You do not need a CISO, a six-figure security budget, or a vendor pitch deck to dramatically improve your company’s security posture. You need a weekend, a checklist, and the discipline to actually finish the list.
Here are 25 things a small business can fix this weekend. Most are free. None require buying new tools. All of them move the needle.
The setup: 4 hours, one Saturday

Block out four hours. Put the phone on silent. Get one or two people to help. Go through this list top to bottom. By Sunday morning you will be meaningfully more secure than 90 percent of businesses your size.
Identity and access
- Turn on MFA on every account that supports it. Email first. Then banking, payroll, and any admin console.
- Use an authenticator app, not SMS. Google Authenticator, Authy, or 1Password. SMS is the fallback, not the default.
- Audit who has admin access. If the answer includes “we think just a few people,” you are not done.
- Remove accounts for people who have left. Every departing employee should lose access within 24 hours. Not “we’ll do it Monday.”
- Use a password manager. Bitwarden is free. 1Password is paid. Pick one and put every work credential in it.
- Set unique passwords on every account. The password manager makes this trivial. Reuse is the gift that keeps giving to attackers.
- Turn on SPF, DKIM, and DMARC on your domain. Your DNS provider can do this in 20 minutes. It stops people from spoofing your domain in phishing.
- Configure spam and phishing filters to quarantine, not just deliver. Train employees to expect to find legit mail in quarantine occasionally.
- Add an external banner to emails received from outside the company. “External” in the subject line. Free. Highly effective against impersonation.
- Practice the “did you mean to send this” reflex. Wire transfer requests that are urgent and unusual are the oldest trick in the book. Slow down.
Devices and updates
- Turn on automatic updates for the OS, browser, and apps. On the Mac, on the PC, on the phone. “I’ll do it later” is how breaches start.
- Enable full-disk encryption on every laptop. FileVault on Mac, BitLocker on Windows. Built in. One toggle.
- Set a screen lock with a real password on every device. Not “1234.” Not your birthday.
- Install an endpoint detection tool if you do not have one. Even Windows Defender, kept on, blocks most commodity malware.
- Wipe old devices before they leave the company. Resold laptops with the old owner’s Google account still logged in are a real thing that happens weekly.
Network
- Change the default password on your router and Wi-Fi. If your IT person installed it and never changed the admin password, this is a Saturday project.
- Use WPA3 (or at least WPA2) for Wi-Fi. WEP is still out there. If your router is that old, replace it.
- Separate the guest Wi-Fi from the business network. Customer and visitor devices should never be on the same subnet as your point-of-sale or file server.
Data and backups
- Set up automated, offsite backups. The 3-2-1 rule: three copies, two media types, one offsite. Cloud plus external drive is fine.
- Test a restore at least once a year. A backup you have never restored from is a backup you do not have.
- Know where your sensitive data lives. If you do not know where the customer credit card data is, you cannot protect it.
- Limit who can access sensitive files. Least privilege by default. Most employees do not need access to most data.
Awareness and process
- Run a phishing simulation. Tools like KnowBe4 or even a free Google form. See who clicks. Train accordingly.
- Write down who to call if something goes wrong. IT person, lawyer, cyber insurance carrier. Print it. Tape it to the server.
- Do a tabletop exercise once a year. “We just got an email that all our files are encrypted. What do we do, who do we call, in what order?” Walk through it on a Saturday.
What this does not include
No SIEM, no MDR, no zero trust, no AI-powered threat detection. Those matter at a certain scale. They do not matter for the 25-person company whose biggest risk is a reused password and an unpatched laptop.
The biggest security wins for a small business are the unsexy ones. Turn on MFA. Update your stuff. Back up your data. Make sure the people who left cannot still get in. That is the difference between “we got phished but no real damage” and “we are shut down for two weeks.”
Pick a weekend. Do the list. You will be glad you did.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



