Would you lock your front door at night, then leave a window wide open?
Of course you wouldn’t. But many small businesses do the digital equivalent every day. They install antivirus software, change a few passwords, and assume their data is protected: while an untested backup, an exposed remote login, or a convincing phishing email leaves the business vulnerable.
That is why this 2026 cybersecurity checklist matters.
The 2025 Verizon Data Breach Investigations Report found that ransomware appeared in 88% of breaches involving small and medium-sized businesses. Across all organizations, credential abuse accounted for 22% of breaches, while vulnerability exploitation accounted for 20%.
That is sensitive data, money, and business downtime at risk.
Whether you operate in St. Louis, St. Charles County, Chesterfield, Clayton, O'Fallon, the Metro East, or elsewhere in Missouri, use this checklist as a practical starting point for stronger cybersecurity for small business.
Your 2026 St. Louis small-business cybersecurity checklist

1. Know what you need to protect
You cannot secure what you cannot see.
Start by creating a current inventory of every laptop, desktop, smartphone, server, cloud application, printer, router, and storage device connected to your business. Then list the data each system handles.
Think about:
- Customer and employee information
- Accounting and payroll records
- Banking and payment systems
- Sales and operational files
- Email and cloud documents
- Intellectual property and business plans
Do you know which devices are company-owned? Do you know who can access your financial systems? If an employee left tomorrow, could you quickly disable every account?
A simple inventory gives you a clearer roadmap for managed cybersecurity services, network design, endpoint protection, and IT support for small business.
2. Require multi-factor authentication everywhere
A password is one lock. Multi-factor authentication, or MFA, adds another lock that requires something extra: such as an authenticator app, security key, or biometric check.
Require MFA for:
- Business email
- Microsoft 365 or Google Workspace
- Payroll and accounting platforms
- Online banking
- Cloud storage
- VPN and remote access
- Administrative accounts
The Verizon report found that compromised credentials remain one of the most common ways attackers gain access. If someone steals your password, MFA can stop that password from being enough.
Start with email and financial accounts today. Then expand until every critical system is covered.
3. Strengthen email and payment security
Phishing: pronounced “fishing”: is a scam designed to trick you into clicking a link, opening an attachment, sharing a password, or sending money.
Imagine receiving an email that appears to come from your biggest supplier. The message says its bank account has changed and asks you to update payment details immediately.
You open it without thinking twice. And just like that, a routine invoice can become a costly fraud attempt.
Protect your business by:
- Configuring SPF, DKIM, and DMARC for your domain
- Using advanced email filtering
- Scanning links and attachments
- Requiring phone verification for payment changes
- Teaching employees never to trust urgency alone
- Giving staff a simple way to report suspicious messages
The FTC’s small-business cybersecurity guidance recommends email authentication, strong passwords, MFA, regular backups, and recurring employee training.
For more local context, read St. Louis Business IT Roundup: Security Threats Your Small Business Can’t Afford to Ignore.
4. Test your backups by restoring real files
Here’s the step most businesses skip.
They have backups. They may even receive a daily “backup completed” notification. But they have never tested whether those backups can actually restore the files the business needs.
A backup that cannot be restored is not a safety net. It is a hopeful assumption.
Follow the 3-2-1 rule:
- Keep three copies of important data
- Store them on two different types of media
- Keep at least one copy offsite
For stronger ransomware resilience, use a 3-2-1-1-0 approach that adds one offline or immutable copy and aims for zero backup errors.
Then test a restoration at least quarterly. Can you recover a customer database? An accounting file? A shared project folder? How long would it take?

