10 essential cyber hygiene best practices

Kevin Mabry shares 10 essential cyber hygiene practices for small firms in 2026. Learn how to block ransomware, fix MFA gaps, and lower your cyber risk today.
I started helping firms protect their data in 1999. Back then, "cyber hygiene" meant making sure you didn't leave your floppy disks in the sun and keeping your antivirus updated so the "I Love You" virus didn't wipe out your hard drive. Today, the stakes have changed completely. I’m no longer just fighting off rogue scripts; I’m helping small business owners defend against multi-billion dollar criminal syndicates using automated AI to find every crack in your armor.
Being a small firm—whether you’re a law practice, an accounting firm, or an engineering group—does not make you invisible to attackers. In many cases, it makes you the perfect target. Criminals expect you to have fewer safeguards, limited monitoring, and employees who have never been shown what to watch for. You don’t need an enterprise-sized security department, but you do need more than just the "assumption" that your IT provider has everything covered.
When I sit down with a business owner today, I tell them the same thing: Cybersecurity is a business decision, not a technical one. If you can’t operate for three days because of ransomware, that’s not an IT problem—that’s a survival problem.
Key Takeaways
- Human Risk is the #1 Vector: Over 60% of breaches still involve a human element, like a malicious click or a socially engineered call (Verizon DBIR 2025).
- Ransomware Hits SMBs Harder: While large firms see ransomware in 39% of breaches, for small businesses, that number jumps to 88% (Verizon DBIR 2025).
- MFA Must Be Phishing-Resistant: Standard SMS or push notifications are no longer enough; 2026 standards require FIDO2 or Passkeys to block real-time phishing.
- The Cost of Silence: The average cost for a small business breach ranges between $120,000 and $1.24 million. For many of the firms I work with, that’s an existential threat.
- Patching is Non-Negotiable: Vulnerability exploitation surged by 34% recently. If your VPN or edge devices aren't patched within 32 days, you're a sitting duck.
The Real Cost of "Just Getting By"
I once got a call from a client at 6 AM—a 15-person specialized consulting firm. They thought they were too small to be noticed. But a single employee reused a password from a compromised retail site, and because they didn't have Multi-Factor Authentication (MFA) on their email, the attacker walked right in. By the time I was called, the attacker had been in their system for three weeks, learning who their clients were and how they billed. The firm lost $85,000 in a single wire fraud incident, and the forensic cleanup cost another $40,000. That is the reality for small firms in 2026.
According to the latest IBM Cost of a Data Breach Report, the average cost of a breach in the U.S. has hit a staggering $10.22 million. While that includes the giants, for a firm with under 500 employees, the average still sits at $3.31 million. Most 10-person firms don't have $3 million sitting in a "cyber disaster" fund. That’s why these ten practices aren't just suggestions—they are the floor of what you need to survive.
1. Move to Phishing-Resistant MFA
In 2022, I would have told you that any MFA is better than none. In 2026, I’m telling you that SMS codes and simple push notifications are failing. Attackers now use "MFA fatigue" (bombarding your phone with requests until you hit 'Approve' just to make it stop) or transparent proxies to steal your session tokens in real time.
I recommend all my professional service clients move to phishing-resistant MFA. This means using hardware keys like YubiKeys or device-based Passkeys (FIDO2). These methods use a cryptographic handshake that only works with the real website. If an employee lands on a fake "Microsoft Login" page, the hardware key simply won't respond because it knows the domain is a fraud. It removes the human's ability to make a mistake.
2. Enforce the Principle of Least Privilege (PoLP)
I’ve seen too many firms where the receptionist has administrative access to the entire server, or every partner has "Global Admin" rights on Microsoft 365. That is a recipe for disaster. If that receptionist clicks a bad link, the malware now has administrative rights to your entire network.
I advise firms to audit their access every 90 days. Ask yourself: Does this person actually need to see these files to do their job? If the answer is no, revoke the access. In 2025, third-party involvement in breaches doubled to 30%. By limiting what your own staff and vendors can see, you contain the "blast radius" of any single compromise.
3. Implement Managed Detection and Response (MDR)
Antivirus is like a locked door. It’s great, but a determined burglar can kick it down. Managed Detection and Response (MDR) is like having a 24/7 security guard watching the cameras inside the building. In 2026, hackers move fast. The median time it takes for an attacker to move from your email to your server is often less than 24 hours.
