Your IT provider should run 12 security controls for your Houston business on a schedule and be able to prove each one. The list covers MFA, patching, endpoint detection, payment fraud, tested backups, admin access, training, inventory, monitoring, a Texas breach plan, the provider’s own access, and a quarterly review. It’s written so you can hold any provider to it, including the team behind our cybersecurity services in Houston. “Handled” isn’t proof.
A Houston SMB cybersecurity checklist should hold your IT provider to 12 recurring controls, from MFA and fast patching to restore-tested backups and a Texas breach plan, and every control should leave a report you can read. If the report doesn’t exist, the control probably doesn’t either.
I oversee how Uprite delivers managed IT, so I think about security as a set of chores with due dates. Somebody patches the firewall. Somebody restores a file to prove it can be done. Somebody reads the alert that fires on a Saturday night. When those chores belong to an outside provider, the owner’s job changes. You stop doing the work. You check that it happened.
That’s harder than it sounds. A provider can say “security is handled” and mean it sincerely while a third of the list goes undone. Nobody’s lying. I’d still be wary of that sentence from any provider, us included.
This one’s about accountability. Not DIY. Each of the 12 items below says what done looks like, which report proves it, how often you should expect to see that report, and the answer that should worry you. If you’d rather work through the basics on your own first, start with our free cybersecurity checklist for SMBs. Still choosing a provider rather than auditing one? Read how to evaluate an MSP’s cybersecurity stack before you sign.
What is an SMB cybersecurity checklist, and who should own it?
An SMB cybersecurity checklist is a short list of security controls that a small or mid-sized business runs on a fixed schedule, with a named owner and a written record for each one. When you pay an IT provider, the provider should own most of the work. You should own the records.
Federal guidance agrees. NIST’s Small Business Quick-Start Guide for its Cybersecurity Framework 2.0 tells owners to use it as “a discussion prompt” with whoever manages their security. The FTC’s cybersecurity guidance for small businesses is blunter about vendors. “Don’t just take their word for it.”
NIST’s April 2025 incident response guide, SP 800-61 Revision 3, calls outsourced security “a shared responsibility model” and says the split belongs in the contract, including who has the authority to act on your behalf when something goes wrong. It flags one more thing. The provider’s own privileged access to your systems is a risk in its own right. Item 11 covers it.
Shared responsibility cuts both ways. Your provider can switch on MFA for every mailbox. Only you can refuse the partner who wants an exception.
Why does a Houston small business need its own version?
The threats aren’t generic here, and neither are the rules. We pulled every notice on the Texas Attorney General’s public data breach list in late September 2026, 640 notices covering roughly the previous 12 months, and sorted them by where each organization is based.
Organizations based in Greater Houston filed 76 of the 264 notices from Texas-based entities. That’s 28.8%. Dallas-Fort Worth filed more, 84, so Houston doesn’t lead the state on volume. It leads on small notices. 29 of the 76 Houston notices involved fewer than 1,000 Texans, more than any other Texas metro, against 21 for Dallas-Fort Worth and 5 for San Antonio. Small notices. Often small firms.
Other numbers stood out.
- 88% of the Houston notices included Social Security numbers, 10 points above the rate for all Texas-based notices.
- Where a start date was reported, the median gap between a breach starting and being discovered was 68 days, and 26 of those 62 notices took 90 days or longer.
- At least 13 notices came from energy, petrochemical, and industrial services firms, including a refinery maintenance contractor in Pasadena and an industrial electrical contractor in Channelview.
- CPA and tax firms filed 4 notices, and 3 law firms filed 4 more.
2 caveats. Only breaches involving 250 or more Texans have to be reported to the Attorney General, so every count here is a floor, and the dates in each notice are self-reported by the organization that filed it. Still, the 68-day median says something plain. In the typical case, about 2 months passed between the breach starting and anyone noticing. That’s mostly a monitoring problem. It’s item 9.
