Skip to Content

Buy small business cyber security in this order

The password rotation rule to delete, the Wi-Fi to fix once, and the line item worth cutting
April 27, 2023 by
Syncritech INC, Bill Roberts

Most small-business security advice is a list of virtues. Use strong passwords. Train your staff. Back up your data. All true, and all useless, because none of it says what to buy on Monday with a real budget and nobody on staff whose job title contains the word security.

So here is the buying order for a 20-person company. If the money runs out after item two, you are still ahead of most competitors.

Buy in this order, not the order the vendor pitches

  1. Microsoft 365 Business Premium, about $22 per user per month on an annual commitment. If you are on Business Standard, this is the highest-return line on your invoice. It bundles Defender for Business (real EDR, not signature antivirus), Intune (device enrollment, patch deadlines, remote wipe, BitLocker), and the Entra ID P1 that gives you Conditional Access. Then actually turn Conditional Access on, so company data is reachable only from an enrolled, compliant device. That one policy does more than the rest of this list combined. On Google Workspace, buy the equivalent controls there instead; changing suites to fix security costs more than the security.
  2. A password manager for everyone, including the owner. Bitwarden or 1Password, single digit dollars per user per month. The fix for bad passwords was never a complexity rule. It was making unique per-site credentials possible for an actual human. Add a shared vault for whatever your team keeps in logins_final_v2.xlsx.
  3. Phishing-resistant MFA on the accounts that would ruin your quarter. Email, banking, payroll, your domain registrar, every global admin (there should be two of those, not nine). Passkeys where the platform supports them, hardware keys where it does not. Yubico's Security Key series is about $30, the YubiKey 5 line about $50, so keys plus spares is a rounding error against one wire fraud incident. SMS is a fallback, never the control.
  4. Automatic patching, enforced by policy, not hope. Intune if you bought Business Premium, NinjaOne or Automox for a mixed fleet or servers. The settings that matter are the install deadline and forced reboot, not the scan schedule. Every patch tool reports lovely numbers for machines still waiting for someone to stop clicking Restart Later.
  5. Backups you have actually restored from. Immutable or object-locked storage, offsite, and one timed restore test a quarter where somebody records how long it took. A backup nobody has restored is a hypothesis.

Delete your password rotation policy today

NIST SP 800-63B dropped forced periodic rotation in its 2017 revision, along with mandatory character-class rules. Change on evidence of compromise, otherwise leave people alone. Most SMB handbooks still say 90 days, because someone copied a template in 2011 and nobody reread it.

What rotation buys you: Summer2026! becomes Autumn2026! and the helpdesk queue fills up every quarter. What it costs you: reuse across sites, sticky notes, and staff who conclude that security is theater. Set your own floor at 12 to 15 characters, allow passphrases, allow paste (blocking paste breaks password managers, which is backwards), and screen new passwords against known-bad lists. Entra ID Password Protection does a version of that natively. Everyone else can use the Pwned Passwords API.

Wi-Fi: do it once, correctly, then stop thinking about it

WPA3, or WPA2/WPA3 transition mode while the old label printer catches up. Then a separate SSID and VLAN for everything that is not a managed laptop: personal phones, guests, the conference room TV, the imaging cart running a Windows version nobody says out loud. Client isolation on guest. That is most of the value; segmenting further rarely pays for itself at 20 people.

The line item worth cutting

Security awareness training. The evidence that phishing simulations durably change behavior is weaker than the vendors imply, and the programs reporting success are mostly measuring click rates on their own simulated mail, which is a fact about the simulation, not about attackers. Teach people to report something odd without feeling stupid, make it one click in Outlook, and move the money to item three. Credentials that cannot be replayed turn most phishing into a nuisance. Not all of it: stolen session tokens still work after sign-in, which is why item one is item one.

Syncritech runs this stack for SMBs in healthcare and medical device manufacturing, where the same settings end up as evidence in a HIPAA risk analysis or an ISO 13485 audit. Most of those jobs start with an hour reading the license the client already pays for and finding two things nobody switched on.

Share this post
Should a small practice pay for a HIPAA risk analysis?
The free federal SRA Tool takes two afternoons, and fixing what it finds is the hard part