5 security basics every 20-person company needs (and what most skip)

Your company isn't insecure because you're careless — it's because nobody owns IT. Here's the five basics attackers count on you skipping.

Small business owner and team discussing cybersecurity in a bright office

Your 20-person company isn’t insecure because you’re careless. It’s because nobody owns IT. The office manager doubles as the IT person. Passwords live on sticky notes. The “backup plan” is a hope and an external hard drive someone plugs in when they remember.

Attackers know this. They’re not targeting you because you’re important — they’re targeting you because you’re easy. And they’re right: most 20-person companies are missing the same five basics. Not exotic technology. Basics.

Here’s the list, in order of impact.

1. Multi-factor authentication on everything that matters

One stolen password should never be enough to get into your business. With MFA turned on — that second step on your phone — a password stolen in a phishing email is useless on its own.

At minimum: your email, your banking, and whatever software runs your business. It takes about ten minutes per person to set up, and it stops the single most common way small companies get broken into.

If you take nothing else from this post: turn on MFA today. It’s free, and it closes the biggest hole you have.

2. Backups the attackers can’t reach — that someone has actually tested

Most companies that think they have backups discover two problems when they need them. First, the backup was sitting on the same network as everything else, so the ransomware encrypted it too. Second, nobody ever tried restoring from it, so nobody knew it had been failing for months.

Real backups are three things: separate from your network (attackers can’t touch what they can’t reach), automatic (not dependent on someone remembering to plug in a drive), and tested (someone has restored a file from them this year — this quarter, ideally).

Ask your office one question: “If our server died tonight, how would we get back?” If the answer is a shrug, you don’t have backups. You have optimism.

3. Fifteen minutes of phishing training

Almost every attack on a small company starts the same way: someone clicks something. A fake invoice, a shipping notification, a “verify your account” email that looks exactly like the real thing. Busy people click. That’s not a character flaw — it’s Tuesday.

The fix isn’t a two-day seminar. It’s one short session: here’s what phishing emails look like, here’s the two-second check before you click (hover the link, check the sender’s actual address), and here’s what to do instead of clicking when you’re unsure.

Then a reminder once a quarter. Most phishing attempts die right there, because the person who would have clicked knows what to look for now.

4. Every computer patched and protected

Those update notifications your team keeps dismissing? Attackers count on that. Most break-ins exploit vulnerabilities that were already fixed — by an update that never got installed.

Every work computer needs two things: updates actually installed (not postponed indefinitely), and real endpoint protection running — not the free trial that expired in 2023 and now just shows a warning everyone ignores.

This is the one most companies get wrong silently. Nobody checks. The computers “work fine,” which is exactly what a compromised computer looks like right up until it doesn’t.

5. Passwords nobody can guess — and access that ends on the last day

Two problems, one fix. First: if your team reuses passwords across sites — and they do — one breach anywhere becomes a breach of your business. A password manager for the team solves this: unique passwords everywhere, nobody has to remember any of them.

Second: when someone leaves, their access has to die the same day. Every account, every shared login, every door code they knew. Former employees with live access are one of the most overlooked risks in small companies, and the fix costs nothing but discipline.

If more than one person knows the “office password” for something, you don’t have a password. You have a rumor.

The bottom line

Five basics. No six-figure security budget, no IT department required. Most of it can be done in an afternoon per item — the hard part is that someone has to own it, check it, and keep it done month after month.

That’s the part most 20-person companies can’t staff. It’s also exactly what a managed IT plan covers — monitoring, security, tested backups, and support — for $150 to $300 per seat per month.

If you don’t know where your company stands on these five, that’s what the free network assessment is for. We’ll check each one and tell you straight what’s solid and what’s risky. If you’re in good shape, we’ll tell you that too.

Start with a free network assessment

Call (361) 704-1373 or request yours online.

Request your assessment →

Not ready to book? Start with the checklist.

Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.

Your download link appears right after you submit. Prefer to talk? Call (361) 704-1373, Mon–Fri 8am–5pm CT.

Frequently asked questions

What are the cybersecurity basics for a 20-person company?

Five things: multi-factor authentication on email, banking, and business apps; backups that are separate from your network and actually tested; a short phishing training session; every computer patched with real endpoint protection; and unique passwords with access revoked the day someone leaves.

How much should a 20-person company spend on cybersecurity?

Done as part of a managed IT plan, security is bundled into $150–$300 per seat per month — roughly $3,000 to $6,000 a month for 20 people, covering monitoring, security, tested backups, and support.

What is multi-factor authentication and why does it matter?

MFA adds a second step — usually a code on your phone — after your password. It means a stolen password alone can't get an attacker into your email or banking. It's free and stops the most common way small companies get broken into.

How often should a small business back up its computers?

Backups should run automatically — daily at minimum — and be stored separately from your network so ransomware can't reach them. Just as important: someone should test-restoring a file from them at least quarterly.

How do I know if my company's computers are secure?

If you can't answer five questions — is MFA on, are backups separate and tested, has the team had phishing training, are updates installed, and is access revoked when people leave — you don't know. That's what our free network assessment checks.

We don't have an IT person — where do we start?

Start with MFA (free, today) and the 10-Point Small Business IT Security Checklist below. Then get a free network assessment — we'll tell you in plain English where you stand and what to fix first.