Then there’s the rest of Houston’s risk profile, which rarely shows up on a national checklist.
| Houston factor | What it adds to the checklist |
|---|---|
| Texas ranked second among states in the FBI’s 2025 Internet Crime Report, with 97,912 complaints and $1,825,636,181 in reported losses | Email authentication and payment verification move up the list (item 4) |
| Business email compromise cost 2,253 Texas victims $304,318,015 in 2025, about $135,000 each, according to the IC3 Texas state report | A written call-back rule for any change to bank details (item 4) |
| Hurricane Beryl cut power to 2.7 million Texas customers in July 2024, 2.2 million of them on CenterPoint, and about 1 million were still out 4 days later, per the Public Utility Commission of Texas | A backup copy outside the Gulf Coast and a restore you’ve actually timed (item 5) |
| Hurricane season runs June 1 to November 30, and the National Hurricane Center puts the peak at September 10 | A backup and failover check before the season and again before the peak |
| Refineries, chemical plants, and their contractors run plant systems on or near the office network | An inventory that separates plant devices from office devices (item 8) |
| Port and freight firms face cyber-enabled cargo theft, which the FBI estimated at nearly $725 million across the US and Canada in 2025 | Tight control over remote access tools, including the provider’s own (item 11) |
| Texas Medical Center practices and their vendors fall under a state health privacy law broader than HIPAA | Privacy training within 90 days of hire, with signed records kept 6 years (item 7) |
If you still need the case for spending on security at all, that’s in why Houston SMBs should prioritize cybersecurity. This post starts after that.
What are the 12 controls your IT provider should run?
Print this list. Or paste it into your next quarterly review agenda.
- MFA on every account that can reach money, email, or admin tools
- Patching on a written clock, known exploited vulnerabilities first
- Endpoint detection and response on every device, with someone watching
- Email authentication plus a call-back rule for payment changes
- Backups that have actually been restored, with a copy outside the storm path
- Few admin accounts, kept separate and reviewed
- Security training that gets measured
- An asset inventory that matches reality, end-of-life gear included
- Logging and alerts with a response clock
- A written incident plan built around the Texas breach clock
- The provider’s own access to you, locked down and in writing
- A quarterly review scored against a named framework
And here’s the version you’d hand to your provider. The last column matters most. It’s the answer that should make you ask a follow-up question.
| Control | Proof to ask for | How often | Red-flag answer |
|---|---|---|---|
| 1. MFA | Registration report for every account, plus a named list of exceptions | Monthly | “Everyone’s on it except a couple of people who hated it” |
| 2. Patching | Report by device showing known exploited flaws and days open, firewall and VPN included | Monthly | “Windows updates itself” |
| 3. EDR | Coverage gap list of devices with no agent or no recent check-in | Monthly | “Every machine has antivirus” |
| 4. Email and payments | Your DMARC policy and the written call-back procedure | Quarterly | “DMARC is set to none so nothing breaks” |
| 5. Backups | Restore test log with the date, what was restored, and how long it took | Quarterly | “We get a success email every night” |
| 6. Admin access | Named list of admin accounts and a dated access review | Quarterly | “You’re an admin so you never get locked out” |
| 7. Training | Completion by person, plus phishing test click and report rates | Quarterly | “There’s a video once a year” |
| 8. Inventory | Device list with operating system, last check-in, and end-of-support date | Quarterly | “We know what’s out there” |
| 9. Monitoring | 1 recent alert traced from detection to action, with timestamps | Monthly | “We’d get an alert” |
| 10. Incident plan | Dated plan with names and phone numbers, plus notes from the last exercise | Yearly | “We’d figure it out” |
| 11. Provider access | How their technicians log in, how that’s protected, and the breach notice clause | Yearly | “Our techs share 1 login” |
| 12. Quarterly review | Scored report with open items, owners, and due dates | Quarterly | “Your score looks good,” with nothing in writing |
What does each control look like when it’s done right?
1. MFA on every account that can reach money, email, or admin tools
This one comes first because it’s the cheapest control with the biggest payoff. A 2023 Microsoft Research study of Azure AD accounts found MFA cut the risk of compromise by 99.22%. Microsoft’s free security defaults turn it on and block the older sign-in methods that can’t do MFA at all.
Done right means more. It’s not a checkbox. CISA’s MFA guidance for small businesses ranks the methods, with physical security keys at the top, authenticator apps in the middle, and text or email codes at the bottom as “the weakest protection.” Admin accounts belong near the top of that ranking. In May 2026 the FBI also warned about Kali365, a phishing kit distributed through Telegram that steals Microsoft 365 sign-in tokens and quietly gets past MFA without ever touching the user’s password. The FBI’s fix is a Conditional Access policy that blocks device code sign-in. Ask if you have one.
