HomeBlog3 Critical Cybersecurity Performance Goals Your Team Missed
All PostsSmall Business Cybersecurity Basics

3 Critical Cybersecurity Performance Goals Your Team Missed

Kevin MabryJuly 20, 2026
small business cybersecuritycybersecurity performance goalsKevin MabrySentree Systemsdata breach preventionMFA securityIT security for small firms
3 Critical Cybersecurity Performance Goals Your Team Missed

Don't let your business become a statistic. I’m breaking down the 3 critical cybersecurity goals your small firm is likely missing and how to fix them today.

Last Tuesday, a 14-person law firm in downtown Chicago vanished. They didn’t move offices, and they didn’t go bankrupt in the traditional sense. They simply ceased to exist because a single paralegal clicked a link in an email that looked like a routine PDF from the county clerk. Within four hours, their entire server was encrypted. Within six hours, their cloud backups—which were unfortunately connected to the same admin account—were wiped clean. By Friday, the hackers demanded $450,000 in Bitcoin. According to the 2024 IBM Cost of a Data Breach Report, the average cost of a breach for a small business has climbed to over $3.3 million when you factor in downtime, lost reputation, and legal fees. For this firm, the cost was 100% of their business. They couldn't pay, they couldn't recover, and they couldn't bill clients. They closed their doors forever.

I’ve been in this game since 1999. In those 26-plus years, I’ve seen the same story play out more times than I care to count. Small business owners often tell me, "Kevin, we’re too small to be a target. Why would a hacker in Eastern Europe care about a 20-person accounting firm in the Midwest?" The answer is simple: because you’re easy. You’re a "soft target." You have the same sensitive data as a giant corporation—Social Security numbers, bank details, healthcare records—but you likely have about 1% of their security budget. To a cybercriminal, you aren't a person or a company; you're a low-risk, high-reward entry in a database.

That is why the recent move by the U.S. Department of Health and Human Services (HHS) is so significant. They have released a set of voluntary Cybersecurity Performance Goals (CPGs). While these were written for the healthcare sector, I am telling you right now: if you run a professional service firm—be it legal, financial, or consulting—these goals are your new gold standard. They are the blueprint for survival in 2026. If your team isn't hitting these three specific goals I’m about to outline, you aren't just "at risk"—you are essentially leaving your vault door wide open with a "Welcome" mat out front.

Key Takeaways

  • The "Too Small" Myth is Dead: 43% of all cyberattacks now target small businesses, yet only 14% of those businesses have any plan to defend themselves.
  • Essential vs. Enhanced Goals: Cybersecurity is no longer an "all or nothing" game. The HHS framework breaks it down into "Essential" hygiene (doing the basics) and "Enhanced" protection (fighting off the pros).
  • MFA is Non-Negotiable: Multi-Factor Authentication is the single most effective way to prevent unauthorized access, yet it is still incorrectly implemented in 60% of small firms I audit.
  • The Human Factor is Your Biggest Leak: According to the 2024 Verizon Data Breach Investigations Report (DBIR), 68% of breaches involved a human element, including errors and social engineering.
  • Recovery is More Important than Prevention: You will eventually get hit. The difference between a "bad afternoon" and "going out of business" is your ability to restore data from an immutable, offline backup.
  • Vendor Risk is Your Risk: If you use a third-party payroll or CRM provider, their weak security is your weak security. The CPGs now demand you vet your partners.
  • ROI of Security: Investing $1 in proactive cybersecurity measures saves an average of $6 in emergency response, legal fees, and lost revenue.

Understanding the CPG Framework: Why It Matters to You

When the government releases a "voluntary" framework, most small business owners yawn and go back to their spreadsheets. But the HHS Cybersecurity Performance Goals (CPGs) are different. They were designed specifically because the old way of doing things—throwing a bunch of technical jargon at a wall and hoping it sticks—wasn't working. These goals are divided into two clear buckets: Essential and Enhanced.

The Essential Goals are what I call "digital soap and water." They are the basic hygiene practices that every firm must follow to stay healthy. If you aren't doing these, you're the equivalent of a surgeon walking into an operating room without washing their hands. The Enhanced Goals are for when the stakes are higher—when you’re dealing with highly sophisticated attackers who are specifically targeting your firm’s intellectual property or large cash reserves.

