You don’t have a security department. You have a business to run, a team that needs their email and files to work, and a growing pile of questions from clients, insurers, and software vendors about “your controls”. This checklist is the answer to those questions — the controls that a Tulsa business with 10 to 100 people should have in place, in the order they matter, in plain language.
Who this checklist is for
Owners, presidents, CFOs, and office managers who are responsible for the business but not trained in security. It applies to CPA and financial firms, engineering and construction firms, HVAC, plumbing, and electrical contractors, and professional services teams across the Tulsa metro. If you already have an IT provider, use it to check what is actually covered. If you don’t, use it to know what to ask for.
Why these controls and not a longer list?
Most attacks on small businesses are not clever. They are a stolen password, a convincing email, an unpatched laptop, or a backup nobody tested. Microsoft has reported that turning on multi-factor authentication alone blocks more than 99.9% of account compromise attacks. The controls below follow that logic: the handful of things that stop the common attacks, then the things that make a bad day recoverable.
- 1People
Security awareness guidance so your team spots what tools miss.
- 2Email
Filtering and hardening for the door most attacks knock on.
- 3Identity & access
MFA, conditional access, and least-privilege for Microsoft 365 and beyond.
- 4Devices & network
Endpoint detection and response, patching, and managed network security.
- 5Backup & recovery
Tested backups and a continuity plan — the layer that makes a bad day recoverable.
The SMB cybersecurity checklist
1. Identity and access
- MFA everywhere it can be turned on — Microsoft 365 or Google Workspace, remote access, banking, payroll, your line-of-business software. Prefer an authenticator app over text messages.
- One person, one account, no sharing. Shared logins make it impossible to know who did what and impossible to remove one person cleanly.
- Least privilege. Day-to-day accounts are not administrators. Admin rights are separate, limited, and logged.
- Same-day offboarding. When someone leaves, every account is disabled the day they go — email, remote access, cloud apps, phone system.
- A password manager for the team, so long unique passwords are the easy path, not the heroic one.
2. Email
- Filtering that catches phishing, malicious attachments, and look-alike domains before they reach an inbox.
- SPF, DKIM, and DMARC set up on your domain so criminals cannot easily send email that looks like it came from you — this also improves deliverability of your real mail.
- A written rule for money movement: no wire, ACH change, or gift-card purchase on the strength of an email alone. Verify by phone using a number you already have.
3. Devices
- Endpoint detection and response (EDR) on every computer, not just antivirus. EDR watches behaviour and can isolate a machine that starts acting like ransomware.
- Patching on a schedule for operating systems, browsers, and the applications your team uses — with someone confirming it actually happened.
- Disk encryption turned on for laptops, so a device left in a truck or airport is an inconvenience, not a breach.
- An inventory. You cannot protect a laptop you don’t know exists.
4. Backup and recovery
- Backups of everything that matters — servers, Microsoft 365 or Google Workspace, and any line-of-business system — with at least one copy stored where ransomware on your network cannot reach it.
- Restore tests on a calendar. A backup that has never been restored is a hope, not a plan. Ask when the last test was and what it proved.
- Agreed recovery targets: how much data you can lose (hours? a day?) and how long you can be down. Those numbers decide what the backup design should be.
5. Network and remote access
- A business-grade firewall that is kept updated, with remote management that is not open to the internet.
- Secure remote access — VPN or a modern equivalent — with MFA. No exposed remote desktop.
- Guest Wi-Fi separated from the network your servers and workstations live on.
6. People
- Short, regular awareness training and simulated phishing, so the team gets practice spotting the real thing.
- A no-blame reporting habit: the person who clicked and told you within five minutes just saved the business. Make that the culture.
7. Vendors, insurance, and paperwork
- A written information security plan. CPA and tax firms are required to have one under the FTC Safeguards Rule; every business benefits from a page that says who does what.
- An incident response plan — one page: who to call (IT, insurer, attorney, bank), what to shut down, what to preserve.
- Cyber-insurance application answered truthfully. Insurers now ask specifically about MFA, EDR, and offline backups. If the answers are “no”, fix them before you renew.
- Vendor access reviewed: who from outside the company can get into your systems, and does each still need to?
How to use the checklist
- Score yourself honestly. Green, yellow, red for each line. Most Tulsa businesses we meet for the first time are red on restore testing and yellow on MFA — you are not behind, you are normal.
- Fix the reds in sections 1, 3, and 4 first. MFA, EDR, and tested backups are the three controls that turn a catastrophe into an inconvenience.
- Assign an owner to each line. Either your IT provider or a named person on your team. “Everyone” means no one.
- Review it quarterly. Ten minutes in a planning meeting keeps it current as people, devices, and software change.
Common mistakes we see
- MFA on email but not on remote access — or the other way around. Attackers try every door.
- Antivirus mistaken for EDR. They are not the same, and insurers know the difference.
- Backups that live on the same network as everything else, so ransomware encrypts the backup along with the files.
- The former employee whose account still works because offboarding is a checklist nobody owns.
- Assuming your IT provider is doing all of this. Ask for it in writing. A good provider will be glad you asked.
What this looks like in Tulsa
The businesses that keep the metro running — an engineering firm off Yale Avenue, a CPA office in Broken Arrow, an HVAC contractor with trucks from Owasso to Jenks — are exactly the size criminals target: enough money and data to be worth it, rarely a security team to notice. The good news is that the controls above are well within reach of a 20-person company. They don’t require an enterprise budget; they require someone to own them.
NSN Management builds these controls into cybersecurity services and managed IT for Tulsa-area businesses, and reviews the checklist with you on a schedule so it stays true. If you would like a second set of eyes on where you stand, book a Discovery Call — we will walk the list with you and tell you plainly what is covered and what is not.
Questions Tulsa businesses ask about this
What are the three most important cybersecurity controls for a small business?
Multi-factor authentication on every account that supports it, endpoint detection and response (EDR) on every computer, and backups with an offline copy that are restore-tested on a schedule. Those three turn most incidents from a catastrophe into an inconvenience.
Is antivirus enough for a small business?
No. Traditional antivirus matches known bad files; endpoint detection and response (EDR) watches behaviour and can isolate a machine that starts encrypting files. Cyber-insurance applications increasingly ask for EDR specifically.
Do Tulsa CPA firms have specific cybersecurity requirements?
Yes. Tax preparers and CPA firms fall under the FTC Safeguards Rule, which requires a written information security plan, a designated person responsible for it, MFA, encryption, and staff training, among other controls. The IRS also publishes guidance for tax professionals in Publication 4557.
How often should a small business test its backups?
Restore tests should be on a calendar — quarterly at minimum, monthly for systems the business cannot run without. Each test should prove a specific file, mailbox, or server can be recovered within the time you have agreed is acceptable.
What do cyber-insurance carriers ask small businesses about?
Applications commonly ask whether MFA is enforced on email, remote access, and admin accounts; whether EDR is deployed; whether backups are offline or immutable and tested; whether staff receive security awareness training; and whether you have an incident response plan. Answer truthfully — a misstatement can void coverage.
Can NSN Management review our checklist with us?
Yes. A Discovery Call includes a walk through these controls against your actual environment, with a plain statement of what is covered, what is not, and what to fix first.