Cybersecurity Is Business Continuity

Beyond Passwords and Phishing
October is Cybersecurity Awareness Month, which makes it a natural time to talk about passwords, phishing emails, software updates, multifactor authentication, and the other practices commonly associated with protecting a business online. Those things matter because each can reduce the likelihood that a business experiences a cybersecurity problem, but they are not really where I believe the cybersecurity conversation should begin.
Imagine arriving at your business tomorrow morning and discovering that you cannot access your email. Your accounting system will not open, the files you normally retrieve from cloud storage are unavailable, or your point-of-sale system cannot process a transaction. Perhaps the problem is even simpler: you cannot sign into an account that has quietly become essential to running the business.
The cause could be a cyberattack, but it could just as easily be a compromised password, a failed device, an account lockout, a corrupted file, a service outage, or an employee mistake. From the business owner’s perspective, the immediate problem is largely the same. Something the business depends on is no longer available, and the first concern quickly becomes whether customers can still be served, employees can still work, payments can still be accepted, and normal operations can continue.
That is why I believe small business owners should think about cybersecurity as more than a technology issue. Cybersecurity is also a business continuity issue because, regardless of what caused the interruption, the business still has to figure out what happens next.
Cybersecurity Is Not Only About Prevention
Much of the cybersecurity advice given to small businesses understandably focuses on keeping something bad from happening. Business owners are told to use strong passwords, enable multifactor authentication, keep software updated, train employees to recognize phishing attempts, and back up important information. Those are all sound practices because prevention is usually easier and less expensive than dealing with the consequences of a successful attack or system failure.
Where the conversation sometimes becomes too narrow is when prevention is treated as the entire objective. I have spent enough time working with business owners to know that businesses can prepare carefully and still encounter something they did not anticipate. Employees make mistakes, equipment fails, accounts are compromised, vendors experience outages, software contains vulnerabilities, and sometimes a problem occurs even though the business believed it had done the right things.
That experience is why I tend to look at cybersecurity differently.
The objective of cybersecurity is not to make your business impossible to attack. It is to make your business harder to compromise, limit the damage when something happens, and make recovery possible.
Once we approach cybersecurity that way, the discussion changes. We still want to prevent the problem, but we also need to think about what happens if prevention does not work. How quickly will the business recognize the problem? How much of the company could be affected? Which operations can continue? Who needs to make decisions, and what will be required to return the business to normal?
The National Institute of Standards and Technology takes a similarly broad approach in its Cybersecurity Framework 2.0, which organizes cybersecurity risk management around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Protection is important, but it is only one part of the framework because cybersecurity does not begin and end with keeping something bad from happening.
For the small business owner, that is one of the most useful ideas to carry forward. Good cybersecurity is not measured solely by whether an incident occurs. It is also reflected in how well the business understands its risk and how prepared it is to respond when something does not go according to plan.
When Convenience Becomes Dependency
What I have seen over the years is that businesses rarely make a conscious decision to become dependent on technology. They usually introduce a system because it saves time, simplifies a process, reduces costs, improves service, or makes the business easier to manage.
The dependency develops gradually. An accounting system adopted to make bookkeeping easier may eventually become the place where the financial information needed to invoice customers, pay bills, or run payroll is maintained. A scheduling platform may become the only reliable record of customer appointments. A point-of-sale system may eventually connect sales, payments, inventory, and customer information in ways that make operating without it difficult. Similar dependencies can develop around cloud storage, marketing, estimating, production, reservations, dispatching, design, compliance, project management, and other systems that have become part of everyday operations.
At some point, the question is no longer whether the technology is convenient. The question becomes what happens to the business when that technology is unavailable.
A system does not have to contain highly classified information or sophisticated intellectual property to be important. Its importance comes from what happens to the business when it cannot be used.
Business owners often hear cybersecurity discussed in terms of protecting valuable information and naturally wonder whether they possess anything a criminal would want to steal. That is a reasonable question, but it is only part of the question. A business should also consider what it could lose access to that would make it difficult to operate.
A restaurant may not think of itself as a technology company, but losing its point-of-sale system during the dinner rush immediately creates an operational problem. Employees may still be able to prepare food and serve customers, but processing payments, entering orders, tracking sales, and closing out the day can become much more difficult.
