How much cybersecurity is enough? The answer depends on your organization’s risks, obligations, and ability to recover from an incident. Spending less can be reasonable when you understand what protection changes, what risk remains, and how a loss would be handled. This guide helps you compare costs, recognized standards, insurance considerations, and documented responsibilities before deciding which safeguards to keep, replace, or reduce. The same questions apply to any IT provider, software vendor, consultant, or other advisor.
60-Second Summary #
- Reducing cybersecurity costs can be reasonable. Identify what protection changes, what replaces it, and what risk remains.
- Use applicable standards and evidence. Government guidance, industry frameworks, laws, contracts, and insurance conditions have different authority.
- Ask the advisor about relevant experience, the environment reviewed, and the specific basis for the recommendation.
- Compare total savings with replacement costs, operational responsibilities, recovery needs, and financial exposure.
- Document the recommendation and leadership’s decision. A signature is not a guarantee of safety or automatic financial protection.
- Apply the same questions to anyone recommending more or less security, including EasyITGuys.
Sharing this with another advisor? Start with the advisor questions, complete the recommendation record, and use the email template. The reference section provides the independent sources.
Where Cybersecurity Standards Actually Come From #
Cybersecurity standards do not originate with EasyITGuys or any other individual IT company. Modern cybersecurity is shaped by overlapping frameworks, government guidance, laws, regulations, contracts, insurance requirements, industry standards, technical research, and organizational risk decisions.
| Source | What it contributes | What to understand |
|---|---|---|
| NIST | Risk-management frameworks, technical standards, cybersecurity guidance, and small-organization resources. | NIST guidance is widely used, but the applicability of a particular publication depends on the organization, contract, regulation, or program involved. |
| Center for Internet Security | The CIS Critical Security Controls and Implementation Groups provide prioritized cybersecurity safeguards based on risk, resources, complexity, and data sensitivity. | CIS describes Implementation Group 1 as essential cyber hygiene. Higher Implementation Groups add safeguards for organizations with greater risk or complexity. |
| CISA, FBI, NSA, FCC, and SBA | Cybersecurity practices, threat information, planning resources, technical recommendations, training, and small-organization guidance. | Government guidance can provide strong independent reference points without automatically making every recommendation a legal requirement for every organization. |
| Regulators and regulated programs | Examples include HIPAA security requirements, FTC Safeguards Rule requirements for organizations within its scope, CMMC and defense-contract requirements, and other sector-specific obligations. | Applicability matters. A requirement that applies to a healthcare organization, financial institution, defense contractor, or another regulated entity should not automatically be described as a universal requirement. |
| State and regional authorities | States, economic-development organizations, universities, and cybersecurity centers publish education, minimum-baseline programs, and localized resources. | State laws and regulatory requirements should be evaluated separately from voluntary state educational guidance. |
| Insurance carriers | Underwriting questions, required controls, eligibility conditions, policy terms, exclusions, limits, and incident-response resources. | The organization’s actual policy, application, representations, endorsements, and carrier decisions control. Never assume coverage from a general article or checklist. |
| Contracts and customers | Customer agreements, vendor contracts, government contracts, payment-processing agreements, and other relationships may create cybersecurity obligations. | A voluntary framework can become important when a contract, insurer, customer, or governing program incorporates it. |
| Organizational leadership | Leadership determines how much residual risk the organization is willing and financially able to retain after required obligations are addressed. | IT can explain risk. Insurance can transfer defined financial risk. Legal counsel can interpret legal obligations. Leadership still owns the organizational decision. |
Important distinction: Authoritative does not always mean mandatory. NIST guidance, CIS Controls, CISA recommendations, an insurance requirement, a state law, and a contractual requirement may all influence a cybersecurity decision, but they do not have the same legal or contractual effect.
How Much Cybersecurity Is Enough for Your Organization? #
Organizations should not purchase security simply because a vendor sells it. A security control should address a known risk, applicable requirement, operational dependency, recovery objective, or reasonable cybersecurity practice. That also means an organization should be willing to question controls that no longer make sense. Technology changes. Applications move to the cloud. Employees leave. Locations close. New authentication methods reduce older risks. Duplicate products sometimes accumulate. A healthy cybersecurity program should change with the organization.
The useful question is not simply, “Do we need this product?” The better question is, “What risk does this control address, and what happens to that risk if the control goes away?”
What Does “Excessive Security” Mean? #
“Excessive security” can be a reasonable conclusion, but it needs a comparison point. Without one, it is only an opinion.
A useful recommendation should be able to explain something similar to this:
Example of a risk-based recommendation: “This control currently addresses this specific risk. Your environment has changed in these specific ways. Another control now addresses most of the same risk. Removing the original control saves approximately this amount per year. This is the remaining risk leadership would be accepting.”
That is much more useful than saying an organization has “too much security.” The same standard should apply when someone recommends adding security. The person making the recommendation should be able to explain why it is needed.
Why Not Reduce Security and Save the Money? #
Sometimes that is the right decision. Cybersecurity should be proportional to the organization. A one-person operation with little stored information can have a different risk profile from a manufacturer with 100 employees, a medical practice, a municipality, a defense contractor, or an organization holding large amounts of customer data.
| Situation | Questions to answer before reducing protection |
|---|---|
| One owner and no employees | Does that one person still depend on email, banking, cloud applications, customer information, a website, payment systems, or a critical computer? |
| Most applications are in the cloud | What protects the cloud identity, email account, authenticated browser session, administrator access, account recovery process, and endpoint used to access the application? |
| Little or no local data | Could a compromised computer still provide access to cloud applications, stored credentials, email, banking, customer portals, or active sessions? |
| Passwordless authentication, passkeys, or security keys | Are all important users, administrators, recovery methods, and critical applications protected to the same standard? |
| No business email | Are SMS, mobile devices, websites, cloud applications, social-media accounts, payment systems, or vendor portals now the primary attack paths? |
| No Wi-Fi or guest network | What protects the wired network, router, firewall, endpoints, internet-facing services, remote access, and cloud identities? |
| No digital payments | Does the organization still have payroll, banking, invoices, ACH, wire transfers, customer information, employee information, or valuable accounts? |
| Very little identifiable customer data | What information actually exists in email, accounting, payroll, employee records, contact lists, backups, cloud applications, and vendor systems? |
| Strong internal IT ability | Does the organization have the knowledge, time, documentation, monitoring, patching, backup, testing, incident-response ability, and coverage needed to perform the work consistently? |
| Strong vendor-provided security | Exactly where does the vendor’s responsibility begin and end? Does it include endpoints, identities, email, local networks, fraud, backup, account recovery, and business interruption? |
| Independent breach or identity monitoring | Does the service only alert after information appears in a known breach, or does it actively reduce the likelihood and impact of account compromise? |
| Large cash reserves | Has leadership intentionally decided to self-insure some cyber risk, and is the organization financially prepared for investigation, legal, recovery, interruption, fraud, notification, and other possible expenses? |
Any of these circumstances can change the risk calculation. None should be treated as automatic proof that cybersecurity is unnecessary.
Understand What Each Security Layer Is Doing #
Different security controls address different problems. Removing one control because another control exists only makes sense when the two actually address the same risk.
| Control | Primary purpose |
|---|---|
| Multi-factor or phishing-resistant authentication | Reduces the chance that a stolen password alone can be used to access an account. |
| Endpoint protection, EDR, or MDR | Helps prevent, identify, investigate, contain, or respond to malicious activity on managed devices. |
| Email security | Reduces phishing, malicious attachments, impersonation, spam, and other email-borne threats. |
| Patching and update management | Reduces exposure to known software vulnerabilities and unsupported software. |
| Backups | Provides recovery options when information is deleted, corrupted, encrypted, damaged, or otherwise lost. Backup design and recovery testing still matter. |
| Password manager and breach awareness | Supports unique credentials and can help identify exposed credentials. It does not replace MFA or other identity controls. |
| Security awareness training | Helps employees recognize phishing, fraud, social engineering, unsafe behavior, and reporting expectations. |
| Least privilege and separate administrator access | Limits what a compromised user or account can access or change. |
| Firewall and network security | Controls and monitors network communications and can reduce exposure between systems, locations, users, and the internet. |
| Logging and monitoring | Improves visibility into activity and can help detect, investigate, and understand unusual events. |
| Incident-response planning | Defines who does what when something goes wrong so decisions do not have to be invented during an incident. |
| Cyber insurance | Transfers defined portions of financial risk according to the actual insurance policy. It does not prevent the incident itself. |
The Cost of Security Is Only One Side of the Decision #
Every control has a cost. That cost should be visible and questioned. The other side of the decision is the amount of financial and operational risk the organization will retain if the control is changed. That does not mean every possible cybersecurity loss is catastrophic. It means leadership should understand how a realistic incident would be financed and managed.
Questions leadership should answer #
- How long could we operate without this computer, application, email system, internet connection, or cloud account?
- What would we do if a fraudulent payment left our account?
- What would happen if customer, employee, financial, or operational information was exposed?