Watch the exceptions list. A single unprotected mailbox is all a payment fraud needs, so every exception should carry a name, a reason, and an end date.

2. Patching on a written clock, known exploited vulnerabilities first
Exploited vulnerabilities are now the most common way into a network. The 2026 Verizon Data Breach Investigations Report puts them at 31% of breaches, ahead of stolen credentials at 13%. In its section on businesses with fewer than 1,000 employees, Verizon says 29% of victims were hit through unpatched edge devices, meaning firewalls, VPNs, and routers. Only 26% of the flaws on CISA’s known exploited list were fully fixed in 2025, and the median fix took 43 days.
43 days is slow. So what’s fast enough?
In June 2026 CISA revoked its old 2-week default for federal agencies and replaced it with Binding Operational Directive 26-04. Under it, an internet-facing known exploited flaw that gives an attacker total control gets 3 days plus forensic triage, and every other known exploited flaw on the list gets 14 days or less. Private firms aren’t bound. It’s still a fair yardstick, and CISA’s own implementation guidance says remediation timelines belong in the service agreement.
A good monthly patch report names the firewall and VPN, not just the laptops. Browsers, PDF readers, and accounting software show up too.
3. Endpoint detection and response on every device, with someone watching
Antivirus hunts known bad files. Endpoint detection and response, or EDR, watches behavior and can cut a machine off the network mid-attack. Different tools. Coverage matters as much as the tool, and Marsh McLennan’s 2025 analysis of insurance-tracked controls found each 25% jump in EDR deployment across workstations and laptops lined up with a further 10% drop in breach likelihood.
Software’s the easy part. Microsoft Defender for Business already comes inside Microsoft 365 Business Premium. The gap list is. Which devices have no agent? Which haven’t checked in for a week? A laptop that walked out with a former employee shouldn’t still count as protected.
Then ask who acts on an alert after hours. An EDR console nobody reads at night is a smoke detector with the batteries pulled. Our MSP SLA benchmarks for 2026 cover what a reasonable response clock looks like.
4. Email authentication plus a call-back rule for payment changes
Business email compromise empties bank accounts without any malware at all. The FBI’s 2025 Internet Crime Report counts $3,046,598,558 in reported losses to it nationally, second only to investment fraud among cyber-enabled schemes.
2 controls carry the load. Only 1 is technical.
First, email authentication. The FTC tells any business that sends email from its own domain to use SPF, DKIM, and DMARC. DMARC is the record that tells receiving mail servers what to do with a forged message from your domain, and it only protects you once it’s set to quarantine or reject. Anyone can look up your DMARC record in about 30 seconds. Your provider should know the answer without looking.
Second, a written rule. Any request to change bank details or wire instructions gets a call back to a phone number already on file, never the one in the email. For Houston contractors and energy service firms that pay large supplier invoices, that habit is the cheapest control on this list. Speed matters when it fails. The FBI’s Recovery Asset Team reported a 58% success rate freezing stolen funds in 2025, and its advice is to call your bank immediately. Our guide to how Houston SMBs spot and stop phishing covers the first hour step by step.
5. Backups that have actually been restored, with a copy outside the storm path
A backup job that reports success every night proves the job ran. That’s all. It doesn’t prove you can get the data back, how long that takes, or whether ransomware can reach the copies first.
CISA’s backup guidance for small businesses sets the bar. Follow the 3-2-1 rule, keep offline and encrypted copies, test both full and partial restores, and make sure you can roll your data back at least 7 days if you ever need to. The FBI’s 2025 report adds that backup data should be immutable, so it can’t be altered or deleted.
Houston adds geography. When Hurricane Beryl came ashore on July 8, 2024, it cut power to 2.7 million Texas customers, and the Public Utility Commission’s investigation report shows outages didn’t fall below 10,000 until July 19. AT&T’s wireline service took until July 18 to fully recover. A second copy in the same building, or in a server room across town on the same grid, isn’t off-site in any sense that counts during a storm.
