Skip to main content
Field Guide · Security3 min read

Cybersecurity Foundations for Small Organizations

Cybersecurity can feel overwhelming because the subject is often presented as an endless list of products, threats, and technical terms. A strong security program does not begin by buying everything. It begins by identifying what the organization depends on, reducing the most likely risks, assigning responsibility, and building a small number of protections that can be maintained consistently.

Start With Responsibility

Cybersecurity is an organizational responsibility, not only an IT task. Leadership should understand:

  • What information the organization holds
  • Which systems are essential
  • Who is responsible for security decisions
  • Which legal, contractual, insurance, or industry requirements may apply
  • How incidents will be reported
  • What level of disruption the organization can tolerate
The NIST Cybersecurity Framework 2.0 organizes cybersecurity work around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Small organizations do not need to implement every possible control at once — the framework can be used to create a practical sequence of improvements.

Know What You Have

An organization cannot protect systems it does not know exist. Maintain a basic inventory of:

  • User accounts
  • Administrator accounts
  • Computers
  • Mobile devices
  • Servers
  • Network equipment
  • Cloud services
  • Websites
  • Vendors
  • Important data
  • Software subscriptions
  • Backup systems
The inventory does not need to begin as a sophisticated database. A maintained spreadsheet or list is better than relying on memory. Include ownership, purpose, support status, renewal dates, and who has access.

Protect Accounts With Multifactor Authentication

Passwords alone are not enough. Multifactor authentication requires another method of verification in addition to the password. This can prevent an attacker from accessing an account even when the password has been stolen.

Require MFA for:

  • Email
  • Administrative accounts
  • Remote access
  • Financial systems
  • Human-resources systems
  • Cloud applications
  • Any service containing sensitive information
Where available, use phishing-resistant authentication such as passkeys, security keys, or other FIDO-based methods for administrators and high-risk roles.

Protect Administrative Access

Administrative accounts can change settings, create users, access information, and weaken security controls. Limit the number of administrators. Use:

  • Separate accounts for administrative work
  • MFA on every administrator
  • Least-privilege roles
  • Regular access reviews
  • Documented emergency-access procedures
  • Prompt removal of unnecessary privileges
People should not use highly privileged accounts for ordinary email and web browsing.

Keep Systems Supported and Updated

Unsupported or unpatched systems create preventable risk. Establish a repeatable process for:

  • Operating-system updates
  • Application updates
  • Browser updates
  • Network-device firmware
  • Website plugins
  • Security products
  • Cloud-service configuration reviews
Prioritize actively exploited vulnerabilities and internet-facing systems. Updates should be monitored rather than assumed. A policy is not complete unless someone can confirm that it is working.

Protect Devices and Email

Every organization should use appropriate endpoint and email protections. That may include:

  • Antivirus and endpoint detection
  • Device encryption
  • Screen-lock requirements
  • Central device management
  • Remote-wipe capability
  • Spam and phishing protection
  • Attachment and link protection
  • Restrictions on local administrative rights
  • Secure configuration standards

Back Up What Matters

Backups should protect the information and systems the organization would need after:

  • Accidental deletion
  • Hardware failure
  • Ransomware
  • Account compromise
  • Vendor failure
  • Fire, theft, or another physical event
A backup that has never been restored is an assumption, not a recovery plan.

Prepare People

Many security incidents begin with a message, phone call, login prompt, or request that appears normal. Training should help people recognize and report:

  • Phishing
  • Unexpected MFA prompts
  • Payment-change requests
  • Password-reset scams
  • Requests for sensitive information
  • Suspicious attachments
  • Impersonation
  • Lost or stolen devices
Create a simple reporting path. People should know exactly whom to contact and should not fear punishment for reporting a mistake quickly.

Create a Basic Incident Plan

Before an incident occurs, document:

  • Who should be contacted
  • Who can disable accounts
  • Who can isolate devices
  • Who communicates with leadership
  • Who contacts vendors, insurers, legal counsel, or law enforcement when appropriate
  • How evidence will be preserved
  • How normal operations will be restored
  • How affected people will be informed when required

Build Security in Layers

No individual product or control can prevent every incident. Security becomes stronger when several protections work together:

  • Good governance
  • Accurate inventory
  • MFA
  • Protected administrator accounts
  • Supported devices
  • Regular updates
  • Endpoint protection
  • Secure backups
  • User awareness
  • An incident plan
A smaller set of protections that is owned, documented, and reviewed is more valuable than a long list of tools no one is actively managing.

Where to Go Next

Security assessments, identity hardening and monitoring are part of our managed technology and cybersecurity services.

Two related guides go a level deeper: Microsoft 365 for Nonprofits covers identity in the platform most organizations already own, and Backup vs. Disaster Recovery covers the recovery half of the plan. Planning the Device Lifecycle explains why unsupported hardware quietly becomes a security problem.

Common Questions

What cybersecurity controls should a small organization put in place first?

Identity protection with multifactor authentication, prompt patching, tested backups, managed device security, basic user awareness, and a written incident plan.

Does a small nonprofit really need an incident response plan?

Yes. Most attacks are automated and do not filter by organization size. A short written plan covering who is called, what is disconnected and how systems are restored matters far more than its length.

Thoughtful Insights

Get the next guide when it is published.

A few thoughtful updates each year — practical guidance, new resources, and important security insights. No spam, no filler.

A few thoughtful updates each year. No spam. Unsubscribe anytime.

Related Resources

Have Questions or Want to Discuss Your Organization's Technology?

We'd love to learn more about your goals and how we can help.

We also run four community programs across Colorado, at no cost to take part — technology help for older adults, technology learning for ages 13–24, records help for veterans, and drop-in help at shelters and day centers. See the programs.