Field Notes No. 2 · Practical baseline
What Does ‘Good Enough’ Cybersecurity Look Like for a Small Organization?
A practical cybersecurity baseline for small businesses in 2026, built around seven questions leaders can answer without pretending risk can be eliminated.
· 11 min read · Iron Dillo Cybersecurity
A credible cybersecurity baseline starts with an honest premise: a small organization does not need perfect security. It needs controls that address its most consequential risks, people who know what to do, and a recovery path that has been practiced.
Perfection is not the standard
No organization can prevent every malicious email, software flaw, vendor failure, stolen device, or human mistake. Trying to do so can consume limited money and attention while leaving basic protections unfinished. The better objective is defensible risk reduction: understand what the organization depends on, make common attacks harder, limit the damage when something gets through, and restore essential work.
This follows the practical approach described in Built for the Real World. Small businesses, nonprofits, rural offices, local governments, and family operations share enterprise-sized dependencies without enterprise staffing. Their baseline must fit the people, technology, connectivity, budget, and consequences they actually face.
“Good enough” is therefore not “the least we can get away with.” Corner-cutting ignores a known danger, leaves ownership unclear, or buys a tool without maintaining it. Defensible good-enough security makes deliberate choices, records important exceptions, assigns responsibility, and revisits decisions as the business changes. It can explain why a protection is present, how anyone knows it works, and what happens when it fails.
Use frameworks as maps, not scorecards
Authoritative frameworks help leaders ask better questions. The NIST Cybersecurity Framework 2.0 organizes outcomes around Govern, Identify, Protect, Detect, Respond, and Recover. Its Small Business Quick-Start Guide adapts that structure for organizations with modest or no cybersecurity plans. CISA provides practical resources for small and medium businesses, while CIS Critical Security Controls Implementation Group 1 offers a prioritized foundation of essential cyber hygiene.
Use them to check coverage and priorities, not to generate paperwork for its own sake. A concise plan that people follow is more valuable than a complete-looking binder nobody can use.
The seven-question test
The most useful baseline is one a leader can test in plain language. Gather the owner or executive, the person responsible for technology, and the people who run essential operations. Ask these seven questions. Evidence matters more than a confident yes.
1. Do we know what must keep working?
Name the critical services, accounts, data, devices, vendors, and processes that produce revenue, deliver care, meet obligations, or protect people. Identify how long each can be unavailable and who knows how it operates. This need not be a perfect inventory; it must be a reliable short list that guides protection and recovery.
2. Are our identities and access reasonably protected?
Important email, banking, payroll, cloud administration, remote access, and backup accounts should use unique credentials and multifactor authentication, preferably passkeys or security keys where practical. Remove former workers promptly, avoid shared administrator accounts, and secure recovery email addresses and phone numbers. Review who has powerful or vendor access and whether they still need it.
3. Are devices, software, and internet-facing systems maintained?
Turn on automatic updates when operations allow. Keep supported browsers, operating systems, routers, remote-access products, website software, and cloud applications current, prioritizing anything exposed to the internet. Know where unsupported equipment remains. If replacement must wait, reduce its access, isolate it where feasible, and record both the risk and the plan.
4. Can we recognize and contain trouble?
People should know how to report a suspicious message, unexpected login approval, changed payment request, lost device, or unusual system behavior without fear of blame. Ensure someone receives useful alerts from major accounts, security tools, and service providers. Define who can disconnect a device, disable an account, or call the technology provider when minutes matter.
5. Can we recover the work that matters?
Back up essential data and configurations with at least one copy protected from routine user access and ordinary ransomware paths. Document who can restore it, what credentials or equipment are required, and the acceptable recovery order. Then restore a representative file, system, or workflow and record the result.
6. Do we know who decides and communicates during an incident?
Write a short incident guide with decision owners, technology and vendor contacts, insurance details, communication responsibilities, and criteria for seeking legal, law-enforcement, or regulatory help. Keep an offline copy. Governance does not require a committee: it requires an accountable person, clear authority, and decisions that can still be made when email is unavailable.
7. Do we verify that the baseline still works?
Assign each recurring task to a named role and place it on a calendar. Review failures, near misses, business changes, new vendors, and automation. If nobody can show when an access review, restore test, or incident exercise occurred, that protection should not be assumed. Improvement comes from a modest operating rhythm, not a once-a-year purchasing event.
Adapt the baseline to real life
A ten-person manufacturer and a family using shared devices should not have identical procedures, but both need protected identities, current systems, recoverable information, and a response plan. For an individual or family, the critical list may include primary email, financial accounts, photos, identity documents, phone recovery settings, and a trusted person who can help. A password manager, multifactor authentication, device updates, backups, credit-account awareness, and a family rule for verifying urgent money requests form a meaningful baseline.
Rural organizations must account for distance, intermittent connectivity, older equipment, limited local support, and dependence on one provider or knowledgeable employee. Store vendor numbers and key instructions offline. Consider a backup communication or internet option. Document essential knowledge before it rests in one person’s head, and plan maintenance around equipment that cannot safely stop without coordination.
Automation can make a small team more consistent: updates can install automatically, backups can run on schedule, account alerts can reach a shared operational channel, and recurring reviews can appear on calendars. But automation also fails quietly. Every automated control needs an owner, a failure notification, and a periodic human check. Automating a bad configuration merely repeats the mistake faster.
Build a sustainable operating rhythm
Using Iron Dillo’s GRIT model, turn the baseline into a recurring operating rhythm rather than a one-time project.
Monthly: practice Tenacity. Confirm updates and backups are completing, review important alerts, remove access that is no longer needed, and discuss suspicious requests or near misses. Keep this review short and assign unfinished work.
Quarterly: strengthen Resilience and Instinct. Restore something meaningful, verify emergency contacts, review critical vendors and privileged access, and walk through one plausible event such as compromised email, unavailable internet, or ransomware. Ask what people noticed, who decided, and what slowed recovery.
Annually: choose Growth. Revisit the critical-service list, business impact, insurance requirements, major technology changes, and the seven questions. Update the incident guide, set the next few priorities, and fund improvements the organization can operate. Growth, Resilience, Instinct, and Tenacity work together: improve deliberately, recover reliably, recognize trouble, and keep doing the basics.
Know when “good enough” is not enough
The baseline is a floor. Raise it when the organization holds regulated or unusually sensitive data, supports safety-critical operations, accepts significant online payments, faces contractual requirements, has repeated incidents, or cannot tolerate extended downtime. Also raise it when growth changes who has access, introduces remote connectivity, or concentrates operations in a new platform. The honest answer may be to obtain specialized assessment, legal guidance, or managed support.
A defensible baseline will not eliminate risk. It will make priorities visible, common failures less likely, response less chaotic, and recovery more credible. That is a serious standard for a small organization, and one it can continue to improve.
Find your practical baseline
Start with what matters and build from there.
Iron Dillo Cybersecurity helps small organizations, rural businesses, and families identify workable priorities without unnecessary complexity.
Start a conversation