Ask for the restore log. It should show the date, what was restored, where it came from, and how long it took. Quarterly is a sensible rhythm for most small businesses, and it’s what our Fully Managed plan includes. Our lower-cost remote plans test twice a year or once a year, so check which tier you’re on with any provider, us included. For the full storm-season version, see our hurricane IT prep checklist for Houston businesses.

6. Few admin accounts, kept separate and reviewed
Short section. Big consequences. Admin rights are what turn 1 stolen password into a company-wide incident, and in that same Verizon section on smaller businesses, 38% of victims were hit because their credentials had been compromised.
Done right looks like this. A handful of named admin accounts, each separate from that person’s everyday email login. No shared admin passwords. A quarterly access review that someone on your side signs. And offboarding that removes a departing employee’s access the day they leave, not at the end of the month.
The red flag is being told you should stay a global admin “so you never get locked out.” That’s convenience talking.
7. Security training that gets measured
People remain the common thread. Verizon found a human element in 62% of breaches in its 2026 breach report. Training works when it’s frequent and measured, and KnowBe4’s 2026 phishing benchmark, which is vendor data from simulated phishing, puts the untrained failure rate at 33.2% and the rate after a year of ongoing training at 4.2%.
Clicks aren’t the only number. Watch reports too. A team that forwards suspicious email to IT within minutes is doing its job.
For some Houston firms, training is also a legal record. Texas Health and Safety Code section 181.101 requires every covered entity, a definition far broader than HIPAA’s, to train employees on health privacy within 90 days of hire and to keep each signed completion statement for 6 years. If you handle patient information in any form, from a Texas Medical Center specialty practice to a medical billing vendor, your provider’s training records should match that clock. More on building the habit in security awareness training for Houston teams.
8. An asset inventory that matches reality, end-of-life gear included
You can’t patch, protect, or back up a device nobody knows exists. CISA’s software update guidance for small businesses tells owners to keep an up-to-date inventory of authorized devices and applications, and to replace anything that’s reached end of life and stopped getting fixes.
For a Houston industrial firm, this item has a second layer. Plant-floor controllers, badge readers, cameras, and building systems often share a network with office PCs. Your inventory should say which is which. The network should separate them.
Ask for the device list with operating system, last check-in, and end-of-support date. If 3 lists exist, say billing, EDR, and inventory, they should agree within a device or 2. When they don’t, somebody’s paying for or protecting the wrong things.
9. Logging and alerts with a response clock
Remember the 68-day median from the Texas breach list? Monitoring shrinks it. The goal is easy to state and hard to run. Something important happens, a person sees it, and a person acts, on a clock you agreed to in writing.
Ask your provider to walk you through 1 real alert from the last month, from the first log entry to the action taken, with timestamps. Ask about log retention. Ask who watches Sunday nights. If the honest answer is an automated email to a shared inbox, that’s alerting, not monitoring. Big difference. Some lower-cost plans, ours included, are built exactly that way, which is fine as long as everyone knows it. Our breakdown of what an after-hours coverage SLA should say has the contract language.
10. A written incident plan built around the Texas breach clock
This is the item where Texas law does the most work. Under Business and Commerce Code section 521.053, the notice clocks run from the date you determine a breach occurred, not the date it started.
| When | What Texas law requires | Who it applies to |
|---|---|---|
| Immediately after discovery | A company holding your data, such as an IT provider or software vendor, must tell you | Anyone maintaining sensitive personal information it doesn’t own |
| By day 30 | Notify the Texas Attorney General through its online form | Breaches involving 250 or more Texans |
| By day 60 | Notify each affected individual | Any breach of sensitive personal information, at any size |
| Without unreasonable delay | Notify the nationwide consumer reporting agencies | More than 10,000 people notified at once |
Missing the individual notice deadline can cost up to $100 per person per day, capped at $250,000 per breach, on top of civil penalties of $2,000 to $50,000 per violation under section 521.151. Your attorney, not your IT provider, makes the notification calls. The plan should already have that attorney’s cell number in it.
A good plan fits on a few pages. Names, cell numbers, the insurer’s claim contact, who can authorize taking systems offline, and where the backups live. It gets rehearsed at least once a year, and Marsh McLennan’s 2025 analysis found organizations that regularly run tabletop exercises and breach drills are 13% less likely to suffer a material cyber event. For what the first days of a real incident look like, read the first 72 hours of ransomware recovery in Texas.
