6 Free Cybersecurity Improvements You Can Make Today

Blue padlock resting on a circuit board.

If a password is the only thing between a stranger and your email, the rest of the security talk can wait. We keep seeing that in Nashville companies that grew faster than their login list. Maybe ten people, maybe forty. The person who first set up Microsoft 365 or Google Workspace has moved on. The logins they created are still there.

You can close the obvious holes today. No new appliance. No extra line item to approve. These six free cybersecurity improvements use the accounts and tools a Middle Tennessee business usually already pays for.

Start these free cybersecurity improvements with MFA

Multi-factor authentication means a password is not enough on its own. The second step is a code from an authenticator app, a prompt on a phone, a hardware key, or a fingerprint. If someone steals or guesses the password, they still have to pass that step.

Turn it on first where a break-in hurts the most. Email. Banking and payroll. Cloud file storage. The VPN. Any account that can change settings for everyone else. Microsoft 365 and Google Workspace both include it. CISA's guidance for small and medium businesses says any MFA is better than none, and that a security key or passkey holds up better against phishing than a text message.

Header: 6 Free Cybersecurity Improvements You Can Make Today.

Then watch the habit that shows up after you turn it on. Someone taps approve during a client call without looking at what the sign-in was for. If the app can ask them to type a number they see on the screen, use that. A blind tap is how those prompts get abused.

Check enrollment once a month. New hires, and anyone who just switched phones, are where MFA quietly drops off.

Retire unused accounts that no longer have a person attached

Unused accounts belonging to former employees, short-term contractors, and vendors you stopped calling are an easy way in. Nobody is watching those mailboxes. The password may be old, reused, or written down somewhere the team forgot.

Start with the user list in email, then the apps beside it. Accounting. The CRM. Payroll. Shared drives. For each login, name the person and the job it still does. If you cannot name both, turn sign-in off.

Block sign-in first when you still need the mailbox. A bookkeeper who left in the spring may have mail the team still searches. Keep the history, disable the login, and drop the license if you are paying for an empty seat. Do the same for a front-desk or "admin" account that three people know and nobody owns.

Take administrator access back from people who do not need it

An administrator can install software, change security settings, and switch protections off. That is a powerful account. It is a bad default.

The way it usually happens is small. The office manager needed administrator access on a Tuesday because a driver would not install, and the owner was on a job outside Davidson County. The rights stayed. The next hire was copied from that account. A single phished mailbox can now change the settings that were supposed to protect everyone else.

Who has to install software or change security settings as part of the job this month? Everyone else gets a standard login. When someone needs a one-time install, grant it, finish the install, and remove it the same day. Write down the accounts that remain administrators. If that list is longer than the people who actually run the systems, it is too long. Sorting that list is network security work, and it does not require a new product to start.

Set automatic updates and stop snoozing the restart

Attackers do not need a secret bug when a fix is already public and your computers have not installed it. Updates close those known holes. Snoozing them leaves the hole open.

Turn on automatic updates for Windows and macOS, phones and tablets, browsers, Microsoft Office, antivirus, and the business apps your team actually uses. Phones get skipped because nobody files them under office equipment. Email and the MFA prompt both live there.

Reliable outsourced IT services in Tennessee

The holdout is usually a front-desk computer that "cannot restart while customers are in the lobby." Give it a window after the door locks. A restart after close beats a locked screen full of a ransom note. If one line-of-business app breaks when Windows updates, test the update on a single machine first, then roll it out to the rest of the office.

NIST's small-business quick-start guide puts automatic updates on the early list, next to MFA and backup testing. The guide is written for smaller organizations, not a corporate security department.

Move the company off a shared password file

People will not remember a long, unique password for every site. They reuse the one they can recall. One breached vendor account then opens the email that used the same password.

A password manager creates those passwords, stores them, and lets someone share a login without pasting it into email or chat. A single owner can often start on a free plan. A shared vault for the office is usually a small monthly fee. Check the current price before you tell anyone it will cost nothing. The cheap mistake is the file named Passwords on the shared drive, or a notes app on one phone that the whole company depends on.

Reuse is the failure mode a manager actually fixes. The surrounding habits, including who knows the master login, are in our guide to password management.

Restore one real file before you trust the backup

Look up when the last backup succeeded, when someone last restored a file on purpose, and how long that restore took. A job that says "completed" still has to produce a file you can open.

Use something the business would miss on a Monday. Last week's payroll spreadsheet, or a client folder from the shared drive. Restore it to a separate location, not on top of the live copy. Time it. If the restore fails, or the only copy sits on the same server an attacker would encrypt, you do not have a restore yet.

The longer version of that test is backup testing, the difference between a backup file and a recovery plan. Do the one-file version today. Put the full test on the calendar.

You need someone with administrator access, a list of the apps the company actually uses, and an hour that will not get bumped. If you are not sure who still has a login, or the last restore date is a guess, call Net Works at 615-249-1131. Ten minutes is enough to see what is still open and what you can close this week. Send a note through the contact page if you want a time on the calendar instead of calling cold.

Schedule a Complimentary Consultation
(opens in a new tab)
Share IT: