Cybersecurity for New Business Owners (First 90 Days)

This post contains affiliate links. If you purchase through our links we may earn a small commission at no extra cost to you.

The first 90 days of a new business are when cybersecurity habits get set — or when they don’t. Most small business owners don’t think about security until something breaks: the fraudulent wire transfer, the ransomware note, the phishing email that fooled the bookkeeper. By then the damage is done and remediation costs 10-100x what prevention would have cost. This guide is the cybersecurity setup roadmap for the first 90 days of business, ordered by priority: what to do first (weeks 1-4), what to build next (weeks 5-8), what to formalize (weeks 9-12). It’s designed for a founder who’s not a security expert but wants to avoid the mistakes that put competitors out of business.

Days 1-30 — the foundation (do these first)

Business email account (correctly)

  • Use a business email service, not personal Gmail/Yahoo tied to the business
  • Microsoft 365 Business or Google Workspace ($6-$22/user/month) — proper business-grade with mailbox recovery, retention, admin controls
  • Enable MFA (multi-factor authentication) immediately for every account
  • Use unique passwords per account, stored in a password manager

Password manager for every human

  • 1Password, Bitwarden, Keeper, or Dashlane — $3-$8/user/month for business tier
  • Every person accesses passwords through the manager, not memory or spreadsheet
  • Enable emergency access / recovery contact
  • See our best password managers guide

MFA on every critical account

  • Email (business + personal recovery)
  • Bank and financial accounts
  • Domain registrar
  • Any cloud service holding customer or company data
  • Use authenticator app or hardware key — SMS 2FA only when nothing else available

Automatic backup for critical data

  • Cloud services: enable version history
  • Add third-party backup for M365 or Google Workspace (Datto SaaS, Backupify)
  • Test restore within week 1 — untested backup isn’t backup
  • See our 3-2-1 backup strategy guide

Business bank account with fraud protection

  • Separate business banking from personal (also required legally for LLC/corp)
  • Enable transaction alerts on all business cards
  • Verify wire transfer procedures — establish call-back verification for anything over $5K
  • Understand ACH fraud liability (business accounts don’t have the consumer protections you’re used to)

Days 31-60 — building out

Endpoint protection on every device

  • Not just antivirus — modern EDR (Endpoint Detection and Response) blocks more, alerts on suspicious behavior
  • SentinelOne, CrowdStrike, or Microsoft Defender for Business — $3-$8/endpoint/month
  • Covers laptops, desktops, and (increasingly) mobile devices
  • See our EDR vs antivirus guide

Business VPN for remote work

  • Any employee working from home or public wifi needs VPN
  • Business VPN services ($5-$15/user/month) or self-hosted (WireGuard, OpenVPN)
  • See our best business VPN guide

Email authentication (SPF, DKIM, DMARC)

  • Prevents email spoofing (someone pretending to be you)
  • Free to set up; requires DNS record configuration
  • Critical for BEC (Business Email Compromise) prevention
  • See our SPF DKIM DMARC guide

Basic firewall and network security

  • Business router with proper firewall (not ISP-provided consumer router)
  • Separate guest wifi from business network
  • Change default admin passwords
  • See our best firewall for small business guide

Employee security training

Days 61-90 — formalizing

Write down your policies

  • Acceptable Use Policy (what employees can/can’t do)
  • Password policy
  • Data handling policy
  • Incident response basic playbook
  • BYOD policy if applicable
  • Even a simple 1-page policy is better than none
  • See our how to create a cybersecurity policy

Incident response plan

  • Who to call (attorney, insurance, IT, forensics) when incident occurs
  • Basic decision tree (contain, investigate, report, recover)
  • Practice with tabletop exercise annually
  • See our incident response plan guide

Cybersecurity insurance

  • Small business cyber policy: $1,000-$3,000/year typical premium
  • Covers ransomware payment (in some states), forensic investigation, notification costs, legal fees
  • Insurer will ask for MFA, backups, security awareness training — meet those requirements first
  • See our small business cyber insurance guide

Cybersecurity budget

  • Rule of thumb: 5-10% of total IT budget for cybersecurity-specific line items
  • Growing rapidly (up from 2-3% historical)
  • See our cybersecurity budget planning

Vendor security review

  • Every SaaS vendor gets access to your data
  • Basic due diligence: SOC 2 report, encryption, backup, incident notification commitments
  • See our vendor security assessment guide

The 90-day priority matrix

Highest priority (do first)

  • MFA everywhere
  • Password manager
  • Business email + backup
  • Bank account with fraud protection
  • EDR on all endpoints

High priority (weeks 2-6)

  • Business VPN for remote workers
  • Email authentication
  • Employee security training
  • Basic firewall

Medium priority (weeks 6-12)

  • Written policies
  • Incident response plan
  • Cyber insurance
  • Vendor security review

Deferrable (after month 3)

  • Advanced tools (SIEM, DLP, penetration testing)
  • Compliance certifications (SOC 2, HIPAA formal audit)
  • Advanced training programs

What NOT to do in month 1

Don’t buy every tool immediately

Security stack sprawl creates more problems than it solves. Start with the essentials; add tools as scale requires. Simple + used > complex + ignored.