This matters because ransomware can encrypt production files and attempt to delete connected backups. Separate, encrypted, and tested copies give you options when systems are locked.
The FTC recommends regular backups, including copies that are not connected to the business network. For a practical example, review Case Study: How a St. Charles County Manufacturer Stopped Ransomware and Kept Its Plant Running.
5. Patch every device, application, and network system
An outdated application can be like a cracked window. It may look harmless, but it gives an intruder a way inside.
Turn on automatic updates where appropriate, and maintain a process for reviewing updates that require testing. Include:
- Operating systems
- Web browsers
- Routers and firewalls
- Accounting and business applications
- Website plugins
- Remote access tools
- Printers and other connected devices
Do not forget equipment that sits quietly in the corner. A printer, camera, or outdated wireless access point can still create risk.
Managed IT services help you track devices, prioritize critical patches, and confirm updates actually installed.
6. Secure your network and remote access
Your business Wi-Fi should not work like an open front porch.
Use strong WPA2 or WPA3 encryption, change default router credentials, disable unnecessary remote administration, and create a separate guest network. Customer and personal devices should not share the same network as file servers, payment systems, or operational equipment.
For remote work:
- Require MFA
- Use a secure VPN or zero-trust gateway
- Avoid exposing Remote Desktop Protocol directly to the internet
- Encrypt company laptops
- Block automatic connections to public Wi-Fi
- Confirm that personal devices meet your security requirements
These safeguards are especially important for businesses with employees working from homes in St. Louis, Chesterfield, O'Fallon, or the Metro East, as well as vendors connecting from outside Missouri.
7. Train your employees: and make reporting easy
Most people do not click a malicious link because they want to break the rules. They click because the message looks familiar, the request seems urgent, or they are trying to help a customer quickly.
It is not about blame. It is about awareness.
Give your team short, recurring training on:
- Phishing and business email compromise
- Text-message and QR-code scams
- Fake technical-support calls
- Password safety
- Lost or stolen devices
- Safe remote work
- How to report a mistake quickly
Then make reporting simple. If an employee clicks something suspicious, you want them to tell you immediately: not hide it until the damage spreads.

8. Monitor systems and prepare for the first hour of an incident
What happens if an employee reports ransomware at 8:30 on a Friday night?
Who disconnects the device? Who contacts your IT provider? Who calls your bank, cyber insurer, legal counsel, or customers?
Write down the answers before you need them.
Your incident response plan should include:
- Internal decision-makers
- IT and cybersecurity contacts
- Banking and payment contacts
- Insurance and legal contacts
- Communication procedures
- Backup restoration priorities
- Steps for isolating infected devices
Monitoring and alerting can help you detect unusual logins, suspicious file changes, impossible travel, and other warning signs earlier.
This is where managed cybersecurity services provide practical value. Security tools matter, but someone must review alerts, investigate unusual activity, and act when the warning is real.
9. Review vendors, access, and insurance
Your risk does not stop at your office door.
A payroll provider, accounting firm, software vendor, marketing platform, or outside technician may have access to business data. Review what each vendor can access and whether that access is still necessary.
Use least privilege, which simply means giving each person or vendor only the access required to do the job.
Also review your cyber insurance requirements. Some policies require MFA, documented backups, employee training, or specific security controls. A policy cannot replace prevention, but it can help address legal, recovery, notification, and business interruption costs.
How to put this checklist to work
Do not try to fix everything in one afternoon.
Start with the highest-impact controls:
- Turn on MFA for email, banking, and administrative accounts.
- Confirm your backups exist and test a restoration.
- Patch internet-facing systems and remote access tools.
- Verify payment-change requests by phone.
- Create a simple incident response contact list.
Then schedule a quarterly review. Your business changes, employees change, vendors change, and threats change.
For additional guidance on building a practical technology plan, read St. Louis IT Consulting Services for Small Business: What You Get and How to Choose the Right Partner.
The bottom line
Cybersecurity is not about buying the most complicated technology. It is about closing the obvious gaps, testing the protections you already have, and creating a clear plan for what happens next.
You lock your doors because protection is easier before a break-in. The same is true for your network, accounts, devices, and data.
Platinum Web Services helps small businesses across St. Louis, St. Charles County, Chesterfield, Clayton, O'Fallon, the Metro East, and Missouri build personalized, proactive security plans backed by 24/7 support.
If you would like help working through this checklist, contact Platinum Web Services.


0 Comments