Category: blog
Cybersecurity baseline
Small and medium-sized businesses need a defined security baseline in 2026
Not a collection of disconnected tools
Not an antivirus subscription with no monitoring
A documented program covering access, infrastructure, detection, response, and recovery
The primary framework
NIST Cybersecurity Framework 2.0
Six functions
- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
The FTC small business cybersecurity guidance recommends NIST CSF 2.0 for organizations of every size
The framework is voluntary
Industry, contractual, regulatory, and insurance requirements may still apply
1. Multi-factor authentication

Passwords are not sufficient for business accounts
MFA should be required for:
- Microsoft 365
- Google Workspace
- VPN
- Remote access tools
- Accounting systems
- Payroll systems
- Banking portals
- Customer relationship management platforms
- Backup consoles
- Firewall administration
- Cloud administration
- Hosting and domain management
Priority accounts
- Global administrators
- Business owners
- Finance personnel
- Human resources personnel
- IT administrators
- Vendor accounts
- Accounts with access to sensitive data
Phishing-resistant MFA should be used where available
Preferred options include:
- Passkeys
- FIDO2 security keys
- Hardware tokens
- Device-bound authentication
Authenticator applications are preferred over SMS when stronger methods cannot be deployed
SMS should be treated as a fallback
MFA implementation requirements
- Disable legacy authentication
- Remove unused accounts
- Review administrator permissions
- Require separate administrator accounts
- Store recovery codes securely
- Test account recovery procedures
- Monitor failed authentication attempts
- Review new MFA enrollments
CISA guidance for small and medium-sized businesses identifies MFA as a priority control
MFA does not replace endpoint security
It reduces account takeover risk
Additional controls are still required
2. Business-grade firewalls

A consumer router is not a complete business security platform
A business firewall should provide:
- Stateful inspection
- Intrusion prevention
- VPN support
- Web and DNS filtering
- Access control
- Security event logging
- Firmware management
- VLAN support
- Device visibility
- Alerting
- Configuration backup
Firewall policies should use a default-deny approach
Inbound traffic should be blocked unless specifically required
Outbound traffic should be restricted where practical
Unused services and ports should be disabled
Remote administration should not be exposed directly to the internet
Remote access should use:
- MFA
- VPN
- Role-based permissions
- Device validation
- Session logging
- Time-limited vendor access
Firewall maintenance requirements
- Review rules at least quarterly
- Remove unused port forwards
- Document business justification for exceptions
- Update firmware
- Review administrator accounts
- Back up configurations
- Confirm logging is active
- Test failover where redundant equipment is deployed
CISA network infrastructure guidance supports secure configuration, segmentation, access control, and monitoring
3. Network segmentation
One flat network increases exposure
A compromised workstation should not provide unrestricted access to servers, backups, phones, cameras, or administrative systems
Separate network zones may include:
- Staff devices
- Servers
- Voice over IP systems
- Guest Wi-Fi
- Printers
- Security cameras
- Internet of Things devices
- Administrative systems
- Backup infrastructure
Guest Wi-Fi should be isolated from internal systems
Voice traffic should be separated where required for security and performance
Sensitive systems should be restricted to approved users and devices
Segmentation limits lateral movement
It also improves troubleshooting and monitoring
Network design should be documented
Documentation should include:
- Subnets
- VLANs
- Firewall rules
- Wireless networks
- Equipment locations
- Internet connections
- Vendor access paths
- Critical systems
- Recovery dependencies
X-Tek provides network design, network equipment, cabling, and network maintenance for business environments that require documented infrastructure
4. Continuous network monitoring