A contractor may not maintain a massive customer database, but losing access to estimates, invoices, schedules, project files, and email could interfere with field operations, customer communication, and cash flow. A small professional firm might employ only a handful of people, but if its client records suddenly become inaccessible, the size of the company does not make the interruption insignificant.
For me, this is where cybersecurity becomes much easier to connect to the realities of a small business. The sophistication of the technology matters less than how much the business depends on it.
Downtime Has a Cost Even When the Doors Stay Open
We sometimes think about business interruption as an all-or-nothing event. Either the business is operating or it is not. In practice, many technology disruptions fall somewhere between those two extremes, and the business may continue functioning, just not very well.
Employees may spend hours reconstructing information that normally appears automatically. Customers may have to wait longer. Transactions may be recorded by hand with the intention of entering them later. Employees may begin using personal phones or email accounts because the normal communication system is unavailable. Managers may have to contact customers individually to recreate a schedule or confirm work that had already been arranged.
None of those things necessarily closes the business, but all of them change how the business operates.
Some of the costs are easy to identify. Sales may be lost, invoices may be delayed, appointments may be missed, overtime may increase, or employees may accomplish less work than they normally would. Other costs are harder to see. Employees working around a failed system may make mistakes. Information recorded temporarily may be entered incorrectly or lost. Customers may become frustrated. Owners and managers may spend most of their day solving an unexpected problem rather than doing the work that normally keeps the company moving forward.
Business continuity is not simply about whether the doors remain open. It is about whether the business can continue doing the things that matter most while the disruption is being resolved.
What that looks like will differ from one company to another. A temporary inconvenience for one business could immediately interrupt revenue for another, which is why cybersecurity planning has to begin with an understanding of the individual business rather than a generic list of technology recommendations.
Protection Has More Than One Job
I tend to think about cybersecurity protection as having more than one responsibility.
The first is the one we discuss most often: reducing the likelihood that something goes wrong. Strong passwords, multifactor authentication, software updates, access controls, employee training, and other safeguards all contribute to that goal.
The second responsibility is limiting what happens when prevention does not work. There is a significant difference between having an incident and allowing one incident to spread throughout the business. A compromised employee account should not automatically provide access to everything the company owns. One infected computer should not necessarily compromise every business file. A mistake made by one employee should not have unlimited consequences simply because everyone shares the same credentials or because access has never been reviewed.
The third responsibility is recovery. If important information or systems become unavailable, the business needs a reasonable path back to normal operations.
The Federal Trade Commission’s cybersecurity guidance for small businesses reflects this broader view by recommending backups and encouraging businesses to think about incident response, disaster recovery, and business continuity. The point is not simply to put safeguards in place and assume the work is finished. Businesses also need to consider what they will do if those safeguards are not enough.
I think of the three responsibilities as working together. Prevention reduces the likelihood of the problem. Limiting the damage keeps one problem from becoming several. Recovery helps the business get back to work.
Recovery Is More Than Restoring Data
Backups are one of the most common recommendations in cybersecurity, and for good reason. Losing important business information can create enormous problems, but having a backup and being able to recover are not necessarily the same thing.
Suppose a company discovers that several days of records have been corrupted and learns that a usable backup exists. That is certainly better than discovering there is no backup at all, but several questions still have to be answered.
When was the backup created? What information does it contain? Where is it stored? Who knows how to retrieve it? How long will restoration take? What happens to transactions or information created after the backup was made? Can the business continue operating while the restoration is taking place?
The goal is not simply to be able to say that the business performs backups. The goal is to be able to restore what the business actually needs.
The same principle applies when an account is compromised. Regaining access may solve the immediate technical problem, but the business may still need to determine whether information was changed, messages were sent, customers or vendors were affected, or other accounts are also at risk.
An emergency contact list presents another simple example. The business may have the telephone numbers and email addresses it needs, but those contacts do little good if the only copy of the list is stored inside the system nobody can access. The same problem exists with an incident response plan that employees have never seen or a cybersecurity insurance policy when no one knows whom to call or what information the insurer will require.
These are the kinds of details I believe make the difference between having something on paper and having something the business can actually use. Recovery is not simply the restoration of technology. It is restoring the ability of the business to function reliably again.