The Essential Goals: Your Minimum Viable Defense

In my 26 years of running Sentree Systems, I’ve audited hundreds of firms. Almost every single one of them thinks they have the "basics" covered. They don't. The HHS Essential Goals focus on things like revoking access for employees who leave the company within 24 hours. I once did an audit for a 50-person engineering firm and found 12 active administrative accounts belonging to people who hadn't worked there in three years. One of those ex-employees was now working for a direct competitor. That’s not a technical failure; that’s a leadership failure. The CPGs give us a checklist to ensure those gaps are closed.

The Enhanced Goals: Leveling Up

Once you’ve stopped the "easy" attacks, you have to worry about the professionals. The Enhanced Goals move into territory like network segmentation—keeping your guest Wi-Fi separate from your billing server—and advanced endpoint detection. Think of it this way: the Essential Goals lock the front door. The Enhanced Goals install the motion sensors and the security cameras inside the hallways. In 2026, where AI-driven phishing attacks can mimic a CEO's voice perfectly on a phone call, these enhanced measures are becoming less "optional" and more "mandatory" for anyone handling client money.

Goal 1: Identity and Access Management (The Gatekeeper)

The first goal your team probably missed isn't about buying a more expensive firewall. It’s about Identity. In the old days (the early 2000s), we focused on the network perimeter. We built a big wall around the office. But today, the office is everywhere. Your employees are working from home, from Starbucks, and from their phones. The "perimeter" is now the individual user's identity.

According to the 2025 FTC reports on business fraud, identity theft and "account takeover" attacks increased by 44% year-over-year. Why? Because hackers realized it’s easier to log in than it is to break in. If they have your password, they don't need to hack anything. They just walk through the front door. This is why the HHS CPGs place such a massive emphasis on phishing-resistant Multi-Factor Authentication (MFA).

The Failure of Basic MFA

I see this all the time: a business owner tells me, "Kevin, we have MFA. My team gets a text code when they log in." I have to be the bearer of bad news—text-based (SMS) codes are effectively useless against a determined hacker. It’s called "SIM swapping" or "MFA fatigue" attacks. A hacker can intercept those texts or simply spam your employee's phone with 100 alerts at 3:00 AM until the exhausted employee hits "Approve" just to make it stop. The CPGs push for "phishing-resistant" MFA, like hardware keys (YubiKeys) or biometric logins (FaceID/Fingerprint). It’s a small change that eliminates 99% of automated attacks.

The Principle of Least Privilege

Another major miss under the Identity goal is what we call "Least Privilege." In most small firms, everyone is an "Administrator" on their own computer because it’s "easier" that way. If the office manager wants to install a new printer driver, they don't want to call IT. But here’s the reality: if your employee is logged in as an admin and they click a malicious link, the virus also has admin rights. It can disable your antivirus, steal your passwords, and spread to every other computer on the network. If they were logged in as a "Standard User," the virus would have been trapped in a sandbox. I’ve seen this one single change save a 30-person firm from a total wipeout during a malware outbreak in 2023.

Security Measure Implementation Cost Potential Loss Prevented
Phishing-Resistant MFA $20 - $50 per user (one time) $3.3 Million (Average breach cost)
Standard User Accounts $0 (Configuration only) 90% of critical Windows vulnerabilities
Security Awareness Training $2 - $5 per user / month 70% reduction in phishing clicks

Goal 2: Incident Response and "Blast Radius" Control

The second goal your team likely missed is preparing for the "when," not the "if." Most small business owners have a "Prevention Mindset." They buy tools to stop things from happening. But the HHS CPGs advocate for a "Resilience Mindset." You have to assume that at some point, a hacker will get in. When they do, how much damage can they do, and how fast can you kick them out?

Think of your business like a ship. If a ship hits an iceberg and the entire hull is one big open room, it sinks. But if the ship has "bulkheads"—watertight compartments—only one section floods, and the ship stays afloat. In cybersecurity, we call this Network Segmentation. This is an "Enhanced" CPG that most small firms completely ignore.

The Story of the "Broom Closet Server"

In 2022, I was called into a boutique financial planning firm. They had a server sitting in a ventilated broom closet. They also had a smart thermostat, a smart refrigerator in the breakroom, and a guest Wi-Fi network for clients. Everything was on the same network. A hacker compromised the smart refrigerator (which had zero security) and used it as a "beachhead" to move across the network to the server. Because there were no bulkheads—no segmentation—the hacker had a straight shot to the firm's client database. We now implement "Zero Trust" principles for all our clients. We assume the network is already compromised and force every device to prove its identity before it can talk to the server. It sounds complex, but for a 20-person office, it’s just a matter of proper router configuration.

