Practical security guides written in plain English for business owners and the people who work for them. No jargon, no scare tactics, just clear steps you can put to work this week.
This library collects our practical security guides for small business owners and their teams. Each guide tackles one real problem (setting up MFA, spotting phishing emails, preparing for ransomware, rolling out a password manager, or getting ready for a cyber insurance application) with steps you can follow even if IT is not your day job. When you finish a guide, take the free 12-question cyber risk assessment to see where your business stands, or book a free 30-minute security awareness session for your team, delivered in English, Spanish, or Portuguese.
A step-by-step walkthrough for turning on multi-factor authentication in Microsoft 365, from enabling security defaults to getting your whole team on Microsoft Authenticator. It is one of the cheapest ways to block account takeovers, and you can finish it in an afternoon.
Seven red flags that give away a phishing email, shown with realistic examples so you know what each one looks like in your inbox. Share it with your team and turn every employee into a second line of defense.
What to do before an attack (backups, MFA, patching), during one (who to call, what to unplug, what not to touch), and after (recovery, reporting, insurance). A plan you can print and keep next to the router.
How to pick a password manager (we cover 1Password and Bitwarden), set it up for a small team, and get everyone actually using it. Includes a rollout plan that handles the inevitable “I like my sticky notes” objections.
The controls insurers now expect before they write or renew a policy: MFA, backups, endpoint protection, and more. Use this checklist to answer the application honestly, avoid a denied claim, and put yourself in a stronger position at renewal.
A free 10-minute check that shows whether your company addresses and passwords are already circulating from past breaches, plus the fix list for what you find: resets, unique passwords, MFA, and closing ghost accounts.
Attackers research your business before they attack it, using free tools anyone can use. Run the same five searches on yourself, from Google operators to Shodan, and close the doors they are counting on.
People-search sites sell home addresses and cell numbers for your whole team, and attackers are buying. The afternoon cleanup that removes the profiles, and the process habits that make the data useless anyway.
The changed bank account scam is the most expensive cybercrime, and it arrives as a normal-looking email no filter catches. How the scam runs, the three verification rules that beat it, and what to do in the first 24 hours if money already left.
Sync tools replicate ransomware as faithfully as they replicate good data. What the 3-2-1 rule means for a small office, the two details that make backups attacker-proof, and why an untested restore is a hope, not a plan.
When someone leaves, the farewell card gets organized faster than the accounts get closed. The same-day access cutoff, the data preservation steps, and the leftovers everyone forgets, from SaaS seats to MFA codes on a departed phone.
Twelve yes-or-no questions, two minutes, no email required. Score your security and see exactly which gaps to close first.
A free 30-minute remote session for your team, in English, Spanish, or Portuguese. One trained employee blocks the attack an untrained one clicks.
Put in your numbers and see what an hour of downtime actually costs you in idle wages and lost revenue, then what it adds up to per year.
Yes. Every guide, the 12-question cyber risk assessment, and the 30-minute security awareness session are free with no obligation. We publish them because better-informed businesses make better decisions, and some readers eventually want help putting these steps in place. That is the whole arrangement.
No. They are written for business owners and office managers, not IT staff. Where a step needs admin access or gets genuinely technical, we say so plainly. And if you get stuck, you can call us at (978) 815-1047. We answer seven days a week, 9 to 6 Eastern.
We review the guides regularly and update them when the tools or requirements change, like when Microsoft moves a setting or insurers add new application questions. Security advice ages fast, so if you spot something outdated, tell us and we will fix it.
If you only do one thing, set up MFA. It blocks most account takeover attempts and costs nothing but a little setup time. Then take the free cyber risk assessment to see which guide covers your weakest area, and work through the library from there.