Free Security Resources

Practical Cybersecurity Help for Business Owners

Use these quick guides and trusted public tools to improve everyday security. These resources are educational and are not a substitute for a scoped professional assessment.

Passwords & MFA

Protect Business Accounts

  • Use unique passwords for every important account.
  • Use a reputable password manager rather than reusing passwords.
  • Turn on multi-factor authentication for email, banking, cloud apps, and administrator accounts.
  • Remove old or unused accounts quickly.

Phishing

Pause Before You Click

  • Be suspicious of urgent payment or password requests.
  • Verify unexpected requests through a second communication channel.
  • Check the real sender address, not just the display name.
  • Do not open unexpected attachments just because they appear to come from someone you know.

Free Public Tools

Useful Security Checks

  • Check your public website's HTTPS/TLS configuration.
  • Review current CISA cybersecurity advisories.
  • Check whether known vulnerabilities are being actively exploited.
  • Use trusted public resources rather than unknown “free scanner” websites.

Backups & Ransomware

Plan for Recovery

  • Keep backups protected from the same accounts and systems used every day.
  • Test that critical data can actually be restored.
  • Keep operating systems and software patched.
  • Limit unnecessary remote-access services and administrator privileges.

Incident Response Checklist

If You Think Your Business Has Been Compromised

Do not panic or start deleting evidence. Focus on limiting damage and preserving useful information.

  1. Disconnect affected devices from the network if you can do so safely.
  2. Do not reuse potentially compromised passwords; change them from a known-clean device.
  3. Document what happened, when you noticed it, and what systems appear affected.
  4. Preserve logs, suspicious emails, screenshots, and other evidence.
  5. Contact your IT/security provider and cyber-insurance carrier if applicable.
  6. Consider legal, regulatory, law-enforcement, or customer notification obligations based on the incident.