- Could we continue working while systems were investigated or rebuilt?
- Who would provide incident response, legal guidance, forensic investigation, customer notification, communications, recovery, and insurance coordination?
- What losses would our insurance policy actually cover?
- What losses would remain ours?
- Could we comfortably pay those costs from normal operating cash?
- Would we use savings, a line of credit, a loan, outside capital, or another financial resource?
- What would happen to the organization if recovery took several days or weeks?
Risk does not become unacceptable simply because it exists. Some risks can reasonably be accepted. The important part is making that choice before the incident, understanding the consequences, and having the financial and operational ability to live with the decision.
Questions to Ask Someone Recommending Less Security #
Anyone can raise a useful cost-saving idea. Before relying on the recommendation, understand the person’s relevant experience, what they reviewed, and where their expertise ends. An application vendor may understand its platform without having assessed your email, computers, insurance, or recovery needs. Ask whether the advisor works with cybersecurity assessments, IT operations, incident response, insurance underwriting or claims, compliance, or your specific industry. Relevant training, credentials, and experience with similar organizations can help establish their background. They do not replace evidence about your environment.
An advisor does not need experience in every discipline. They should identify which questions require input from someone else. A qualified insurance professional may address coverage questions while a cybersecurity specialist evaluates technical protection.
- What experience supports your recommendation? Explain your relevant role, experience with similar organizations, and any important limits to your expertise.
- What did you actually review? Identify the users, devices, email, applications, network, data, backups, reports, and agreements examined. State what was not reviewed.
- What should change, and why? Name the specific control or service. Explain the risk it addresses and why that risk is reduced, duplicated, no longer present, or acceptable.
- What supports the conclusion? Identify the publication, version, safeguard, assessment result, policy provision, or other evidence. Distinguish mandatory obligations from recommendations.
- What replaces the protection or work? Explain the replacement control, responsible party, ongoing maintenance, monitoring, response arrangements, and how effectiveness will be checked.
- What are the actual savings? Include replacement subscriptions, implementation, internal staff time, support labor, training, and any applicable transition costs.
- What risk and financial exposure remain? Address realistic incident scenarios, downtime, recovery funding, insurance or warranty implications, and applicable obligations. Identify estimates and unknowns.
- What will you document and commit to? Provide the written recommendation, proposed recovery role, and any existing or proposed financial commitments. Identify the person or legal entity making each commitment.
Also disclose any financial interest in the outcome. A recommendation may increase or reduce revenue for the current provider, a replacement provider, or an application vendor. That does not automatically invalidate the advice. It makes independent evidence more important. A written response on the advisor’s normal letterhead or through its established process is acceptable when it addresses the same questions. The purpose is a useful decision record, not a paperwork test.
Use the Same Questions With the Provider Recommending More Security #
Accountability should work in both directions. If an IT or cybersecurity provider says a control must remain, ask what it protects. Ask what recognized baseline supports it. Ask whether another control could accomplish the same goal for less money. Ask what changes in the environment would allow the control to be reduced later. “Because we require it” is not a complete cybersecurity explanation. A provider should be able to explain its standard and why the standard exists.
How EasyITGuys Uses Cybersecurity Baselines #
EasyITGuys uses the CIS Critical Security Controls as a foundation for standard organizational cybersecurity. Plan 2 is designed around a CIS Implementation Group 1 baseline. Plan 1 is designed around the broader Implementation Group 2 level. Organizations with greater regulatory, contractual, data-sensitivity, or operational risk may require additional controls. Those environments may use higher CIS safeguards together with requirements from frameworks or programs such as NIST, HIPAA, FTC/GLBA, CMMC, ISO 27001, state requirements, federal requirements, and other applicable standards. This is an EasyITGuys service-design standard. It is not a statement that every organization is legally required to purchase an EasyITGuys service. An organization may use another provider, maintain controls internally, or use different technologies, subject to its applicable agreements and obligations.
A framework-based service design is not proof that every applicable safeguard is implemented throughout an organization. Ask for the framework version, applicable safeguards, assigned responsibilities, documented exceptions, and evidence of implementation. Distinguish services the provider performs from responsibilities retained by leadership, employees, application vendors, and other parties. CIS Implementation Groups are not interchangeable with CMMC levels. Using a higher Implementation Group does not automatically establish HIPAA, CMMC, or other regulatory compliance. Each applicable program requires its own scope and requirements review.
Organizations that want to understand the service models can review Business IT Support and Security Membership Plans and Business Membership Pricing.
