Security · 4 min read
Five security questions every small business should be able to answer
August 16, 2026
Prefer listening? This is the full article as a narrated video.
Small businesses get attacked precisely because they're small: no IT staff, no training, and the comforting assumption that 'we're too small to target.' Attackers automate everything — nobody picks targets by hand anymore.
Question one: is your business running on the free router your internet provider shipped? If yes, your entire operation sits behind consumer-grade hardware with default settings.
Question two: what's on your laptops? Endpoint protection on every machine is table stakes — one infected laptop can encrypt the whole office.
Question three: would your team spot a fake invoice? Phishing is how most SMB breaches start, and the fix is training, not technology.
Question four: when did you last test a backup restore? Backups you've never restored from are a hope, not a plan. Ransomware loses its leverage the moment you can rebuild from a known-good copy.
Question five: what does your cyber insurance actually require? More policies now mandate specific controls — and deny claims when they're missing.
If any of these made you uncomfortable, that's normal — and fixable. A security review with a TSI advisor walks these exact questions and turns the answers into a prioritized, budget-sized plan.