Continuity Is Also About Time
When I talk about business risk, one of the things I want to understand is not simply what system a business uses, but how long the business can afford to be without it.
Not every system has the same urgency. Losing access to a social media account for two hours may be frustrating but have little immediate impact on operations. Losing the ability to process customer payments for two hours could be much more serious. A company may be able to operate without its accounting system for a day but face a very different problem if payroll cannot be completed by the end of the week.
The importance of a system therefore depends not only on what it does, but also on how quickly its absence begins to affect the business.
For some systems, that point may be several days away. For others, it may arrive within minutes. A small business does not need a complicated formula to begin thinking this way. The owner can simply ask how long a system can be unavailable before customers, employees, revenue, cash flow, or contractual obligations begin to suffer.
If an interruption lasting one hour would create confusion, lost revenue, or significant customer problems, the business probably needs to think more carefully about what it would do during that hour. Something the company could comfortably operate without for several days may reasonably receive a different level of attention.
Time changes the impact of a disruption, and I believe understanding that relationship helps business owners make more practical decisions about where preparation matters most.
Recovery Is a Business Decision
Small business owners already make decisions about risk every day, even when they do not describe what they are doing as risk management.
They purchase insurance because some losses would be difficult to absorb. They maintain equipment because mechanical failure can interrupt production. They keep cash available for unexpected expenses. They develop relationships with alternate suppliers because inventory may not always arrive when expected. They decide who can sign checks, authorize purchases, or make commitments on behalf of the company.
Some businesses maintain spare parts, extra inventory, or backup equipment because they know what being without something important would mean to the operation. None of those decisions eliminates risk. Instead, they give the business more options when something goes wrong.
Cybersecurity belongs in that same conversation.
I do not believe every small business owner needs to become a cybersecurity expert any more than every owner needs to become an accountant, attorney, insurance professional, or information technology specialist. Expertise can be brought into the business when it is needed.
What cannot be delegated quite as easily is the owner’s responsibility to understand what the business depends on and what happens when something important stops working.
If the accounting system became unavailable for several days, payroll and invoicing might be affected. If email stopped working, employees might lose their normal way of communicating with customers. If a scheduling system became inaccessible, field employees might not know where they are supposed to go. If a laptop disappeared, the consequences would depend partly on how much business information existed only on that device.
Those are cybersecurity questions, but they are also management questions because they affect operations, financial exposure, customer relationships, employee responsibilities, and the ability to deliver what the business has promised.
The technical work may be delegated, but the business consequences still belong to the business.
Start With the Business, Not the Technology
One of the reasons cybersecurity can feel overwhelming is that the discussion often begins with technology. There are unfamiliar terms, new products, different types of attacks, changing recommendations, and a seemingly endless list of things an owner is told to worry about.
There is a simpler place to begin: start with the business.
Think through a normal day from the moment work begins. Consider what employees need in order to do their jobs, how customers communicate with the company, how sales are completed, where schedules are maintained, how payments are accepted, how employees are paid, and where the information needed to perform the work is stored.
Then imagine removing one of those systems from the day.
The useful questions are not necessarily technical. Could customers still be served? Would employees know what work had already been scheduled? Could payments still be accepted? Is there another way to communicate? Can important information be retrieved somewhere else? How long could the business continue before the disruption began affecting customers, employees, cash flow, or the ability to complete the work that has been promised?
This kind of exercise helps separate technology the business happens to use from technology the business has become dependent upon.
Distinction is particularly important for small businesses because resources are limited. Owners do not have unlimited money, people, time, or attention to prepare equally for every conceivable problem. Understanding where a disruption would hurt the business most gives the owner a more practical place to begin.
A Plan Has to Work When the Plan Is Needed
I have seen many areas of business where the plan seems obvious until someone actually has to use it, and cybersecurity and business continuity are no different.
The first time employees think about what they would do during a disruption should not be while the disruption is occurring. A company does not necessarily need an elaborate cybersecurity exercise to test that assumption. Sometimes a conversation is enough to expose a problem nobody had considered.
If the point-of-sale system were unavailable for four hours, how would transactions be handled? If email could not be accessed, how would tomorrow’s customers be contacted? If the owner were unavailable, who would have authority to make operational decisions? If outside technical support were needed, where is that contact information stored?
