# Small Business Tech > Independent, plain-language digital-safety and recovery guidance for small-business owners and operators without a full IT department. Canonical: https://smallbusinesstech.org/ Owner and publisher: Bridgepath AI Solutions Editorial review: July 24, 2026 Boundary: This publication does not scan systems, connect to accounts, receive incidents or business records, rank products, certify controls, or replace qualified review. Note: This is a transparent content index, not a security assessment, crawler-access claim, product endorsement, or guarantee. ## Start and topic - [Start here](https://smallbusinesstech.org/start-here) - [Build a small-business digital-safety routine](https://smallbusinesstech.org/topics/small-business-digital-safety) - [Free practice resources](https://smallbusinesstech.org/resources) ## Digital-safety knowledge - [Critical account ownership](https://smallbusinesstech.org/knowledge/critical-account-ownership): Critical account ownership means the business can name the accountable owner, control its administrators, use business-controlled sign-in and recovery routes, remove obsolete access, and recover the account without depending on one employee, vendor, or personal address. - [Strong authentication routine](https://smallbusinesstech.org/knowledge/strong-authentication-routine): A practical strong-authentication routine combines a unique credential, the strongest suitable multifactor method available, protected recovery routes, separate administrative access, and a repeatable process for enrollment, loss, replacement, and removal. - [Trusted second channel](https://smallbusinesstech.org/knowledge/trusted-second-channel): A trusted second channel is a separately established way to confirm a sensitive request with the right person, using a known phone number, approved account, or documented process instead of the message, link, caller, or contact details that delivered the request. - [Maintained device baseline](https://smallbusinesstech.org/knowledge/maintained-device-baseline): A maintained device baseline is a current record of business devices, supported software, accountable owners, update expectations, protective settings, important data, and safe replacement or retirement steps. - [Recovery evidence](https://smallbusinesstech.org/knowledge/recovery-evidence): Recovery evidence is a dated record that an approved person restored a named business record or configuration from a protected backup into a safe location, checked the result, measured the time, recorded gaps, and assigned the next correction. - [First-hour incident plan](https://smallbusinesstech.org/knowledge/first-hour-incident-plan): A first-hour incident plan names who leads, who must be contacted, which safe actions are preapproved, how evidence and continuity are protected, what must not be changed, and when to involve technology, legal, insurance, financial, privacy, communications, or public authorities. ## Safety guides - [Name an owner for every critical business account](https://smallbusinesstech.org/guides/name-an-owner-for-every-critical-account): Create a plain inventory for email, domain, banking, payroll, cloud, website, social, and vendor accounts before an emergency exposes an ownership gap. - [Make everyday sign-in safer without making work impossible](https://smallbusinesstech.org/guides/make-everyday-sign-in-safer): Use individual accounts, a business password manager, and multi-factor authentication to reduce the damage from reused or stolen passwords. - [Keep devices and software current with a visible routine](https://smallbusinesstech.org/guides/keep-devices-and-software-current): Turn updates, supported versions, screen locks, encryption, and device retirement into a small operating routine instead of an occasional scramble. - [Verify payment and account-change requests on a second channel](https://smallbusinesstech.org/guides/verify-payment-and-account-change-requests): Use a short verification script for new bank details, urgent payments, password resets, gift cards, payroll changes, and unusual vendor requests. - [Make backups you can actually restore](https://smallbusinesstech.org/guides/make-backups-you-can-actually-restore): Identify the records that keep the business operating, protect copies from the same failure, and test a small restore before calling the backup complete. - [Remove access when people and vendors change](https://smallbusinesstech.org/guides/remove-access-when-people-and-vendors-change): Use one joiner, role-change, departure, and vendor-exit routine so accounts, keys, devices, forwarding rules, and shared access do not survive by accident. - [Write a first-hour incident plan before the first hour](https://smallbusinesstech.org/guides/write-a-first-hour-incident-plan): Prepare a short contact and decision card for lost devices, compromised email, suspicious payments, malware, outages, exposed records, and ransomware. ## Practice kits - [Critical account ownership card](https://smallbusinesstech.org/practice-kits/critical-account-ownership-card): A protected reference for the accounts that control identity, money, customers, records, and recovery. - [Access change checklist](https://smallbusinesstech.org/practice-kits/access-change-checklist): A repeatable joiner, role-change, departure, and vendor-exit record. - [Device care calendar](https://smallbusinesstech.org/practice-kits/device-care-calendar): A small recurring record for updates, support dates, protection checks, and retirement. - [Payment-change verification script](https://smallbusinesstech.org/practice-kits/payment-change-verification-script): A short second-channel script for money, payroll, password, and sensitive account changes. - [Backup restore drill record](https://smallbusinesstech.org/practice-kits/backup-restore-drill-record): A dated record that proves a safe sample could be restored and identifies remaining recovery work. - [First-hour incident card](https://smallbusinesstech.org/practice-kits/first-hour-incident-card): An offline contact and decision card for the first hour of a suspected technology incident. ## Primary sources - [National Institute of Standards and Technology: Small Business Cybersecurity Corner](https://www.nist.gov/itl/smallbusinesscyber): Practical cybersecurity resources and planning material designed for small and medium-sized businesses. - [Cybersecurity and Infrastructure Security Agency: Small and Medium Businesses](https://www.cisa.gov/audiences/small-and-medium-businesses): Current CISA audience hub for small-business security, resilience, services, and official guidance. - [Cybersecurity and Infrastructure Security Agency: Cybersecurity Resources for Small and Medium Business Leaders](https://www.cisa.gov/small-and-medium-sized-business-resources): Plain-language business resources for phishing, passwords, multifactor authentication, software updates, backups, and incident preparation. - [Federal Trade Commission: Cybersecurity for Small Business](https://www.ftc.gov/business-guidance/small-businesses/cybersecurity): Business guidance for common threats, employee practices, vendors, data, devices, email, and incident response. - [U.S. Small Business Administration: Strengthen Your Cybersecurity](https://www.sba.gov/business-guide/manage-your-business/strengthen-your-cybersecurity): Small-business planning guidance for risk assessment, employee training, access controls, updates, backups, and response. - [Cybersecurity and Infrastructure Security Agency: StopRansomware Guide](https://www.cisa.gov/stopransomware/ransomware-guide): Current prevention, response, reporting, and recovery guidance for ransomware and related incidents.