The 3-2-1-1 Backup Rule

Backups are part of the Essential CPGs, but most firms are doing them wrong. They have a "set it and forget it" attitude. I had a client—a 40-person architecture firm—that backed up to a USB drive every night. They thought they were safe. When ransomware hit, the virus was smart enough to look for connected drives. It encrypted the server and the backup drive simultaneously. They were left with nothing.

The CPGs recommend "Immutable Backups." This means once the data is written, it cannot be changed or deleted for a set period, even by an administrator. I advocate for the 3-2-1-1 rule: 3 copies of your data, on 2 different media, with 1 copy offsite and 1 copy immutable or offline. If you don't have that "1" at the end, you don't have a backup; you have a ticking time bomb.

Goal 3: Supply Chain and Vendor Risk Management

The third goal your team missed is looking outside your own four walls. You might have the best security in the world, but what about your payroll company? What about the IT guy you hire as a contractor? What about your cloud-based CRM? The HHS CPGs make it clear: you are responsible for the vendors you choose.

In 2024, the "MoveIt" hack showed us that one vulnerability in a piece of file-transfer software could lead to data breaches at thousands of companies worldwide. According to KnowBe4, supply chain attacks have increased by 300% since 2021. Small professional service firms are especially vulnerable because they rely heavily on niche software vendors who might not have a dedicated security team.

The "Blind Trust" Problem

I recently spoke with a CEO of a 60-person consulting firm. I asked him how he vetted his new cloud-based project management tool. He said, "Well, they had a nice website and they were recommended in a LinkedIn group." That’s not vetting; that’s gambling. The CPGs suggest a formal "Vendor Risk Management" process. This doesn't mean you need a 50-page legal document. It means asking three simple questions before you sign a contract:

  1. Do you have an independent security audit (like a SOC 2 Type II report)?
  2. How do you encrypt my data both when it's sitting on your servers and when it's traveling over the internet?
  3. What is your notification timeline if you get hacked?

If a vendor can’t answer those questions, they don't deserve your data. In my 26 years, I’ve seen more firms compromised through their "trusted partners" than through their own mistakes. You cannot outsource your liability. If your vendor loses your client's data, your name is the one on the lawsuit, not theirs.

The Danger of "Shadow IT"

Vendor risk also comes from inside your house. This is "Shadow IT"—when your employees use apps you didn't approve. Maybe your marketing person is using a free version of Dropbox to share files because the company's secure portal is "too slow." Or maybe an accountant is using an AI tool to "summarize" a confidential client transcript. Once that data is in a free, unmanaged app, it’s gone. You’ve lost control of it. The CPGs emphasize the need for a "Software Inventory." You can’t protect what you don't know you’re using. My team at Sentree Systems uses tools to scan networks and find these "shadow" apps, and we almost always find a dozen or more that the CEO had no idea existed.

Implementation Best Practices: Your 7-Step Action Plan

I know this sounds like a lot. As a small business owner, you’re already wearing ten different hats. You don't want to be a Chief Information Security Officer (CISO). The good news is that you don't have to be. You just need to be a leader who sets the standard. Here is the exact checklist I use when I walk into a new firm to get them aligned with the HHS CPGs:

  1. Conduct a "Reality Check" Audit: Stop guessing. Hire someone to do a vulnerability scan. You need to know exactly where your "broom closet servers" are. This should cost a few thousand dollars but will give you a roadmap for the next three years.
  2. Enforce "Phishing-Resistant" MFA: Don't make it optional. Give every employee a hardware key or set up biometrics. If they complain it takes an extra 2 seconds to log in, remind them that a breach takes 200 days to recover from (IBM 2024).
  3. Kill the "Admin" Accounts: Tomorrow morning, have your IT person remove administrative rights from every workstation. No one should be browsing the web or checking email with an admin account. Period.
  4. Implement "Immutable" Backups: Call your backup provider and ask one question: "If a hacker gets my admin password, can they delete my backups?" If the answer is yes, change your provider immediately. You need "Air-Gapped" or "Immutable" storage.
  5. Start Monthly "Micro-Training": Don't do a 2-hour boring video once a year. Nobody learns that way. Use a platform that sends out a 2-minute "security tip" or a fake phishing test every month. According to KnowBe4, firms that do this see phishing click rates drop from 30% to under 2% within 12 months.
  6. Create a "Kill Switch" Plan: This is your Incident Response Plan. It should be a physical piece of paper (not a digital file!) that tells everyone exactly what to do if they see a "Your files are encrypted" message. Who do they call? Do they unplug the computer? (Hint: usually, yes).
  7. Vet Your Top 5 Vendors: You don't have to vet everyone at once. Start with your top five—the ones who handle your money or your most sensitive client data. Send them a simple security questionnaire. If they balk, start looking for their replacement.

