving evidence. Rehearse one realistic scenario each year.
15. Review and test the environment
Run regular vulnerability checks, review access and conduct authorised security testing based on exposure and change. Track remediation to closure instead of treating the report as the end of the work.
A realistic 90-day rollout
| Period | Priority actions | Evidence of progress |
|---|---|---|
| Days 1–30 | Owner, asset list, MFA, administrator review, critical updates | Named owner, inventory and protected high-risk accounts |
| Days 31–60 | Test backups, password manager, email/domain controls, staff briefing | Successful restore test and documented access process |
| Days 61–90 | Supplier review, useful logging, incident plan and security assessment | Open-risk register with owners and target dates |
If the budget is limited, spend in this order
- Protect email, administrators and financial accounts with strong MFA.
- Make backups recoverable and independent of everyday credentials.
- Remove unsupported software and patch exposed systems.
- Train staff to verify payment, password and executive requests.
- Assess internet-facing systems and close the highest-impact gaps.
A clear owner and reliable process often reduce more risk than buying another dashboard nobody monitors.
Frequently asked questions
Where should a small business start?
Assign an owner, list critical systems, enable MFA on high-risk accounts, patch supported software, test backups and document incident contacts.
Which accounts need MFA first?
Email, cloud administration, banking, accounting, domain, social media and remote-access accounts should be the first priority.
How often should backups be tested?
Test them often enough to prove the business can meet its recovery target. Critical services may require more frequent tests than archive data.
Find the gaps that matter most to your business.
Innomerc Tech can review controls, infrastructure and internet-facing exposure, then organise improvements into a practical plan.