Cyber Insurance Should Be Reviewed Before Making a Major Reduction #
Do not assume that a general business insurance policy automatically provides the cyber protection the organization expects. Cyber protection may be provided through a dedicated policy, endorsements, supplemental coverage, or other policy structures. Coverage varies substantially.
Before changing an important control, consider asking the organization’s licensed insurance professional or carrier:
- Do we have a dedicated cyber policy, an endorsement, or another form of cyber coverage?
- What are our limits, sublimits, deductible, and retention?
- What first-party losses are covered?
- What third-party liability is covered?
- What business interruption coverage exists?
- What fraud, phishing, social-engineering, or funds-transfer coverage exists?
- What incident-response services are included?
- What cybersecurity controls did we represent or attest to during underwriting?
- Would removing this control affect eligibility, renewal, pricing, policy conditions, or a future claim?
- Can the carrier or broker confirm the answer in writing?
The insurance policy and carrier determine coverage. An IT provider cannot promise that an insurance claim will be paid.
Cyber Warranty and Cyber Insurance Are Different #
Cork Protect activation began for qualifying EasyITGuys Plan 1 clients during 2026. Plan 2 activation is planned for the fourth quarter of 2026. A rollout schedule or plan membership is not proof that a particular organization has active financial protection. Confirm the organization’s current activation status, warranty documents, eligibility requirements, and applicable financial limits before relying on the protection. Cork Protect is a limited cybersecurity warranty and financial protection program. It is not cyber insurance and does not replace an appropriate cyber insurance policy. EasyITGuys does not issue the warranty or decide whether Cork pays a particular claim. Current plan references, financial limits, sublimits, eligibility requirements, exclusions, and client-specific status can change. Review the current Cyber Warranty Financial Protection and Cork Protect Guide and the organization’s current Cork documentation before relying on any amount or coverage.
Financial Protection Does Not Replace Security #
An organization can manage cybersecurity risk in several ways. It can reduce risk through safeguards. It can avoid an activity that creates risk. It can knowingly retain some risk. It can also transfer or share portions of financial risk through insurance, warranties, contracts, or other arrangements.
| Risk response | Example |
|---|---|
| Reduce | Use security controls to lower the likelihood or impact of an incident. |
| Accept | Leadership knowingly retains the risk and has sufficient financial and operational capacity to absorb it. |
| Transfer or share | Use insurance, warranties, or contractual arrangements to allocate defined portions of financial risk. |
| Avoid | Stop the activity creating the risk, such as no longer storing a particular type of sensitive information. |
Transferring financial risk does not make the technical risk disappear. Insurance may help pay defined expenses after an incident. It does not stop an employee from being unable to work, restore a damaged reputation automatically, or prevent a compromised account from being used.
The Accountability Stress Test #
When a recommendation could materially change organizational risk, documenting it is healthy. The purpose is not to trap the person providing advice. The purpose is to make the assumptions, reasoning, responsibilities, and final decision visible. A written recommendation should identify what is being changed, why the change is recommended, what information was reviewed, what baseline was used, what risk remains, and what role the advisor expects to have if an incident occurs. An advisor who declines to assume financial liability is not automatically wrong. Professional advisors normally provide recommendations without becoming the organization’s insurer. It is still reasonable to ask them to document the recommendation and the basis behind it.
A signature is not automatically a transfer of liability. Signing a recommendation documents what someone advised. It does not automatically make that person or company responsible for future losses. If the parties want actual indemnification, reimbursement, guarantees, or other financial risk sharing, that should be established in a separate written agreement reviewed by appropriate legal and insurance professionals.
Cybersecurity Recommendation & Decision Record #
- Use this short record to document a cybersecurity recommendation before making changes. It can be sent to an outside advisor, an internal team, or your current provider, including EasyITGuys. A written response in the advisor’s usual format is also acceptable when it addresses the same points.
- Download the editable Word form (.docx). The template has no EasyITGuys branding. Add your organization’s name or logo before sharing it. Download the EasyITGuys Branded version is here: Download the editable Word form (.docx)
- Use one record for one change or a related group. The advisor completes the recommendation, cost, risk, and response details. An authorized organizational representative completes the decision. Keep answers brief and attach evidence as needed. State “not reviewed” or “unknown” rather than guessing.