11. The provider’s own access to you, locked down and in writing
None of the 23 ranking checklist pages we reviewed for this post treat this as a control. It matters anyway. Your IT provider holds the keys to every system it manages, and CISA’s #StopRansomware Guide says managed service providers “have been an infection vector for ransomware impacting numerous client organizations.” Verizon’s 2026 report found a third party involved in 48% of breaches.
So ask how the provider’s technicians get into your systems. Named accounts or shared logins? MFA on their remote tools? What happens to their access if you part ways? The contract should also say they’ll tell you about a breach on their side right away, which section 521.053 already requires of anyone holding sensitive personal information they don’t own. The FBI’s April 2026 warning on cyber-enabled cargo theft described criminals abusing remote management software to hijack freight, which should get the attention of every logistics firm working the Port of Houston.
Independent proof helps. Read the date. Ours is a SOC 2 Type 1 examination (2023), a point-in-time review completed in May 2023, and you should weigh any report of that age accordingly, ours included. For the contract wording itself, see Houston MSP contract terms.
12. A quarterly review scored against a named framework
The last item holds the other 11 together. Once a quarter, your provider should hand you a dated report that scores each control, lists what’s still open, names an owner for each open item, and sets a due date you can check against. Microsoft Secure Score makes a useful trend line inside that report. Just not the whole report.
The framework matters more in Texas than it used to. Senate Bill 2610, effective September 1, 2025, shields businesses with fewer than 250 employees from exemplary damages after a breach, but only if they can show they had a qualifying cybersecurity program at the time. A stack of dated quarterly reports is how you show it.
Pick 1 framework. Stay with it. For a company of 20 to 99 people, the law itself names CIS Controls Implementation Group 1, 56 safeguards that CIS describes as “essential cyber hygiene.” The Texas section below breaks down every tier.

How often should each check happen?
The calendar below is a sensible default for a Houston small business. It isn’t a legal standard. It’s a working rhythm, and the patch windows borrow from the federal benchmark in item 2.
- Every month, reports on MFA coverage, patch status, EDR coverage gaps, and alert handling
- Within 3 days, internet-facing flaws that are already being exploited and give an attacker total control, and within 14 days, every other known exploited flaw
- Every quarter, a restore test, an access review, training and phishing results, an inventory check, and the scored review
- Every May, before hurricane season opens June 1, a backup and failover check that assumes the office is dark for a week
- Every August, a second storm check ahead of the September 10 peak
- Every year, an incident plan update, a tabletop exercise, and a review of the provider’s own access and attestation
- The same day, removal of a departing employee’s access
Which of these does Texas law actually require?
Honestly? No Texas statute hands a small business a 12-item checklist. Section 521.052 requires “reasonable procedures” to protect sensitive personal information, with no small-business exemption, and leaves the details to you.
SB 2610 comes closest, and it’s often oversold. It isn’t immunity. It doesn’t stop breach lawsuits or Attorney General penalties. What it does is bar exemplary, or punitive, damages against a business that can show its program met the tier for its size.
| Company size | What SB 2610 expects | Share of Harris County business locations |
|---|---|---|
| Fewer than 20 employees | “Simplified requirements,” including password policies and employee cybersecurity training | 83.0% |
| 20 to 99 employees | “Moderate requirements,” including CIS Controls Implementation Group 1 | 13.7% |
| 100 to 249 employees | Conformity with a recognized framework such as the NIST Cybersecurity Framework, CIS Controls, ISO 27000, or SOC 2 | 2.2% |
| 250 or more employees | No safe harbor under SB 2610 | 1.0% |
The shares come from the Census Bureau’s 2023 County Business Patterns, which counts 111,215 business locations with employees in Harris County. They’re sized by the headcount at each location, not by whole companies, so treat them as a rough guide. The takeaway holds anyway. For 4 out of 5 Harris County business locations, the Texas tier starts with passwords and training, which are items 1 and 7 on this list. The bill also requires every program to conform to a recognized framework, so read each tier as a floor and get legal advice before relying on it.
