Nobody picked your business. The attack that finally lands will not come from someone who studied your company — it will come from a script that scanned a million internet addresses and found one unpatched box, one leaked password, one inbox willing to open an invoice. In Verizon’s 2026 Data Breach Investigations Report, 96% of ransomware victims were small and mid-sized businesses. Not because attackers prefer small companies — because small companies are easier.
The checklist below is the fix. Most of it is free, none of it needs a security team, and it is ordered roughly by how much trouble each item prevents per hour of effort. Work through it top to bottom.
Turn on multi-factor authentication everywhere
If you only do one thing this week, do this. Stolen or reused credentials still turned up in 39% of the breaches in that same 2026 Verizon report, and multi-factor authentication turns a stolen password from a master key into a useless piece of trivia. Start with email — whoever controls the inbox can reset every other account — then banking, payroll, accounting software and anything that holds customer data.
Use an authenticator app rather than text messages where the service allows it, and set up a backup method before you need one. Budget about twenty minutes per person; the full walkthrough is in our two-factor authentication guide.
Put the whole team on a password manager
People reuse passwords because remembering sixty unique ones is not a reasonable request. A password manager makes the secure path the lazy path: it invents a strong, different password for every account and types it for you. Buy team seats rather than letting everyone fend for themselves — when someone leaves, you revoke one login instead of wondering what they knew. It also retires the spreadsheet named passwords.xlsx, which at least one computer in your office almost certainly has.
Let everything update itself
For the first time in the nineteen years Verizon has published its report, the most common way into a breached company is not a stolen password — it is an unpatched software flaw, the entry point in 31% of breaches in the 2026 edition. The answer is policy, not diligence: automatic updates on for Windows, macOS, browsers and phones, and the restart prompt treated as an instruction rather than a suggestion.
The machines that hurt are the ones nobody thinks of as computers — the firewall, the Wi-Fi access points, the NAS in the closet. Put a recurring monthly reminder in the calendar to check their firmware, and retire anything that no longer receives updates at all. A router that last saw a patch in 2021 is not saving you money.
Back up, then prove the backup works
Ransomware’s whole business model is that your files exist in one place. The 3-2-1 rule — three copies, on two kinds of storage, one of them off-site — breaks that model, and the off-site copy should be one that a stolen administrator password cannot reach and delete. Cloud backup with version history does this well; a USB drive that stays plugged in does not.
Then restore something. Pick a file, recover last Tuesday’s version, time how long it takes. A backup you have never restored from is a hope, not a backup.
Protect the inbox — money leaves through email
The FBI’s 2025 internet crime report, released in April 2026, logged more than $3 billion in losses to business email compromise — the fake-invoice scam, which needs no malware at all, just a convincing email and a busy afternoon. The strongest defense costs nothing: a standing rule that no payment detail ever changes on the strength of an email alone. You call a number you already had on file, every time, no exceptions — and everyone who touches money knows how the scam actually runs.
While you are in there, have SPF, DKIM and DMARC configured on your domain, so the crooks cannot send mail as you either.
Give people the access their job needs — and no more
Nobody needs administrator rights to read email. Day-to-day work happens in standard accounts; the admin password comes out for installs and settings changes, then goes away again. That way one phished employee costs you one account, not the whole network.
The same thinking applies in time: access ends the day employment does. Accounts that outlive their owners are common enough that we keep a separate onboarding and offboarding checklist — the offboarding half is the one that prevents the horror stories.
Endpoint protection, honestly
You probably do not need to buy antivirus. Microsoft Defender ships with Windows, is already switched on, and has been a serious product for years — not the afterthought it was in 2010. An expensive security suite nobody ever opens loses to the built-in one plus everything else on this list, and the industry does not enjoy saying that out loud.
Paid tools start earning their keep at the monitored end — endpoint detection that a human actually watches, looking at behavior rather than signatures. That is worth real money once you have a dozen machines and something to lose. It is pointless while MFA is still off.
Split the Wi-Fi
Your card terminal should not share a network with a customer’s phone. Two networks minimum: one for business machines, one for guests and personal devices. If you run a restaurant, salon or shop, set guest Wi-Fi up properly instead of taping the main password to the till. Cheap smart devices — cameras, TVs, thermostats — belong on the guest side too; they are the printers of the security world, forever doing something unexpected.
Write the incident plan on one page
Whatever goes wrong will go wrong at 4:50 on a Friday. Print one page and keep it near the router. On it:
- Who gets the first call — your IT person, or a technician through Koadi at (848) 266-6363.
- Your bank’s fraud desk and your insurer’s claims number.
- The disconnect drill: unplug affected machines from the network, leave them powered on, wipe nothing.
That page changes outcomes. The 2026 Verizon report puts the median ransom paid at $139,875 — and notes that 69% of victims paid nothing at all, a far easier position to take when your backups restore and everyone knows their first move. If the worst does arrive, here is how the first 24 hours should run.
The insurance questionnaire is a preview of the claim
Cyber insurance is worth pricing, but read the application form for what it is: a list of promises. It will ask whether you have MFA, tested backups, patching and proper offboarding — this checklist, in insurance language — and carriers do refuse claims when those answers turn out to have been optimistic. Answer honestly, and treat every box you cannot tick as the next item to fix. The same measures that make you insurable are the ones that make the claim unnecessary.
Making the list someone’s job
Everything above can be done in-house; the usual failure is that nobody owns it. Koadi closes that gap two ways. Post any single item free as a job — an MFA rollout, backup setup, Wi-Fi segmentation — then set a fixed price or take bids from vetted, identity-verified technicians, with payment held in escrow until you approve the work. Remote help covers every US state, evenings and weekends included; on-site visits come through local techs. For the fuller picture, Koadi delivers VAPT — a vulnerability assessment and penetration test showing which of these gaps are visible from outside — and managed IT that makes patching, backups and offboarding somebody’s actual job. Call (848) 266-6363 or email help@koaditech.com.