CERT-In’s elemental cyber defence controls give Indian MSMEs a useful starting point, but founders still need a practical sequence for what to do first.
The simple answer is to assign ownership, enable MFA, document assets, test backups, review payment-change workflows and then build monthly evidence that the controls actually work.
Why this matters now
Many small businesses have a website, email, WhatsApp Business, accounting software, cloud storage and payment collection tools, but no single person owns the security checklist.
A phased plan matters because buying tools before fixing account ownership, backups and access removal creates expense without resilience.
Indian teams also need to consider how quickly operational details change. Staff roles, vendors, bank accounts, devices, apps, branch locations and customer channels can change faster than the website or policy document. A checklist that is not reviewed becomes stale, so every recommendation below includes an owner and evidence item.
Action checklist
- Owner: Name one security owner and one backup owner.
- MFA: Turn on multi-factor authentication for email, domain, hosting and payment tools.
- Assets: List admin accounts, devices, software and vendors.
- Backups: Restore one sample file or database, not just confirm that backups exist.
- Payments: Verify bank-account changes through a second channel.
Implementation plan
First week
In the first week, do not try to solve every control. Protect email, domain, hosting, payment and cloud-storage accounts first, because compromise of these systems can disrupt the whole business.
During the first week, keep the scope narrow and visible. A founder or manager should be able to open one document and see the status of every important item. If the team cannot explain who owns the task, the task is not ready for automation.
First month
Within a month, create a monthly review calendar covering patches, inactive users, backup restore tests, vendor access and payment-verification exceptions.
The first month should convert one-time cleanup into a repeatable habit. Create a calendar reminder, define the evidence to be saved and agree who signs off. This prevents the checklist from becoming a document that was created once and forgotten.
Quarterly review
Every quarter, run one tabletop exercise: a hacked mailbox, a ransomware note, a lost laptop or an unauthorised website admin login.
A quarterly review should not only mark items as complete. It should ask whether the business model changed, whether a new vendor was added, whether a branch or remote team changed the process, and whether any customer complaint exposed a weak point.
Decision table
| Area | What to check | Owner | Evidence |
|---|---|---|---|
| MFA, forwarding rules and recovery email | Founder or IT partner | Settings screenshots | |
| Backups | Restore test and retention | Operations | Restore notes |
| Payments | Vendor bank-change approval | Finance | Approval log |
| Website | CMS, plugin and hosting updates | Developer | Update log |
Practical worksheet
Create a working sheet with five columns: owner, current status, evidence link, next action and review date. This makes the article usable by a founder, agency manager, finance lead or IT partner instead of leaving it as a reading exercise.
The worksheet should include only actions the team can prove. If an item is not complete, mark it as pending and add a date. A visible pending item is better than a control that everyone assumes exists but nobody can demonstrate.
For multi-location businesses, add one more column for branch or channel. A website form, a WhatsApp sales number, a marketplace listing and a physical counter can all need different handling even when the headline policy is the same.
What to measure
Track a small number of signals after the change. Useful signals include open exceptions, old accounts removed, evidence collected, failed checks, staff questions and customer complaints. Measurement should help the team improve the process, not create paperwork for its own sake.
For a young business, the most important metric is consistency. A weekly or monthly review that actually happens is more valuable than a complex dashboard that nobody opens.
Common mistakes
The most common mistake is treating cybersecurity as a one-time purchase. MSMEs often subscribe to a tool but continue using shared passwords and unmanaged freelancer access.
Another mistake is keeping no evidence. During an incident, screenshots, logs, invoices, admin lists and timeline notes are more useful than memory.
A third mistake is outsourcing responsibility without requiring evidence. Agencies, freelancers, payment partners and IT vendors may perform important work, but the business still needs a record of what was configured and when it was last checked.
How IndiaPress readers can use this
Use this plan as a working checklist in a spreadsheet. Add a due date, owner and proof link for every line item.
If you outsource IT, make the vendor share monthly evidence rather than only saying that updates were completed.
Teams can turn this article into a one-page internal SOP. Copy the checklist, remove anything irrelevant, add owner names and review it in the next weekly meeting. The goal is not perfection on day one; the goal is visible progress and fewer unknowns.
Practical note for Indian teams
For small teams, the best control is the one that someone can repeat. Keep the first version simple, then improve it with every monthly review.
Keep the first version simple enough for the smallest branch, store, agency desk or founder-led team to follow. Once the process works, add automation, dashboards and deeper controls. If the process fails on a busy day, simplify it before adding more software.
Teams should also keep ownership visible. A checklist without a named owner usually becomes a forgotten document. Add the owner’s role, backup owner and the date when the item was last reviewed.
Finally, keep customer communication plain. If a change affects payments, support, privacy, security or service availability, staff should know how to explain it without jargon. Clear explanations reduce disputes and make the business look more reliable.
Related IndiaPress reading
- Website security checklist every new business should follow
- AI-assisted invoice fraud checklist for Indian businesses