Organization: [Organization name]
Date / reference: [Date and optional reference]
Advisor / company: [Name, role, legal entity, and email or phone]
Recommendation #
Proposed change: Name the control or service and affected systems, users, or data. [Enter response]
Basis for the recommendation: Briefly identify relevant experience, information reviewed, supporting standard or evidence, and important limits or assumptions. [Enter response]
Cost and Remaining Risk #
Cost impact: Estimated net monthly savings and one-time costs. Include replacement costs and labor. [Enter response]
Protection after the change: State what replaces the protection, who maintains it, and the remaining risks or downtime exposure. [Enter response]
Requirements review: Identify insurance, warranty, legal, or contractual effects. Name the reviewer or state what remains unchecked. [Enter response]
If an Incident Occurs #
Response plan: Who will assist, with what tasks, availability, and charges? Identify the contact and agreement. Mark proposed services as proposed. [Enter response]
Who pays? Identify existing coverage or cost sharing, the responsible entity, limits, and document reference. State who funds remaining costs, or what is unresolved. [Enter response]
Additional financial risk sharing: ☐ Not proposed ☐ Open to a separate agreement
This selection does not create new coverage or a payment commitment.
Advisor confirmation: This records my recommendation based on the information and limits stated above. It is not a guarantee of an incident-free outcome.
Advisor signature / date: [Signature and date]
Organizational Decision #
☐ Proceed as described ☐ Proceed with conditions ☐ Keep current controls ☐ Further review
Conditions / implementation: Record conditions, the change owner, validation required before removal, target date, and next review date. [Enter response]
For an approved change, I acknowledge the stated remaining risks, response plan, and funding arrangements.
Authorized decision maker / signature / date: [Name, role, signature, and date]
Purpose and limits: This record does not itself authorize technical changes, amend agreements, release existing duties, create insurance, a warranty, or a payment obligation, or determine the cause of a future incident. Follow applicable requirements and the normal change-approval process. Document new service or financial commitments separately with authorized parties. Obtain legal and insurance review as appropriate. Do not include credentials.
Email Template: Ask an Advisor to Document a Recommendation #
Download the Word form above, add your organization’s details, and attach it to the email. Replace the bracketed details before sending. The recipient can return the completed form or provide a written response covering the same points.
Subject: Please document the proposed cybersecurity changes
Hi [Name],
Thank you for helping us review our costs. We are open to changes that make sense for our organization. Before we decide, please complete the attached Cybersecurity Recommendation & Decision Record with your recommended changes, supporting reasons, expected savings, and remaining risks. Your usual written recommendation is also welcome if it covers the same information. Please explain what assistance you would provide if an incident occurred and who would cover the costs. Clearly distinguish commitments under existing agreements from any proposed services or financial risk sharing. We will review the recommendation and applicable requirements before approving changes.
For background, here is the guide we are using: How Much Cybersecurity Is Enough?
Thank you,
[Name]
[Organization]
A Simple Decision Process #
- Define the change. Identify the exact protection, affected systems, current responsibilities, and reason for the recommendation.
- Compare the full cost. Include replacement tools, support labor, internal staff time, implementation, training, and applicable contractual costs. Separate first-year savings from ongoing savings.
- Review the remaining exposure. Check applicable requirements, insurance and warranty implications, recovery needs, and how losses would be funded. Use the organization’s own operating costs and realistic scenarios rather than an unrelated average breach cost.
- Record the decision. Document the recommendation, evidence, assumptions, responsible parties, conditions, and leadership approval. Keep unresolved requirements visible.
- Implement and validate. Name the person responsible for the change. Where a replacement is needed, verify it before removing the existing protection. Confirm access, backups, monitoring, response arrangements, and any employee instructions affected by the change.
- Check the result. Confirm the expected savings and protection. Record how the change can be reversed and when it will be reviewed again.
Example: Removing a $100 monthly service creates $1,200 in annual invoice savings. If replacement tools cost $25 per month and implementation costs $300, first-year savings are $600 before staff time or other costs. This is an arithmetic example, not an estimate of incident likelihood or loss. A provider change and a reduction in security are different decisions. An organization may change providers while preserving or improving its controls. It may also reduce unnecessary products without reducing the protection it needs.
Cybersecurity Videos and Training #
These videos provide additional cybersecurity education. Use the reference section to review the supporting sources and current guidance before applying recommendations to your organization.
Independent Cybersecurity References and Further Reading #
For a general starting point, review the NIST, CIS, FTC, and CISA resources. Use insurance, industry, federal-contracting, and state resources when they apply to your organization. You do not need to read every reference to begin a useful discussion. These sources serve different purposes. A technical framework, educational tutorial, commercial service description, advocacy statement, and legislative announcement are not interchangeable. Inclusion here does not mean the publisher endorses EasyITGuys, a particular product, or a specific recommendation. Some resources are historical or describe a specific program. Check publication dates, framework versions, applicability, and current governing requirements before using them to justify a change. External links open in a new tab or window.
