Build the smallest workable stack
- Start with outcomes: Protect identity and devices, verify payments, detect suspicious activity and restore critical work.
- Use existing entitlements first: An included but unconfigured control is often more valuable than a new subscription.
- Buy for a named gap: Record owner, exact plan, limitation, incremental cost and a pass/fail pilot.
- Avoid tool-count targets: More products can add alerts and administration without improving protection.
Last updated: September 24, 2026
A cybersecurity toolbox is the set of controls your business can operate and verify, not a shopping list. The NIST CSF 2.0 small-business guide supports choosing outcomes that fit your context. CISA's SMB resources emphasize phishing awareness, MFA, updates, logs and backups. Use those as a baseline, then see what is already licensed and working.
A practical stack for 5–100 staff
| Outcome | Check what you own | Add a product when |
|---|---|---|
| Identity and credential sharing | Named accounts, SSO/MFA and browser or existing vault controls | Team vaults, recovery or lifecycle review cannot be managed reliably |
| Endpoint protection and patching | Included OS security, device management and update policy | Coverage, detection or patch workflow remains unowned or incomplete |
| Email and payment protection | Provider filtering, MFA, sender authentication and callback rules | A documented gap remains after configuration and finance workflow changes |
| Backup and recovery | Existing backup scope and a real restore test | Critical workloads lack independent recoverable copies or usable support |
| Remote/network access | Existing identity/device controls and firewall rules | Private-app, gateway or managed remote-desktop needs are defined |
| Incident response | Named incident lead, contacts and restore order | An external provider is needed to run a capability you cannot staff |
A subscription can span several rows, but its presence does not prove configuration or coverage. Microsoft 365 Business Premium, for example, includes Defender for Business and Defender for Office 365 Plan 1; check the exact tenant and enabled policies before adding a second endpoint or email product. See the Defender for Business review and Defender for Office 365 review.
Product examples by use case
These are examples, not a numeric leaderboard. Each link describes a selected plan, limitations and source date. Some vendors may have affiliate relationships; the individual buying link should disclose them. No product earns a higher suitability score for being featured or commission-eligible.
- Team passwords: 1Password Business, Bitwarden Teams, Proton Pass Essentials and NordPass Business. Check whether your existing SSO and browser manager already address the actual sharing need.
- Endpoint security: Defender for Business, ThreatDown, Bitdefender and CrowdStrike Falcon Go. Compare device counts, included licenses and who will respond to alerts.
- Recovery: Backblaze, Acronis and Synology Active Backup address different workloads. A file-sync service is not automatically an independent backup.
- Managed access: NordLayer is a managed VPN example; LogMeIn Pro is remote desktop priced by host computer. Buy the architecture your app requires, not a generic “remote-work” label.
The free/no-incremental-cost tools guide provides a starting sequence when budget is constrained. The security budget calculator accepts actual quotes without invented industry multipliers.
A purchasing gate that reduces shelfware
For every proposed product, fill in one row:
| Field | Example question |
|---|---|
| Supporting gap | Which assessment answer or incident shows the problem? |
| Existing entitlement | What do we already pay for, and has it been configured and tested? |
| Selected plan | Which exact edition, seats/devices, term and prerequisites apply? |
| Owner and effort | Who administers it and responds to alerts after launch? |
| Limitation | What important requirement does it not cover? |
| Cost | What is the incremental first-year and renewal total, including support? |
| Verification | What test would show the purchase was worthwhile? |
A “free trial” is only useful if it tests a real workflow. Pilot one staff onboarding, one leaver, one false positive, one alert and one recovery task where applicable. If nobody can own those tests, defer the purchase and fix the process first.
A 30/60/90-day operating rhythm
First 30 days: Inventory current licenses and critical accounts, enforce MFA, name backup and incident owners. By 60 days: Configure included endpoint/email controls, test a restore and close the highest-risk access gaps. By 90 days: Pilot only the products needed for remaining gaps and review alerts, costs and ownership. The free assessment gives three prioritized actions with a local report; its suggestions are planning inputs, not purchase orders.
Start with the controls you own
Run the assessment, then use the NIST implementation guide to assign an owner and proof of completion. Visit a product profile only after a named action genuinely requires a new tool.
Sources checked September 24, 2026: NIST SP 1300 and CISA SMB resources. Product claims are documented in the linked profiles. This guide does not claim comparative hands-on testing, verified affiliate commissions or quantified risk reduction.