Read almost any serious cybersecurity guidance and you will notice something odd within two pages. It keeps referring to people you do not employ. The security operations center. The compliance team. The risk committee. The identity architect. The guidance is not wrong. It is written for an organization with a security department, a dedicated budget line, and an auditor who visits every year.

You have twenty people, an office manager who also handles HR, and an owner who signs every check over a thousand dollars. When you read enterprise guidance in that context, one of two things happens. Either you conclude that real security is out of reach and quietly do nothing, or you buy a pile of tools trying to imitate a program you do not have the staff to run. Both outcomes are bad, and both are avoidable. The guidance does not need to be ignored. It needs to be right sized.

The Assumptions Nobody States Out Loud

Enterprise security advice is not padded with nonsense. Every recommendation exists because something went wrong somewhere. The problem is that those recommendations sit on assumptions that go unstated because, in a large company, they are simply true.

  • Somebody watches alerts. Detection guidance assumes a person or a service is reviewing what the tools produce. A tool that emails a busy office manager is not detection. It is a filing cabinet.
  • There is a separate approver. Large organizations separate who requests access from who grants it. In a twenty person company, that is often the same person. You can still manage this, but not by pretending the separation exists.
  • Projects have owners with time. A rollout that takes an enterprise team six weeks takes a small business six months, because the person doing it also has a day job.

Naming these assumptions is not an excuse to skip security. It is how you decide which parts of the advice translate directly, which parts need a smaller version, and which parts do not apply to you yet.

The Small Version Already Exists, and It Is Free

Here is the part most owners do not know. The organizations that write the big frameworks also wrote short versions for you, free.

The National Institute of Standards and Technology publishes a Small Business Quick-Start Guide for its Cybersecurity Framework 2.0. It organizes everything into six functions in plain language: Govern, meaning establish and monitor your strategy and policy; Identify, meaning determine your current risks; Protect, meaning use safeguards to prevent or reduce those risks; Detect, meaning find and analyze possible attacks; Respond, meaning take action on what you find; and Recover, meaning restore what was affected. Six ideas. Not six hundred pages.

CISA does something similar with its Cyber Essentials material, built around six areas it calls essential elements: Yourself, meaning the leader; Your Staff; Your Systems; Your Surroundings; Your Data; and Your Crisis Response. Both documents assume you have limited time and no security department. Neither assumes you will do everything at once. That is the point.

The Owner Is the Security Decision Maker

In an enterprise, security decisions get spread across committees. In your company, they land on you. That sounds like a disadvantage. It is one of the few structural advantages small businesses have, because you can decide something Tuesday and have it in place Friday.

The federal guidance says this directly rather than dancing around it. NIST’s small business guide tells owners to “understand who within your business will be responsible for developing and executing the cybersecurity strategy.” CISA’s Cyber Essentials is blunter still, telling leaders that “your success depends on Cyber Readiness. Both depend on YOU,” and that “your investment drives actions and activities that build and sustain a culture of cybersecurity.” Neither document says to hire a chief information security officer. They say to decide who owns this, and to make sure that person has authority and budget.

Practically, that means the owner sets the direction and either does the work, assigns it internally, or hires it out. NIST’s guide explicitly contemplates the third option, noting that these materials can serve as a discussion prompt with whoever you have chosen to help reduce your risks, including a managed service provider. Delegating the execution is normal. Delegating the decision is not.

Do the Handful of Things That Stop Most Attacks

Right sizing does not mean doing less security. It means doing fewer things properly instead of many things halfway. Most attacks that hit businesses your size are not clever. They are opportunistic: a stolen password, an unpatched system, a convincing email, a backup that turned out not to work. A short list of controls, actually finished, stops a disproportionate share of that.

  1. Multi-factor authentication everywhere it exists. NIST’s small business guide calls enabling multi-factor authentication “one of the fastest, cheapest ways you can protect your data.” Start with email, then remote access, then finance.
  2. Backups that are offline and tested. A backup you have never restored from is a theory. Restore something on purpose, on a calm day, and write down how long it took.
  3. Patching on a schedule. Not perfect, not instant. Consistent. A monthly rhythm that actually happens beats an aspirational weekly one that does not.
  4. Access that shrinks when people leave. Offboarding is a security control. Most small companies discover their gaps here only after someone leaves badly.
  5. A one page response plan. CISA tells leaders to develop an incident response and disaster recovery plan outlining roles and responsibilities, and to “test it often.” One page with names and phone numbers beats a binder nobody has opened.

You Are Allowed to Skip Things

This is the part almost nobody will say plainly, so we will. At twenty people, some enterprise controls do not apply to you, and pretending otherwise wastes money you could spend on the ones that do.

You do not need your own twenty four hour staffed security operations center. You do not need a formal risk register with quantified loss modeling. You do not need a five tier data classification scheme when you have two kinds of sensitive information. You do not need separate development, testing, and production environments if you do not write software.

Two honest caveats. First, “does not apply yet” is different from “never applies.” Growth, an acquisition, a large customer, or a regulated contract can change your obligations quickly, so revisit the skip list once a year. Second, if a customer contract or an insurance application asks about a control, it applies to you regardless of your size, because you are now attesting to it in writing. Skipping is a deliberate decision you can defend, not a default you drift into.

The Bottom Line

Enterprise security advice is not too advanced for you. It is scoped for a different organization. Translate it: read the small business versions the same agencies publish, name one person who owns the decisions, finish a short list of high value controls before adding anything new, and deliberately set aside the parts that do not fit your size yet.

That approach has a second benefit worth naming. It gives you back time, which for most small businesses is the scarcer resource. We wrote about that tradeoff in our piece on why saving time takes priority over saving money, and it applies here directly. And if you are still deciding whether any of this is urgent, our take on why cybersecurity is no longer optional for mid-sized businesses covers that ground.

If you want an honest read on which controls matter for a company your size and which ones you can leave alone for now, that is a conversation we have with Denton County businesses regularly. No enterprise checklist, no scare tactics, just a short list you can actually finish. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).