NIST and the NIST Cybersecurity Framework #
- NIST Small Business Cybersecurity Corner
- Cybersecurity Basics | NIST
- NIST Cybersecurity Framework 2.0 for Small Business
- NIST Small Business Quick-Start Guides
- NIST Cybersecurity Framework 2.0: Small Business Quick-Start Guide, SP 1300 PDF
- NIST Cybersecurity Framework 2.0: Small Business Quick-Start Guide
- SP 1300 | NIST Computer Security Resource Center
- Building Your Small Business’s Cybersecurity Team: From In-House to Outsourcing | NIST explains staffing options, relevant provider experience, and documented service responsibilities.
- Digital Identity Guidelines: Authentication and Authenticator Management | NIST SP 800-63B-4 provides technical authentication guidance, including password changes and compromised credentials.
Center for Internet Security and CIS Controls #
- CIS Critical Security Controls Implementation Groups
- CIS Critical Security Controls Implementation Group 1
- Implementation Guide for Small- and Medium-Sized Enterprises: CIS Controls IG1
- CIS Managed Detection and Response is a service overview. It is separate from the CIS Controls and does not establish a requirement to purchase that service.
U.S. Small Business Administration #
- Strengthen Your Cybersecurity | U.S. Small Business Administration
- Cybersecurity for Small Business | SBA Legacy Resource
- Protect Your Small Business from Cybersecurity Attacks | SBA Preview Resource
- Keep Your Business Safe from Cybersecurity Threats | SBA Preview Resource
- Office of the Chief Information Officer | SBA Preview Resource
- Empower to Grow | SBA Preview Resource
- In Today’s Economy, Cyber Safety Is Critical to Small Business Success | SBA Legacy Resource
- Protect Yourself from Scams and Fraud | SBA
- Small Business Cybersecurity: Reduce Risk and Build Resilience | SBA Legacy Event Resource
SBA SBIR/STTR Cybersecurity Planning #
- Elements of a Small Business Cybersecurity Plan | SBIR.gov covers physical, network, and data security, employee responsibilities, and planning. This older tutorial references NIST CSF 1.0. Use the current NIST CSF 2.0 resources above for the current framework structure.
Defense-Sector Cybersecurity Resources #
Review defense-sector guidance in the context of the organization’s work, information, and applicable contract requirements. Do not assume every defense-contract requirement applies to every small organization.
U.S. General Services Administration #
- Improving the Nation’s Cybersecurity | GSA explains federal cybersecurity initiatives and government-contractor considerations associated with Executive Order 14028.
This resource provides federal and acquisition context. It is not a universal cybersecurity checklist for organizations that do not have the relevant federal obligations.
Federal Trade Commission #
- Cybersecurity for Small Business | Federal Trade Commission
- Protecting Small Businesses | Federal Trade Commission
- Cybersecurity Basics for Small Business | Federal Trade Commission
- Recognize Data Privacy Day by Protecting Your Small Business from Cybercriminals | FTC
- Protecting Small Business | FTC Bureau of Consumer Protection
- Cybersecurity Basics for Small Business | FTC Consumer Advice
- Protect Your Business from Scams and Online Threats | FTC
- Cybersecurity for Small Business: Secure Remote Access | FTC
- Cyber Insurance | Federal Trade Commission
- FTC Safeguards Rule: What Your Business Needs to Know
Department of Homeland Security and CISA #
- Cybersecurity | U.S. Department of Homeland Security
- Cyber Guidance for Small Businesses | CISA
- Small and Medium Businesses | CISA
- Small and Medium-Sized Business Cybersecurity Resources | CISA
Federal Communications Commission #
- Cybersecurity for Small Businesses | Federal Communications Commission
- Ten Cybersecurity Tips for Small Businesses | FCC PDF
Federal Bureau of Investigation #
National Security Agency #
- NSA Cybersecurity Advisories and Guidance
- NSA Center for Cybersecurity Standards
- NSA Highlights Cyber Hygiene Best Practices Effective Against AI-Enhanced Targeting
- NSA’s Top Ten Cybersecurity Mitigation Strategies | PDF
Wisconsin State and Business Development Resources #
- Cybersecurity | Wisconsin Small Business Development Center
- Cybersecurity Matters | Wisconsin Economic Development Corporation
- Cybersecurity Basics | Wisconsin Department of Administration PDF
- Cybersecurity | Wisconsin Division of Enterprise Technology provides state cybersecurity education, response information, and links to standards and other resources.
