A simple small-business computer hygiene checklist

A practical baseline for passwords, MFA, updates, backups, email, domains, devices, and account ownership.

Most small businesses do not need to begin with exotic security products.

They need to consistently do the basic things that prevent ordinary mistakes from becoming expensive incidents.

Use unique passwords and a password manager

Every important account should have a unique password. Reusing the same password means one compromised service can expose several others.

A reputable password manager makes unique passwords realistic for humans.

Avoid storing the business’s master list in a shared spreadsheet, browser notes, email drafts, or a notebook next to the computer.

Turn on multi-factor authentication

Prioritize accounts that can unlock other accounts:

  • business email,
  • domain registrar,
  • password manager,
  • Microsoft 365 or Google Workspace,
  • banking and accounting,
  • cloud storage,
  • website administration,
  • social media.

Authenticator apps and security keys are generally preferable when the service supports them.

Keep operating systems and software updated

Enable automatic updates where practical.

Pay attention to laptops, desktops, phones, web browsers, office applications, routers, website platforms, plugins, and security software.

Old software is not dangerous merely because it is old. It becomes dangerous when it no longer receives fixes for known vulnerabilities.

Know what is backed up

Ask four questions:

  1. What data is actually included?
  2. Where is the backup stored?
  3. How far back can we recover?
  4. When did somebody last test restoring something?

Cloud synchronization and backup are not always the same thing.

Protect business email

Email is often the recovery path for every other service.

Remove departed staff promptly, require MFA, review forwarding rules after suspicious activity, and verify unusual payment or banking requests through a second channel.

Protect the domain name

The domain is easy to overlook because it normally just works.

Keep it in a business-controlled registrar account, enable MFA, use current recovery information, turn on auto-renew, and document who has access.

Keep an account inventory

You do not need a giant database.

Start with a list of the systems that would hurt if nobody could access them tomorrow: email, domain, website, accounting, banking, phones, cloud files, payroll, scheduling, CRM, and social media.

Record the service, business owner, administrative contact, renewal method, and recovery path.

Have a simple departure checklist

When someone leaves:

  • disable their account,
  • transfer business files,
  • preserve anything required for records,
  • remove access to shared systems,
  • rotate shared credentials that cannot be individually revoked,
  • update aliases and forwarding,
  • recover company devices.

Do it the same day when possible.

The point is resilience

Good computer hygiene is not about making technology perfect.

It is about making ordinary failures less damaging: a stolen password, a dead laptop, a forgotten renewal, a phishing message, an employee departure, or a vendor who is suddenly unavailable.

The boring controls are boring because they work.

Want a second set of eyes on your setup?

We can review your website, business email, domain, or everyday technology and give you a practical next step.