I tell business owners to stop relying on generic IT support for security monitoring. You need a dedicated team (a Security Operations Center or SOC) using AI-driven tools to spot weird behavior—like an employee logging in from Virginia and then two minutes later from Bulgaria. MDR services have become affordable for small firms, and they are the single best way to stop a breach before it becomes a headline.
4. Automate Your Patch Management
Last year, I worked with an 8-person accounting firm that got hit with ransomware because of an unpatched VPN. They had the patch available for 45 days, but their IT guy "hadn't gotten around to it" because he was busy fixing a printer. That delay cost them two weeks of downtime during tax season.
The 2025 DBIR shows that exploitation of vulnerabilities surged by 34%. Attackers are using automated bots to scan the internet for unpatched systems. If you are doing this manually, you will lose. You must use automated tools that push security updates to every laptop, server, and network device the moment they are released. If it’s not automated, it’s not happening.
5. Use a Corporate Password Manager (and Kill Passwords)
The average professional now juggles over 100 sets of credentials. Expecting your staff to remember these without reusing them is a fantasy. I’ve watched firms lose everything because a partner used the same password for his firm’s banking and his local pizza shop’s rewards app.
You need a corporate-grade password manager like Bitwarden or 1Password. This allows you to enforce long, complex passwords (think 16+ characters) without the friction. Even better? Move toward Passkeys. Passkeys are the future—they use your face, fingerprint, or a PIN on your device to log you in, meaning there is no password for a hacker to steal in the first place.
6. Encrypt Everything (At Rest and In Transit)
If a laptop is stolen from a partner’s car, is it a "bad day" or a "firm-ending event"? If that hard drive is encrypted, it’s just a bad day—you wipe the device remotely and buy a new one. If it’s not encrypted, you have to notify every client that their sensitive data is now in the hands of whoever has that laptop.
In 2026, we also have to worry about Shadow AI. I've seen employees upload sensitive client contracts to public AI tools to "summarize" them. That data is now out of your control. Proper cyber hygiene includes using Data Loss Prevention (DLP) tools that stop sensitive info from being uploaded to unauthorized sites or AI platforms. IBM found that Shadow AI adds an average of $670,000 to breach costs because of the legal fallout.
7. Deploy Immutable Backups and Test Them
Ransomware actors have gotten smart. They don't just encrypt your data; they find your backups and delete them first. I once sat with a law firm owner who was crying because he had paid for backups for five years, but when he needed them, they were gone. The hackers had been in his system for a month and wiped every backup he had.
You need immutable backups—backups that cannot be changed or deleted for a set period, even by an administrator. And you must test them. I recommend a full "fire drill" once a quarter. If you haven’t restored a file in the last 90 days, you don’t have a backup; you have a hope.
8. Human Risk Management (Not Just "Training")
Most "security awareness training" is a boring 15-minute video that employees play on mute while they do other work. That doesn't work. You need Human Risk Management. This means regular, short bursts of info and simulated phishing tests that reflect the world in 2026—like AI-generated deepfake voice notes or highly personalized emails.
When I run these tests for clients, I usually find that one or two people click everything. I don't fire them; I train them. I’ve seen a 7x improvement in phishing resistance in firms that do this monthly. It’s about building a culture where an employee feels safe saying, "Hey Kevin, this email looks weird," rather than hiding their mistake.
9. Secure the "Home Office"
The line between work and home has vanished. I frequently see partners using their work laptops to let their kids play games or check social media. That’s a massive hole in your security. A "free" game downloaded by a teenager can install a keylogger that steals every password the partner types.
Your policy must be strict: Work devices are for work. Period. Additionally, ensure your home routers are not using the default "admin/admin" passwords. If I can hack your home Wi-Fi from the street, I can get onto your work laptop. I recommend a separate Wi-Fi network (a "VLAN") just for work devices in home offices.
10. Create (and Rehearse) an Incident Response Plan
In my 26 years of doing this, I've learned that the businesses that survive a breach are the ones that had a plan *before* the screen turned red. If you’re trying to find your insurance policy number and an emergency IT contact while your files are being deleted, you’ve already lost.
You need a one-page document that lists exactly who to call: your cyber insurance carrier, your specialized security provider (like Sentree), and your legal counsel. IBM’s 2025 report shows that firms with a tested Incident Response (IR) plan save $2.66 million on average compared to those without one. It is the single biggest ROI in cybersecurity.