- Cybersecurity Center for Business | University of Wisconsin-Whitewater provides information about cybersecurity education, research, outreach, and organizational resources.
Massachusetts Cybersecurity Minimum Baseline #
Small Business Development, SCORE, and Educational Resources #
- Important Cybersecurity Basics for Small Businesses | SCORE
- Transcript: Cybersecurity for Small Businesses | NCSBC
Cyber Insurance Carrier Education #
These resources are provided as examples of how major insurance carriers discuss cyber risk and cyber insurance. They are not substitutes for the organization’s actual insurance policy or advice from its licensed insurance professional.
- Cyber Insurance for Small Businesses | The Hartford
- Cyber Insurance for Small Business | Main Street America Insurance
- Cyber Insurance for Small Businesses | Liberty Mutual
Regulated and Contractual Cybersecurity Examples #
These are examples of requirements that may apply when an organization operates within a particular regulated or contractual environment. Applicability should be confirmed for the specific organization.
- HIPAA Security Rule | U.S. Department of Health and Human Services
- HIPAA Cybersecurity Guidance | U.S. Department of Health and Human Services
- Cybersecurity Maturity Model Certification Program | Department of Defense CIO
- CMMC Resources and Documentation | Department of Defense CIO
Videos and Training #
- Cybersecurity Basics for Small Business | Video
- Cybersecurity Basics for Small Business | FTC Consumer Advice
- Small Business Cybersecurity and Privacy Videos | NIST
- Cybersecurity Basics for Small Business | FTC Video Resource
- Cybersecurity Basics for Small Business | Vimeo Video
Small Business Advocacy: National Small Business Association #
NSBA is a private small-business advocacy organization, not the U.S. Small Business Administration. This page presents advocacy positions. It is not a government cybersecurity standard or an insurance coverage document.
Legislative Background and News #
These resources document legislative proposals and reporting at the time of publication. A proposal, press release, or news article is not proof of a currently applicable legal requirement. Verify current legislative status, enacted text, applicability, and effective dates before relying on legislation.
- Rep. Wied Introduces Bill to Strengthen Cybersecurity and Reduce Costs for Small Businesses | Congressional Office Announcement is the September 3, 2026 announcement of the proposed legislation.
- U.S. Rep. Wied: Introduces Bill to Strengthen Cybersecurity and Reduce Costs for Small Businesses | WisPolitics republishes the announcement. It should not be counted as a separate technical standard or independent validation of its claims.
- Federal Cyber Bill Would Probe Attacks on Small Businesses | Government Technology is a news resource, not a cybersecurity control standard.
Independent and Secondary Commentary #
Secondary commentary can be useful for perspective. It should not replace current authoritative standards, governing requirements, insurance documents, or organization-specific risk analysis.
Source of Truth #
This guide is educational. It does not determine an organization’s legal obligations, insurance coverage, cybersecurity requirements, contractual responsibilities, or acceptable level of risk. Applicable laws, regulations, contracts, customer requirements, insurance policies and applications, governing agreements, documented technology configuration, approved organizational risk decisions, and current authoritative standards remain the source of truth where applicable. For EasyITGuys clients, the applicable MSA or Terms, Service Guide, accepted Quote or Order, documented configuration, and current client-specific Cork documents also remain controlling where applicable. A signed recommendation record documents advice and a decision process. It does not by itself create indemnification, insurance coverage, reimbursement obligations, guarantees, or a transfer of legal liability.
Frequently Asked Questions #
Is it wrong to reduce cybersecurity spending? #
No. Cost is a legitimate part of risk management. Organizations should regularly identify unused services, duplicate controls, obsolete technology, unnecessary accounts, and protections that no longer address a meaningful risk. The important part is understanding what changes when the cost is removed.
Does every small organization need the same amount of cybersecurity? #
No. Risk varies based on users, data, applications, industry, contracts, locations, technology, regulatory obligations, insurance requirements, operational dependence, and the organization’s ability to absorb a loss.
Are the CIS Controls legally required for every organization? #
No. CIS Controls are a recognized cybersecurity framework and prioritization model. CIS describes IG1 as essential cyber hygiene, but CIS itself does not make IG1 a universal law. A particular safeguard may still become important through a contract, insurer, regulatory requirement, customer requirement, or organizational standard.
Why does EasyITGuys use CIS IG1 and IG2? #
CIS provides a structured way to prioritize safeguards according to organizational risk and complexity. EasyITGuys uses IG1 as the Plan 2 design baseline and IG2 as the Plan 1 design baseline. That is an EasyITGuys service standard. It does not mean every organization is legally required to purchase those services or use the same technologies.
