Cybersecurity Checklist for NYC Small Businesses
An effective cybersecurity checklist for an NYC small business should cover six outcomes: know what you depend on, protect accounts and devices, detect unusual activity, prepare a response, restore operations and assign someone to keep the program current. The goal is not to buy every security product. It is to reduce the most likely and costly gaps in a way the owner can verify.
Use this checklist as a working record. For every item, mark an owner, due date and evidence such as a screenshot, policy, device report or completed test. Revisit it after major staffing, software, location or vendor changes.
1. Assign Security Ownership and List Critical Assets
Name one person who is accountable for coordinating cybersecurity, even if technical work is handled by an outside provider. Record who may approve emergency changes, contact vendors and make operational decisions during an incident.
Create a current list of:
Business laptops, desktops, phones, tablets and network equipment
Email, file storage, accounting, banking, point-of-sale and customer systems
Administrators and other privileged users
Vendors with remote access or access to sensitive information
Data required for revenue, payroll, customer service and legal obligations
Rank systems by business impact. Start improvements with the accounts and devices that could stop operations, expose private information or authorize payments.
NIST's Cybersecurity Framework 2.0 small-business resources organize this work around Govern, Identify, Protect, Detect, Respond and Recover. That structure helps owners avoid treating security as only an antivirus or firewall project.
2. Protect Every Important Account
Require multifactor authentication for email, cloud storage, banking, accounting, remote access, website administration, social media and password managers. Start with administrator and finance accounts, then cover every employee account that supports it.
Use individual accounts rather than shared logins. Give each person only the access needed for the job, review administrative privileges regularly and remove access immediately when a worker or vendor leaves. A documented Microsoft 365 offboarding process helps prevent old accounts, forwarding rules and sessions from remaining active.
Store unique passwords in an approved password manager. Keep recovery codes in a controlled location that remains available if the normal email account is unavailable.
3. Secure and Maintain Business Devices
Turn on automatic operating-system, browser and application updates where practical. Establish a deadline and responsible owner for updates that cannot install automatically. Replace unsupported software and devices instead of accepting permanent exposure.
Use business-managed endpoint protection, screen locks and full-disk encryption. Confirm that lost devices can be disabled or wiped and that employees know how to report one immediately. Separate administrative accounts from everyday work and do not let staff install unapproved software.
For a repeatable inventory, patching and device standard, consider managed IT services rather than relying on memory or one-time cleanup.
4. Reduce Email and Payment Fraud Risk
Train employees to pause before acting on urgent requests involving passwords, invoices, gift cards, bank changes or confidential files. Give them a simple way to report suspicious messages without forwarding potentially harmful attachments.
Require a second communication channel to verify changes to payment instructions, payroll or vendor bank details. A phone call to a previously verified number is stronger than replying to the same email thread that may be compromised.
CISA's small and medium-sized business resources emphasize phishing avoidance, strong passwords, MFA, software updates, logging, backups and encryption as practical security essentials.
5. Protect the Network and Remote Access
Change default passwords on firewalls, routers, wireless access points, cameras and other connected devices. Keep guest Wi-Fi separate from business systems and payment devices. Disable unused remote-management features and require MFA for approved remote access.
Document the firewall, internet provider, Wi-Fi equipment, network administrator and support contacts for each location. Keep a protected copy outside the network so it remains available during an outage or compromise.
Review vendor access at least whenever a contract, employee or project changes. Remove dormant accounts and limit each provider to the systems and time period required for its work.
6. Back Up Data and Prove You Can Restore It
Identify the files, cloud data, databases and system configurations the business cannot recreate. Back them up on a schedule that matches how much recent work the business can afford to lose. Protect at least one recovery copy from routine administrator access or the same failure that could damage production.
Do not stop at a successful backup notification. Restore representative data, confirm it opens and record how long recovery takes. Use the IT disaster recovery test checklist to validate recovery priorities, credentials, communications and evidence before a real outage.
7. Prepare a One-Page Incident Response Plan
Write down the first actions for a suspected compromised account, stolen device, ransomware message, fraudulent payment request or exposed customer data. Include:
Who employees contact and how
Who may isolate a device or disable an account
IT provider, cyber-insurance, legal and key vendor contacts
Where logs, backups and recovery credentials are kept
How decisions and evidence will be documented
Who evaluates customer, contractual or regulatory notifications
Do not erase or rebuild a potentially compromised system before the response lead considers evidence preservation. For urgent help containing a suspected compromise, use a qualified incident-response provider or contact Sosa Solutions NYC about cybersecurity services.
8. Document New York Data Safeguards
The New York Attorney General explains that the SHIELD Act requires businesses that maintain private information to adopt administrative, technical and physical safeguards. The listed examples include assigning security coordination, identifying risks, training employees, selecting capable service providers, assessing network and software risks, responding to attacks and testing key controls.
This checklist is operational guidance, not legal advice. A business should have qualified counsel evaluate which New York and other legal, contractual or industry requirements apply to its data and incident-notification obligations.
A 30-Day Owner Action Plan
Days 1–7
Assign the security owner and emergency decision-maker.
Inventory critical systems, administrators and vendors.
Turn on MFA for email, banking and administrator accounts.
Remove accounts and remote access that are no longer needed.
Days 8–15
Confirm updates, encryption and endpoint protection on every business device.
Separate guest Wi-Fi and review firewall administration.
Document payment-change verification and phishing reporting steps.
Days 16–23
Review backup coverage and complete a controlled restore.
Write the one-page incident response plan.
Confirm offline access to emergency contacts and recovery information.
Days 24–30
Run a tabletop exercise with the owner, IT support and key managers.
Record gaps, assign deadlines and preserve evidence of completed controls.
Schedule the next access, backup and vendor review.
Turn the Checklist Into a Working Program
Cybersecurity improves when the business can show who owns each control, when it was checked and what evidence supports the result. Start with the highest-impact systems, close obvious account and recovery gaps, and build a repeatable review cadence.
Sosa Solutions NYC helps small businesses assess accounts, devices, cloud services, networks, backups and response readiness. Schedule a cybersecurity readiness review to turn this checklist into a prioritized plan for your locations and operations.



Comments