Don’t rely on “we’re too small to be targeted”

Small businesses are targeted MORE, not less, because attackers know defenses are weaker. Ransomware groups explicitly target small business as low-effort, high-yield attacks.

Don’t skip cyber insurance because “it seems expensive”

$1,500/year insurance vs $50,000+ average small business ransomware cost is not a close comparison. The insurance also often provides better response resources than you can access on your own.

Don’t outsource everything to your IT provider without oversight

Even with MSP or MSSP, you own the security responsibility. Verify what’s being done; audit periodically.

Common founder-era security mistakes

  • Personal accounts as business accounts. Gmail personal address as company email = major recovery risk if you lose access.
  • Shared passwords via Slack/email. Use password manager sharing features; never sensitive credentials over messaging.
  • No MFA because “it’s inconvenient.” Convenience cost: 10 seconds per login. Breach cost: potentially the business.
  • Trusting default settings. Router, laptop, SaaS all ship with defaults that trade security for convenience. Configure explicitly.
  • Untested backups. Restore test in month 1 or backup is useless when needed.
  • Ignoring wire fraud training. BEC is the single most costly small business cybercrime. Everyone with wire authority needs training.
  • Waiting for “later” to establish policies. By month 3 you have baggage; establish practices in month 1 when everything is fresh.

90-day cybersecurity budget (~$4,000-$8,000 initial + $200-$500/month recurring)

  • Password manager (5 users): $150-$300/year
  • M365 Business Standard (5 users): $750/year
  • EDR (5 endpoints): $180-$480/year
  • Cyber insurance: $1,000-$2,500/year
  • Backup add-on: $180-$600/year
  • Security awareness training (5 users): $120-$240/year
  • Business VPN (5 users): $300-$900/year
  • Total: $2,680-$5,770/year for the basics + optional consultant/attorney fees

Recommended tools

Related SBSG topics

Related foundational pieces: how to create a cybersecurity policy, cybersecurity checklist, small business cybersecurity on a budget. Technical foundation: what is MFA, best antivirus, business VPN setup. Framework: NIST framework explained, CIS Controls starting point. Response: incident response plan.

Key takeaways

  • First 30 days: MFA everywhere, password manager, business email + backup, bank fraud protection, EDR on endpoints.
  • Days 31-60: business VPN, email authentication (SPF/DKIM/DMARC), employee training, firewall, network security.
  • Days 61-90: written policies, incident response plan, cyber insurance, vendor security review.
  • Realistic budget: $2,700-$5,800/year for basics; ROI vs single incident is 10-100x.
  • Don’t skip cyber insurance or wire-fraud training — highest-cost small business cybercrime scenarios.

FAQ

Is 90 days too aggressive for a new business owner already handling everything? The 90-day timeline is aspirational but achievable if you set aside 4-6 hours per week. The alternative — no security foundation — leaves the business vulnerable during the exact period it’s most fragile. Even 60-70% of this list completed is dramatically better than 0%.

What’s the single most important cybersecurity investment for a new business? If you can only do ONE thing: enable MFA on every account (email, bank, cloud, admin panels). That single control blocks 99%+ of automated attacks. Password manager comes second; EDR/antivirus third. Beyond these three, everything else is optimization.

Should I hire a cybersecurity consultant to help with setup? For businesses expecting rapid growth or handling sensitive data (healthcare, finance, legal), yes — a fractional CISO or MSSP can accelerate setup and reduce mistakes. For general small business, the checklist above is achievable DIY with good documentation and disciplined follow-through.

Recommended companion
Cyber Policy Premium Bundle
The 90-day roadmap gets you set up. The Cyber Policy Premium bundle gives you the written policies (AUP, password, incident response, BYOD, remote work) that formalize what you built — the paperwork clients, insurers, and auditors will ask for once you’re past the first 90 days.

Get the Cyber Policy Premium Bundle →