2 more laws matter here. The Texas data privacy law exempts businesses that count as small under SBA size standards, with 1 exception. They still can’t sell sensitive data without consent. And the health privacy training rule in item 7 applies at any size. Our Texas SB 2610 safe harbor checklist goes deeper on the documentation.
What does it cost to have a provider cover all 12?
Less than most owners expect for the tools, and more than they expect for the work. Microsoft lists Microsoft 365 Business Premium with Copilot at $32.00 per user per month, and it includes Defender for Business and Intune, which together cover much of items 1, 3, and 8 at the license level. Licenses don’t run reports. People do.
We publish our rates. The Fully Managed plan starts at $138 per user per month and includes quarterly backup testing. The MSSP Security Focus plan starts at $40 per user per month and covers SOC monitoring, vulnerability scanning, and quarterly security reviews. Our entry remote plan at $91 runs the Microsoft Defender stack with alerting only, no response, and tests backups once a year. It doesn’t cover all 12. We’d rather say so here than in a quarterly review. Full details are on our published pricing page, and the budgeting side lives in what enterprise-grade cybersecurity costs a small business. The same plans priced at 10, 25, 50, and 100 seats, plus what a federal rule adds, are in our guide to what cybersecurity costs in Houston.
Where Uprite fits, and when you don’t need us
We’re a 42-person managed IT and cybersecurity team that’s worked with Texas businesses since 1999, with Houston offices on Westheimer Road and Space Center Boulevard. Support requests get a first response in 5.06 minutes on average, and every ticket is triaged within 10 minutes. That’s the part of the business I answer for.
You may not need us. If an in-house IT person already produces these 12 reports on schedule, use this list to review the work and leave it there. If you’re a very small company on a tight budget, the TSBCAC program offers Texas small businesses up to 40 hours of certified vCISO help at no cost, with the University of Houston’s small business development center as its Gulf Coast partner. It’s a good start.
If you’d rather hand the whole list to a provider, look at our managed security services in Houston, then ask us for the same reports you’d ask anyone else for.
Questions Houston owners ask about this checklist
Does Texas law require small businesses to follow a cybersecurity checklist?
Not a specific one. Texas requires every business to use reasonable procedures to protect sensitive personal information, and SB 2610 rewards businesses under 250 employees that can show a program matched to their size. For companies under 20 employees, that tier names password policies and staff training.
How often should my IT provider send me security reports?
Monthly for the operating numbers, quarterly for a scored review. Monthly means MFA coverage, patch status, EDR gaps, and alert handling. Quarterly adds restore tests, access reviews, training results, and progress against your framework. Anything less frequent lets a problem sit for a season.
What should a Houston business do first if it suspects a breach?
Call your IT provider, then your bank if any money moved. The FBI’s Recovery Asset Team reported a 58% success rate freezing stolen funds in 2025, and speed is why. After that, bring in your attorney and insurer, preserve evidence, and track the Texas 30-day and 60-day notice clocks, which run from the date you determine a breach occurred.
Will these controls affect my cyber insurance?
Almost certainly. Insurers now ask about MFA, EDR, backups, patching, and incident planning on the application itself, and the answers have to be true. In Travelers v. International Control Services, the insurer said its client had claimed MFA it wasn’t fully using, and in 2022 both sides agreed to void the policy from its inception.
Can a 10-person company realistically do all 12?
Yes, scaled down. A 10-person firm might have 2 admin accounts, 1 firewall, and a 3-page incident plan, and most of the tooling ships inside Microsoft 365 Business Premium. What doesn’t shrink is the need for someone to run the reports every month.
What if my IT provider won’t share these reports?
That refusal is your answer. The FTC’s advice on vendors is to put security requirements in the contract and verify them rather than take the vendor’s word. A provider doing the work usually has the reports already, because its own tools generate them.
Is text message MFA good enough?
It’s better than nothing, but it’s the weakest option. CISA ranks text and email codes last, behind security keys and authenticator apps with number matching. Admin accounts and anyone who approves payments should use something stronger, and Marsh McLennan linked phishing-resistant MFA to a 9% lower breach likelihood than MFA that isn’t.
Want to know which of the 12 your current setup can actually prove? We’ll walk the checklist with you, look at what your Microsoft 365 tenant, devices, and backups can show today, and put the gaps in writing. You keep the written findings either way.
Get an Assessment