Prevention is not enough
Security events must be detected and reviewed
Monitoring should cover:
- Firewalls
- Routers
- Switches
- Wireless access points
- Servers
- Workstations
- Cloud identity platforms
- VPN connections
- Backup systems
- Remote access tools
- Email security systems
- Critical applications
Useful alerts include:
- Login attempts from unusual locations
- Repeated failed authentication
- New administrator accounts
- Disabled security controls
- Unauthorized devices
- New firewall rules
- Large outbound transfers
- Sudden bandwidth changes
- Malware detections
- Backup failures
- Endpoint encryption changes
- Suspicious PowerShell activity
- Unusual file access
- New services or open ports
Logging without review is not monitoring
Logs should be centralized where practical
Security notifications should be assigned to a responsible party
Escalation rules should define:
- What qualifies as an incident
- Who receives the alert
- How quickly it is reviewed
- Which systems may be isolated
- When customers or vendors are notified
- When law enforcement or regulators are contacted
Small businesses may not have staff available to review alerts overnight
An X-Tek managed IT support plan can provide continuous monitoring, maintenance, security management, backup oversight, and support
5. Endpoint protection and patching
Every device connected to business systems creates risk
Required controls include:
- Endpoint detection and response
- Supported operating systems
- Automatic security updates
- Application patching
- Full-disk encryption
- Screen lock enforcement
- Local firewall protection
- Removal of unsupported software
- Standard user permissions
- Device inventory
Patching should include:
- Workstations
- Servers
- Firewalls
- Routers
- Switches
- Wireless equipment
- Printers
- VPN appliances
- Web applications
- Cloud applications
Critical vulnerabilities should be prioritized
Patch status should be reported
Exceptions should be documented
Unsupported systems should be isolated or replaced
6. Backup and recovery controls
Security includes recovery
Backups should be:
- Automated
- Encrypted
- Monitored
- Access-controlled
- Stored off-site
- Protected from routine user accounts
- Tested through restoration procedures
The 3-2-1 backup model remains a useful baseline
- Three copies of important data
- Two storage types
- One copy stored off-site
At least one backup copy should be isolated from the production network
Backup administrators should use MFA
Backup deletion and retention changes should be logged
Recovery testing should confirm:
- Files can be restored
- Applications can be restored
- Servers can be rebuilt
- Credentials are available
- Recovery priorities are documented
- Recovery time objectives are achievable
A successful backup job does not prove recoverability
A restore test does
7. Email and identity security
Business email is a primary attack path
Email controls should include:
- SPF
- DKIM
- DMARC
- Malware filtering
- Link inspection
- Attachment scanning
- External sender identification
- Mailbox auditing
- MFA
- Conditional access
The FTC email authentication guidance explains how SPF, DKIM, and DMARC reduce domain spoofing
Financial requests should require secondary verification
Examples
- Wire transfers
- Bank account changes
- Payroll changes
- Gift card purchases
- Vendor payment changes
- Password reset requests
Verification should use a known phone number or separate communication channel
Not the contact information in the original message
8. Security policies and response planning
Technology controls require operating procedures
Every SMB should maintain written policies for:
- Passwords
- MFA
- Remote access
- Mobile devices
- Acceptable use
- Data retention
- Vendor access
- Backup retention
- Incident response
- Employee offboarding
The incident response plan should define actions for:
- Phishing
- Ransomware
- Lost devices
- Compromised credentials
- Business email compromise
- Unauthorized access
- Vendor incidents
- Data exposure
The plan should include contact information for:
- Management
- IT support
- Cyber insurance
- Legal counsel
- Key vendors
- Law enforcement
- Regulatory contacts
The plan should be tested
Lessons learned should be recorded
Controls should be updated after each exercise or incident
9. X-Tek managed IT
Cybersecurity operations require ongoing ownership
X-Tek can support SMB environments through:
- Managed support plans
- 24/7 security and backup monitoring
- Server maintenance and repair
- PC and Mac maintenance
- On-site and remote support
- Network design
- Firewall and network maintenance
- Google Cloud services
- Microsoft Cloud services
- Website security
- Managed DNS
- Domain registration
- Backup oversight
- Incident response coordination
The X-Tek business solutions page lists available infrastructure, cloud, web, and business IT services
Managed IT does not remove business responsibility
It provides assigned processes, monitoring, documentation, maintenance, and escalation
2026 SMB cybersecurity checklist
Use this as a baseline review
- MFA enabled on business-critical accounts
- Phishing-resistant MFA available for administrators
- Legacy authentication disabled
- Business-grade firewall deployed
- Firewall rules reviewed
- Guest Wi-Fi isolated
- Internal networks segmented
- Devices inventoried
- Endpoint protection installed
- Critical patches monitored
- Logs collected
- Security alerts assigned
- Backups monitored
- Restore tests completed
- SPF configured
- DKIM configured
- DMARC configured
- Incident response plan documented
- Vendor access reviewed
- Employee training completed
- Business risks mapped to NIST CSF 2.0
Cybersecurity standards provide structure
Implementation provides protection
Monitoring provides visibility
Managed IT provides ongoing ownership
Contact Information
Business Solutions Information Request:
https://xtekit.com/business-solutions-information-request/
815-516-8075