Frequently Asked Questions

Does my small firm really need to follow "Healthcare" goals?

Yes. While the HHS CPGs were written for healthcare, the threats are the same. A hacker doesn't use a different kind of ransomware for a doctor than they do for a CPA. These goals represent the "best practices" that insurance companies are now starting to require. If you want to keep your cyber insurance policy (and you should), you’ll eventually have to prove you’re doing these things anyway.

Is this going to be incredibly expensive?

Actually, most of the "Essential" goals are about configuration, not buying hardware. Removing admin rights costs $0. Implementing MFA often costs less than $10 per user per month. The most expensive part of cybersecurity is the "Emergency Fee" you pay a forensics firm after you've been hacked. Proactive security is a fraction of that cost. I often tell my clients that cybersecurity is like life insurance—it feels like a waste of money until the day you actually need it.

We use the Cloud (Microsoft 365/Google), aren't we already secure?

This is the biggest mistake I see. Microsoft and Google provide the infrastructure, but you are responsible for the configuration. It’s like renting a high-security apartment building; the landlord provides the locks, but if you leave your front door wide open and give your key to a stranger, the landlord isn't responsible. By default, many "security" features in 365 are turned off to make it "easier" for users. You have to go in and turn them on.

Do I need a full-time IT person to manage this?

Not if you’re under 100 employees. For most firms our size, a full-time IT person is an unnecessary overhead. What you need is a "Managed Security Service Provider" (MSSP)—someone who lives and breathes this stuff and can manage it for you at a fraction of a full-time salary. You want someone who is proactive, not "break-fix." If you only call your IT person when something is broken, you aren't doing security; you're doing "disaster management."

What if my employees hate the new security measures?

They will. At first. Change is hard. But security is a culture, not a product. In my 26 years, I’ve found that if the CEO leads by example—if you are the first one to use the hardware key and you attend the training sessions—the rest of the team follows. If you act like security is an "annoying IT thing," they will too. Explain the "why." Tell them about the Chicago law firm that went out of business. It’s not about being "mean"; it’s about protecting everyone’s paycheck.

How often should we update these goals?

Cybersecurity isn't a project; it’s a process. The HHS CPGs are meant to be reviewed at least annually. The threats evolve—AI is the big one in 2026—so your defenses have to evolve too. I recommend a "Quarterly Security Review" where you spend one hour looking at your goals and seeing where you’ve slipped.

Conclusion: The ROI of "Doing the Basics"

I get it. You started your business to be a lawyer, an accountant, or a consultant—not a tech expert. But in 2026, every company is a tech company, whether they like it or not. The HHS Cybersecurity Performance Goals aren't just another government mandate; they are a survival guide for the modern era.

Look at the numbers again. If you spend $10,000 this year on better MFA, immutable backups, and staff training, and that prevents a $3.3 million breach, your Return on Investment is 32,900%. You won't find that kind of return in the stock market or in any real estate deal. Cybersecurity is the only part of your business where a small investment today can literally save the entire company tomorrow.

I’ve spent 26 years helping firms like yours navigate these waters. I’ve seen the heartbreak of a business closing because of a single clicked link, and I’ve seen the triumph of a firm that shrugged off a massive attack because they had their "bulkheads" in place. The CPGs give you the map. All you have to do is start walking. Don't wait for the ransom note to decide that security matters. Start with the Essential goals today, and build your way up to a resilient future. Your clients, your employees, and your bottom line will thank you.

Watch: Client Data Exposure Security Essentials for Consulting Firms

4 viewsJul 9, 2026Watch on YouTube →
KM

Kevin Mabry

Founder & CEO, Sentree Systems

Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.

His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.

Take Action

Is your business protected?

Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.

Schedule Your Free Assessment