Skip to content
Saturday, August 29, 2026
ORERSMALL BUSINESS · MARKETS
S&P 500−0.35%FTSE 100−0.17%Euro/Dollar+0.22%Brent Crude+1.25%10-Year US+1.40%
ORERSMALL BUSINESS · MARKETS
Home / Business News
Business News

The FTC's Small-Business Cybersecurity Baseline, Decoded

Federal consumer-protection law already covers your data practices — the FTC's free guidance is effectively the inspection checklist before the inspection.

ID
Isabel Duarte, · May 6, 2026 · 3 min read
ShareXFacebookLinkedInTelegramEmail
Defense-layers checklist diagram for business data

The Federal Trade Commission does not run a small-business cybersecurity certification, but for any company handling consumer data it does something with similar effect: it enforces Section 5 of the FTC Act against unfair or deceptive data practices, and its case history defines what "reasonable" security means at each size of business. The FTC's own small-business guidance — its free cybersecurity publications for small business — is effectively that case history translated into a checklist. Orer News publishes information, not legal advice.

The framing that matters: security failures are prosecuted not as breaches but as broken promises — representations about protection that practices did not match.

What does the FTC's guidance actually cover?

Its small-business materials converge on a dozen practices: multi-factor authentication on email and financial accounts; unique strong passwords stored in a manager rather than a browser or spreadsheet; timely patching of operating systems, software, and firmware; disk encryption on laptops and phones; file backups kept offline or off-site; network firewalls; access control — employees get only what their role needs; and vendor management, since your data in a vendor's system is still your enforcement exposure. None of it requires an IT department; most of it is configuration, not procurement.

Why does enforcement reach small companies?

Because the deception theory is broad. A privacy policy promising safeguards is a representation; a breach enabled by absent multi-factor authentication, unpatched software, or shared logins makes it a misrepresentation — and the FTC has taken action against companies of modest size whose claims outran their practices. The order that typically follows requires decades of assessed audits, which is a heavier ongoing burden than the original fix. The economical read: the cheapest security program is one aligned to what you already claim, written down, and actually practiced.

What about phishing and payments?

The FTC's guidance treats phishing as the primary vector for small firms, and the defense is procedural: verify payment-change requests and wire instructions through a known channel before acting, train staff to treat urgency as a red flag, and script the out-of-band confirmation so employees have a rule to follow rather than judgment under pressure. Business email compromise — an impersonated executive or supplier redirecting a payment — is the loss event most likely to end a small firm, and it is defeated by a callback protocol that costs nothing.

What should a plan look like at small scale?

One page, three sections. Prevention: the checklist above, assigned to a named person with dates. Detection: who notices, and how — including monitoring of financial accounts for anomalies. Response: which systems get isolated, who calls which attorney or insurer, which customers must be notified and on what legal clock — state breach-notification laws set deadlines that begin at discovery, not at convenience. Then test the response piece annually with a one-hour tabletop: the first run of a plan should never be during the incident.

The FTC checklist is free, current, and written for businesses without security staff. Following it is the cheapest available alignment between what your privacy policy says and what your router settings do.

Frequently Asked Questions

Does the FTC regulate small business cybersecurity?
Indirectly but forcefully: it enforces the FTC Act against unfair or deceptive data practices, so a privacy promise your practices do not match is an enforcement risk regardless of company size. Its free small-business guidance reflects what its cases require.
What are the FTC's baseline security recommendations?
Multi-factor authentication, strong unique passwords in a manager, timely patching, device encryption, offline backups, firewalls, role-based access, and vendor management — configuration-level measures, not enterprise procurement.
What is business email compromise?
An impersonation attack redirecting payments via a fake executive or supplier request. The defense is procedural: verify any payment-detail change through a known out-of-band channel before acting.