Cybersecurity Essentials for Small Business

A live working session on the threats that actually hit small businesses — phishing, weak credentials, and untested backups — and the handful of habits that stop them.

Wednesday, February 18, 2026

About this session

Held live online on Wednesday, February 18, 2026 — a 90-minute working session with 21 business owners and operators. No fear-mongering, no vendor pitches: just the small set of controls that stop the attacks small businesses actually face.

What we covered

  • The real threat model for an SMB — why small businesses are the #1 ransomware target, and what that means for a five-person shop versus a fifty-person one.
  • Phishing defense that works — the patterns to spot, what to do the moment a suspicious message lands, and the one policy that prevents most account takeovers.
  • Multi-factor authentication, everywhere — which accounts matter most and how to roll MFA out to a whole team without friction.
  • Password & identity hygiene — why a password manager plus unique passwords removes the most common failure mode.
  • Backups that survive ransomware — the 3-2-1 rule, tested restores, and why "we have backups" is not a plan.

What attendees walked away with

Every participant left with MFA enabled on their primary email, a one-page incident checklist, and a backup they had actually tested during the clinic — not just configured.

Key takeaways

  1. Most SMB breaches are not sophisticated — they're a reused password and a missing update.
  2. MFA on email is the single highest-leverage control you can add this week.
  3. A backup you have never restored is not a backup.
  4. Write the "what to do if" checklist before you need it.

Materials & recording

  • Session recording — shared with everyone on the free list after each session.
  • Incident response checklist — the one-page template we built together.
  • Security self-audit — the ten-minute baseline review we walked through live.

"I'd read about MFA for years but never set it up. Twenty minutes into the session it was done on every account I care about." — session attendee

Missed it?

Security topics repeat regularly. Join the free list to be notified when the next session opens — and to receive the recording and checklists from this one.