Frequently Asked Questions
What is the median ransom payment for a small business in 2026?
Per the Verizon 2026 DBIR, the median ransom payment has settled around $139,875. However, this doesn't include the cost of downtime, which can be 5 to 10 times higher than the ransom itself. Many firms spend over $500,000 just to get back to normal operations.
Why is SMS-based MFA considered unsafe now?
SMS codes are vulnerable to "SIM swapping," where an attacker convinces a cell provider to move your number to their phone. Furthermore, AI-driven phishing sites can now "proxy" the code in real-time. The attacker captures your username, password, and the SMS code as you type it into a fake site, logging in as you instantly. Phishing-resistant methods like Passkeys eliminate this risk.
Can I just rely on my cyber insurance for protection?
No. Cyber insurance is a safety net, not a shield. In 2026, insurance carriers are much stricter. If you don't have MFA, encrypted backups, and an incident response plan, they may deny your claim or refuse to renew your policy. Most policies also have exclusions for "gross negligence," which unpatched systems can fall under.
How long does it take to recover from a typical breach?
The average breach lifecycle in 2026 is roughly 241 days—181 days to identify the intruder and another 60 to contain the damage. Small firms often take longer because they lack the monitoring tools to spot the "smoke" before the "fire" starts.
Conclusion
Cybersecurity in 2026 isn't about buying the most expensive software; it's about the habits you build every day. I’ve spent my career helping firms under 100 employees realize that they can be secure without being technical experts. It starts with the basics: move to better MFA, automate your updates, and stop letting people have access to things they don't need.
If you're feeling overwhelmed, start with point #10. Write down your emergency contacts today. Then, look at point #1. If you aren't using Passkeys or hardware keys, make that your goal for next month. Cybersecurity should help you make better decisions—not bury you in technical noise. Your firm's survival depends on it.
Related Articles in Small Business Cybersecurity Basics
- Why Small Businesses Are Prime Targets for Cyberattacks in 2026
- Why Your Small Business Is a Prime Target for Cyberattacks
- Why Small Indiana Law Firms Are Top Targets for Cyberattacks
- Why Classifying Information is Essential for Small Business Cybersecurity
- What is an Advanced Persistent Threat (APT)? Protecting Your Small Firm
- Disaster-Proofing Your Firm: Why Business Continuity Planning is Critical
- Small Business Cyber Security: Protecting Your Firm with the NIST Framework
- Protecting Your Firm: The Real Cost of Data Collection and Security
- Cybersecurity Awareness: Why Your Small Firm is a Prime Target
- Why Active Threat Hunting is Critical for Small Professional Service Firms
- Best Cybersecurity Trends in 2023 for a Positive Future
- Scams: The latest in 2022 Holiday's
- Cyber Security Audit: 5 Powerful Ways to Boost Protection
- Cybersecurity Fundamentals: 5 Power Moves for Unbreakable Digital Armor
- 3 Critical Cybersecurity Performance Goals Your Team Missed
- 5 Powerful Steps for Security in Depth Success
- Preventing Cyber Threats in Small Business: 5 Essential Tips
- Unlock Success: 5 Tips for Employee Cybersecurity Training
- Cyber Resilience In The Face Of Increase Threats
- 7 Essential Best Practices for Indiana Small Business Cyber Security
- 5 Shocking Questions to Ask Before Hiring a Cybersecurity Provider
- Digital Transformation: Why cyber security is critical
- Tiers of Cyber Security: 3 Critical Levels for Full Protection
- 5 Reasons Why Cyber security is important to small business
- Why MFA Is the Single Most Important Security Control
- 5 Essential Cybersecurity Solutions for Small Businesses
- Cyber security Tips: 10 Powerful Ways to Secure Your Business — Complete guide on Small Business Cybersecurity Basics
- 7 Essential Employee Cybersecurity Training Tips That Work
- Ultimate Multi-Factor Authentication for SMBs: 5 Critical Steps
- Boost Your Security with Implementing Multi-Factor Authentication: 5 steps
- Ultimate Best Practices for Data Backup and Recovery: 5 Key Takeaways
- 7 Critical Steps for Conducting a Cybersecurity Audit
Watch: $450,000 Vanished: The 3 PM Email That Ended a Title Firm
Kevin Mabry
Founder & CEO, Sentree Systems
Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.
His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.
Is your business protected?
Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.
Schedule Your Free Assessment