If another provider can offer less security for less money, can we use them? #
Yes. The important question is what the new environment includes, what it removes, which risks remain, whether applicable requirements are still satisfied, and who is responsible for each function. The provider name matters less than the resulting risk and accountability.
If everything is in the cloud, do we still need computer security? #
Possibly. Cloud applications can remove substantial local infrastructure, but the computer may still provide access to authenticated sessions, email, credentials, banking, customer information, administrator portals, and other cloud services. The risk often moves rather than disappears.
If we use passkeys or security keys, can we eliminate other controls? #
Strong passwordless authentication can materially reduce some credential-related risks. It does not automatically address malware, unpatched software, data loss, unauthorized administrator access, backup, network risk, employee fraud, monitoring, or incident response.
What if we barely use email? #
That can reduce one common attack surface. The organization should still evaluate websites, mobile devices, SMS, cloud applications, banking, vendor portals, social-media accounts, remote access, and other digital systems it depends on.
What if we do not store customer data? #
That can materially reduce exposure. Confirm what actually exists before making the decision. Email, employee information, payroll, accounting, customer contact information, credentials, cloud applications, backups, and payment records can still contain sensitive or operationally important information.
What if our software vendor says its platform is secure? #
That is valuable, but determine the boundary of the vendor’s responsibility. A cloud application provider may secure its platform while the organization remains responsible for user identities, endpoints, administrator access, email, local networks, account recovery, and other systems.
Does breach monitoring replace a password manager, MFA, or identity security? #
No. Breach monitoring can identify information that has appeared in known breach data. It does not prevent a new phishing attack, malicious login, stolen session, weak recovery method, or future credential theft.
Should we change every password every month? #
Not simply because another month has passed. NIST SP 800-63B-4 says authentication systems should not require periodic password changes, but should require a change when there is evidence of compromise. The publication is linked in the NIST references above. Use unique credentials and appropriate authentication protection. Follow applicable requirements and review conflicting policies with the responsible technical or compliance advisor. Routine password changes do not replace MFA, secure recovery methods, or protection of the device used to sign in.
Does cyber insurance mean we can safely reduce security? #
Not automatically. Insurance transfers defined portions of financial risk according to the actual policy. It does not prevent an incident. Security changes can also affect underwriting, renewal, policy conditions, or other insurance considerations. Review material changes with the organization’s licensed insurance professional.
Is cyber warranty coverage the same as cyber insurance? #
No. Cyber warranty financial protection and cyber insurance are different. A warranty may complement insurance when its requirements are satisfied, but it does not replace an appropriate cyber insurance policy.
If an advisor will not sign the accountability record, does that prove the recommendation is bad? #
No. Some advisors may have policies that prevent them from signing client-created documents or accepting financial responsibility. Ask whether they will provide their technical recommendation and reasoning through their normal written process instead.
If an advisor signs the record, are they responsible for our future losses? #
Not automatically. The signature documents the recommendation. Actual indemnification, reimbursement, guarantees, or financial risk sharing should be established through a separate enforceable agreement reviewed by appropriate legal and insurance professionals.
Why ask whether the advisor will share financial risk at all? #
The question helps separate technical advice from financial risk transfer. Someone can reasonably recommend that a risk is acceptable while also stating that the organization will retain the financial consequences. That distinction should be understood before leadership makes the decision.
Should the same accountability apply to EasyITGuys? #
Yes. EasyITGuys should be able to explain why a control exists, what risk it addresses, what baseline supports it, what alternatives may exist, and what changes if the control is removed. Accountability should not depend on which direction the recommendation goes.
Can we knowingly accept more cybersecurity risk to save money? #
Yes. Leadership can make an informed decision to retain risk after applicable obligations are addressed. The organization should understand the expected savings, remaining exposure, insurance implications, recovery plan, financial capacity, and decision owner. The decision should also be reviewed when circumstances change.
Who makes the final decision? #
Organizational leadership makes the organizational risk decision. IT providers, cybersecurity professionals, insurers, attorneys, auditors, regulators, vendors, and other advisors can provide important information. They do not normally replace leadership’s responsibility to decide how much residual risk the organization is prepared to retain.
What takes precedence if this guide conflicts with our agreement, policy, regulation, or another governing requirement? #
The applicable governing source controls. That may include law, regulation, contract, insurance policy, customer requirement, accepted agreement, documented configuration, or current authoritative program requirement. This guide is intended to help organizations ask better questions and make better-informed decisions. It does not replace those sources.