The SMB Software Security Checklist: 12 Things Your Vendors Should Do

You don't need enterprise security theater. But these basics prevent 90% of breaches.

By The StackMatch Research Team

60% of SMBs experience a data breach within 12 months

60%Breached within 1 year
$120KAvg breach cost
85%Preventable with basics

Directional figures for a small business running a typical $3K-$10K/mo software stack — the point isn't the exact percentage, it's that a handful of basics cover most of the risk.

The uncomfortable truth

Enterprise security checklists have 200+ items. You're not going to do 200+ items. But 85% of SMB breaches come from 5 basic failures: weak passwords, no MFA, unpatched software, no backups, and phishing. This checklist focuses on what actually matters.

An illustration of a software audit checklist.

Security is about consistent basics, checked on a schedule — not expensive tools.

Vendor requirements (ask before buying)

Your vendors must have these 6 things

  • SOC 2 Type II certification (or equivalent)
  • MFA required for all employees (not optional)
  • Encryption at rest AND in transit (TLS 1.3 minimum)
  • Automated backups with 30-day retention
  • Incident response plan with 24-hour notification
  • Annual penetration testing by third party
6
vendor requirements that matter

Internal requirements (do these now)

12 things your team must do

  • MFA on every account (email, banking, CRM, everything)
  • Password manager for all employees (1Password, Bitwarden)
  • Unique passwords (no reuse across accounts)
  • Laptop encryption (FileVault on Mac, BitLocker on Windows)
  • Automatic OS updates (no snoozing beyond 48 hours)
  • Phishing training quarterly (use KnowBe4 or similar)
  • Offboarding checklist (revoke access same day)
  • Vendor access reviews (quarterly, remove unused)
  • Backup verification (test restores monthly)
  • Incident response plan (who to call, what to do)
  • Cyber insurance (minimum $1M coverage)
  • Data classification (know what's sensitive)

The #1 breach vector: former employees with active accounts. Offboarding within 24 hours prevents 40% of breaches.

Red flags (run away if you see these)

Vendor says 'we're too small to be targeted' — wrong. Vendor can't name their last penetration test — walk away. Vendor stores passwords in plaintext — immediate disqualification. Vendor doesn't have MFA — they're next.

Breach prevention by control

The bottom line

Security isn't about checking every box. It's about the basics, consistently. MFA everywhere. Password manager for everyone. Backups you actually test. Vendors who take it seriously. Do these four things and you're ahead of 90% of SMBs.

Run the free StackMatch audit to see which security tools fit your business size and risk profile.

Run your own audit
More from the blog