Most of the organizations we talk to do not have an IT department. They have a founder who resets passwords, an office manager who knows where the router is, and a volunteer or family friend who shows up when something breaks.
That is not a failure. It is the normal condition for most small businesses, most nonprofits and a surprising number of small defense contractors. The problem is that nearly every security guide on the internet is written as if you have a team to hand the work to. So let us write one that assumes you do not.
What does cyber hygiene actually mean when it is not anyone's job?
Cyber hygiene is the small set of habits that stops the ordinary attacks, not the sophisticated ones. Think of it the way a restaurant thinks about handwashing and refrigeration temperatures: unglamorous, repeatable, and responsible for most of the outcome.
In practice it comes down to a short list. Know what accounts and devices you have. Turn on multifactor authentication. Keep software updated. Back up your data and test that the backup restores. Give people only the access they need. Have a written plan for the day something goes wrong.
That is it. Not because that is all security is, but because an organization with no IT department that does those six things consistently is in far better shape than one that buys a tool and never configures it.
Where do you start when everything feels urgent?
Start with an inventory, because you cannot protect what you have not written down.
Open a spreadsheet. One tab for accounts: every cloud service, email tenant, payroll system, donor database, file share and vendor portal your organization uses. One tab for devices: every laptop, phone, tablet and server that touches your data, including personal devices people use for work. One tab for people: who has access to what, and who has administrator rights.
This is tedious and it is also the single highest value hour you will spend. Almost every organization that does it finds at least one of the following: an account belonging to someone who left, an administrator login shared by four people, a service nobody remembers signing up for, or a backup that has silently stopped running.
When did you last look at the list of people who still have access to your email system? If the answer is that no such list exists, that is your first task, not a security tool.
Who owns security when there is no IT department?
Somebody has to. If the answer is everybody, the real answer is nobody.
The person who owns it does not need to be technical. They need to be the person who notices when a task did not happen. Their job is to keep the inventory current, confirm the backup ran, chase the software updates that did not install, and be the named human that staff contact when something looks wrong. Name them in writing. Give them a recurring block of time. Tell the rest of the organization who they are.
If you use an outside provider for computers or email, that does not transfer ownership to them. Read what they actually agreed to do. Many general technology providers keep the lights on and do not do security monitoring, patch verification or logging unless it is named in the agreement. Do you know, specifically, which security tasks your provider has committed to in writing, and which ones quietly fall to you?
Does this week's CMMC news change what you should do?
Several outlets circulated reports this week that the Department of Defense has paused or adjusted Level 2 certification requirements for CMMC. We are going to be direct with you: as of this writing, we do not treat that as settled, and neither should you. Blog posts and vendor commentary are not the rule. The CMMC Program rule at 32 CFR Part 170 and the acquisition rule that puts CMMC into contracts are the authority, and DoD's own CMMC pages are where changes get confirmed. Check those before you change a plan. Our own read on the pause is in what the CMMC Phase 2 pause means for small contractors.
Here is the part that matters more. Whether a certification date moves or not, the underlying obligation for defense contractors handling controlled unclassified information has not changed. If you hold DFARS 252.204-7012, you already owe implementation of NIST SP 800-171 and incident reporting. A schedule change is a change to when someone checks. It is not a change to what you agreed to do.
So the honest advice on a pause, confirmed or not, is the least exciting advice available: keep doing the work. Organizations that treated earlier timeline shifts as permission to stop are the ones now scrambling. Nobody has ever regretted having accurate documentation ready early.
See Where You Actually Stand
If you are a small business, nonprofit or defense contractor without IT staff, our in-kind gap assessment grants give you a clear, funded picture of your current state -- we perform the assessment for you rather than handing over cash.
Apply for the Gap Assessment Grant →How do you train people without a training department?
Awareness training in a small organization does not have to look like a corporate learning platform. It has to look like something that actually happens.
Three things carry most of the weight. First, teach people what your organization will never ask them to do, so an unusual request is recognizable. We will never ask you to buy gift cards. We will never ask you to change bank details by email. Second, make reporting fast and blameless. If a staff member who clicked something feels safe telling you within ten minutes, you have bought yourself an enormous advantage. Punish the click and you will find out about incidents from your bank instead. Third, do it in short and frequent doses. A ten minute item at a monthly all hands beats an annual session everyone clicks through.
Write down the reporting path on one page: what to do, who to tell, what not to do (do not delete the message, do not pay anything, do not reply). Post it where people can see it.
What does good enough look like, and how do you prove it?
Good enough is written down, current, and matched to what you actually do.
For most small organizations, that means a short set of documents: your inventory, an access list reviewed on a schedule, a backup and restore record, a one page incident response plan with real phone numbers, and a note of which security responsibilities sit with which vendor. For a defense contractor, the bar is more specific: a System Security Plan, plan of action and milestones for what is not yet implemented, and a score in the Supplier Performance Risk System, all consistent with each other.
The reason we push documentation on organizations with no IT staff is not paperwork for its own sake. It is continuity. When the one person who knew how everything worked takes a new job, the documentation is the difference between an inconvenience and a crisis. If your most knowledgeable person were unavailable for two weeks starting tomorrow, could someone else restore a backup?
Frequently Asked Questions
What is the first thing a small organization with no IT department should do?
Build a written inventory of accounts, devices and who has access to each. You cannot protect systems you have not listed, and most organizations discover stale accounts or a failed backup during this exercise. It takes an hour or two and requires no technical skill or tooling.
Do we need to hire someone to handle cybersecurity?
Not necessarily, but someone must be named as the owner. That person does not have to be technical. Their role is to maintain the inventory, verify backups and updates actually happened, and serve as the known point of contact when staff see something suspicious.
Has the Department of Defense paused CMMC Level 2 requirements?
Reports to that effect circulated in late July 2026, but the authoritative sources are the CMMC Program rule at 32 CFR Part 170, the corresponding acquisition rule, and DoD's official CMMC pages. Verify there before acting. Regardless of certification timing, existing DFARS 252.204-7012 obligations to implement NIST SP 800-171 and report incidents remain in force.
Is our outside computer support provider handling security for us?
Only what your written agreement says they handle. Many general technology providers cover uptime and helpdesk without covering patch verification, logging, monitoring or backup testing. Read the agreement and write down which security tasks are theirs and which are yours.
What security controls give the most protection for the least effort?
Multifactor authentication on email and any system holding sensitive data, prompt software updates, tested backups, and removing access for people who have left. These are widely recommended by NIST and CISA for small organizations and they block the majority of ordinary attacks.
How often should we review who has access to our systems?
At minimum quarterly, and immediately whenever someone leaves or changes roles. Put it on a calendar with a named owner, because access reviews are the task most likely to be skipped when nobody's job title includes IT.
Sources: NIST Small Business Cybersecurity Corner; CISA Cyber Essentials; NIST SP 800-171; CMMC Program final rule, 32 CFR Part 170; DoD CIO CMMC program pages; DFARS 252.204-7012; FTC Cybersecurity for Small Business.
