Cyber AssessValydex™by iFeelTech
Implementation Guide

Small Business Cybersecurity Roadmap (2026)

90-day implementation plan for practical security outcomes

Source-backed 90-day roadmap covering identity, endpoint, email, network, backup, incident response, and governance controls.

Last updated: September 24, 2026
4 minute read

The 90-day outcome

  • First 30 days: Identify critical systems and owners; close the most dangerous access and payment-approval gaps.
  • By day 60: Verify device coverage, email authentication, vendor access and backup restore capability.
  • By day 90: Practice a response scenario, resolve exceptions and establish a monthly review.
  • Spending rule: Check your current subscription and configuration before buying another product.

Last updated: September 24, 2026

This roadmap is for a US small business with roughly 5–100 staff and limited security capacity. It is an implementation schedule, not a promise of compliance or immunity. NIST's Small Business Quick-Start Guide presents CSF 2.0 as voluntary risk-management guidance that businesses adapt to their own priorities. Start with a free assessment if you need to identify your largest gaps; treat unknown answers as items to verify, not as proof of protection.

Before day one: define the business impact

List the systems that take orders, pay staff, move money, communicate with customers and hold essential records. For each, record the business owner, technical administrator, main supplier, recovery contact and the longest disruption the business can tolerate. Identify your Microsoft 365 or Google Workspace edition, device-management tools, backup service and IT-support arrangement. An existing license may already cover a proposed action, but only a configured and tested control counts.

Priority questionEvidence to collectDecision it supports
Who can administer email, banking and remote access?Named accounts, MFA enrollment and exceptionsRemove stale access and protect privileged roles
Which devices access customer or financial data?Device inventory and last updateSet a minimum managed-device rule
Can the business restore critical work?Backup scope, last success and a test restoreRepair the recovery path before adding tools
Who can approve a payment change?Written callback and second-approver ruleStop email-only approvals

Days 1–30: control the obvious exposure

The owner or operations lead names one accountable person for each workstream. IT enables MFA for email, cloud administration, remote access and financial systems, starting with administrators and finance. Review dormant users, shared administrator logins and third-party access. Finance requires a callback to a previously known number for new bank details and a second approver for material payments; see the BEC verification guide. Confirm backups exist for the systems that matter, including cloud data where coverage is often assumed. Record what could not be verified.

Day-30 evidence: an access list, MFA exception list, payment-change procedure, critical-system inventory and named response contacts. A completed task without a screenshot, export, test or other check is still an unverified task.

Days 31–60: make protection repeatable

IT checks patch and endpoint coverage against the device inventory and assigns an alert owner. The email administrator inventories every legitimate sending service, checks SPF/DKIM/DMARC configuration and reads real message results before changing DMARC enforcement. See the email-security workflow. Review remote and contractor access with a sponsor and expiration date. Restore one important file or service into a safe test location and record whether users could actually resume work.

Day-60 evidence: device-coverage report, overdue-update list, email-sender list, vendor-access exceptions and a dated restore record. If a license includes endpoint or email controls, test those first; only compare a new product against a specific unmet requirement. The SMB toolbox organizes those choices.

Days 61–90: rehearse and govern

Run a tabletop exercise for one likely scenario, such as a finance mailbox compromise or unavailable file server. Decide who can isolate systems, contact the bank or insurer, preserve records, approve customer communications and authorize restoration. Use the incident-response guide to create the runbook. Re-test one access removal and one backup restore. Review all exceptions with a due date and owner.

Day-90 evidence: exercise notes, updated contacts, a restore result, a closed-or-funded exception register and a monthly review date. Continue the security checklist after the first 90 days.

How to decide whether to buy

Write the unmet control, the capability already available, the reason it fails, the administrator who will operate the replacement, and the cost of rollout plus renewal. A paid service that no one can configure or monitor does not close the gap. For identity, endpoint and recovery options, begin with the linked guides in the toolbox; compare plans only after the requirement is clear.

Owner's next three actions

If you have no baseline, appoint the security owner, protect email/admin/finance access with MFA, and verify one critical restore. Assign dates and collect evidence before expanding the list.

Sources checked September 24, 2026: NIST SP 1300, CISA small-business resources, and FTC Cybersecurity for Small Business. This is source-based planning guidance, not a tested deployment or certification.