Questions like these can reveal that the continuity plan exists more clearly in one person’s head than it does within the business. That can become a vulnerability of its own.
A business is in a stronger position when important knowledge, authority, and procedures do not depend completely on one person being available at exactly the right moment. Preparation does not have to become complicated simply for the sake of having a plan. It does, however, have to work when the business actually needs it.
Resilience Is What Happens Next
There is a natural tendency to judge cybersecurity by whether an incident occurs. If nothing happens, we assume the security worked. If something happens, we may assume the business failed to protect itself.
I do not think the answer is always that simple.
A well-prepared business can still experience a cybersecurity incident, service outage, lost device, employee mistake, or some other unexpected disruption. The difference may be in what happens afterward. The problem is recognized, the damage is limited, critical information remains available, employees understand what they should do, customers can still be served, and normal operations can be restored.
That is what resilience means to me in this context. It is not an expectation that nothing will ever go wrong. It is the recognition that something eventually might and that the business should be capable of responding without allowing one disruption to determine everything that follows.
Small business owners already understand that principle because uncertainty is part of operating a business. Cybersecurity simply requires us to apply that same thinking to the technology, information, accounts, and systems that have become part of everyday operations.
Keeping the door locked matters. Knowing what to do if the lock fails matters too.
You Do Not Have to Figure This Out Alone
One of the reasons I wanted to write about cybersecurity this month is that small business owners do not have to approach the subject by themselves.
America’s SBDC has invested in strengthening the cybersecurity knowledge of advisors through the North Star Cybersecurity Program. North Star is designed for SBA Resource Partner staff and advisors, including SBDCs, and provides training in cybersecurity fundamentals, phishing, password security, malware, software updates, data security and privacy, cybersecurity standards and frameworks, cyber insurance, and cybersecurity advising. Its purpose is to give advisors a working level of cybersecurity knowledge that can help them better support small businesses.
I am North Star certified, and I view that training much the same way I view the other tools I use when working with business owners. It does not mean I replace an information technology professional, cybersecurity specialist, attorney, insurance professional, or another expert when one is needed. It means I am better prepared to have the initial conversation, ask better questions, help an owner think about cybersecurity from a business perspective, and recognize when additional expertise may be appropriate.
That is an important part of what America’s SBDC is here to do.
Sometimes a business owner knows there is a cybersecurity concern but does not know what questions to ask. Others may not be sure whether a particular issue is technical, operational, financial, or some combination of all three. Starting the conversation with an SBDC advisor can help the owner organize those concerns and better understand where additional attention may be needed.
Small business owners do not have to understand every cybersecurity standard, technical term, or threat before they can begin improving their position. The first step may simply be talking through how the business operates, what happens when something important becomes unavailable, and where additional planning or professional assistance may make sense.
Your local SBDC can help you begin that conversation.
Where Cybersecurity Planning Begins
Cybersecurity Awareness Month gives small business owners a useful point on the calendar to stop and look at how their businesses have changed. Systems change. Employees change. Vendors change. Technology changes. The way customers interact with the business changes. The protections and plans surrounding those systems should be reviewed as well.
I encourage business owners to use October as the beginning of an annual cybersecurity review. Look at the systems, accounts, devices, information, and services your business depends on today, not simply the ones you were using the last time cybersecurity received your attention.
A useful place to begin is with a simple question:
If I could not use this tomorrow, what would happen to my business, and how long could I operate without it?
The answer can help reveal where additional planning, protection, or professional assistance may be needed.
So, welcome to Cybersecurity Awareness Month. Over the next several weeks, I will continue looking at cybersecurity from the perspective of the small business owner, including what we are protecting, who has access to it, and how much of the business may depend on systems and organizations outside our direct control.
October gives us an opportunity to review these things, but cybersecurity does not belong to October alone.
The business gives us a reason to keep the conversation going all year long.
References
National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0.
National Institute of Standards and Technology. NIST Cybersecurity Framework 2.0: Small Business Quick-Start Guide.
Federal Trade Commission. Cybersecurity for Small Business.
America’s SBDC / Delaware Small Business Development Center. North Star Cybersecurity Certification Program.
Cybersecurity Is Business Continuity | By Manzel McGhee Jr., ASBC® | Abilene SBDC




