← Back to blog

2026-10-06 · Security Basics

Houston SMB Security Gaps: Map Each Mistake to a CISA Fix

A fix-mapping card for Houston small businesses: each common security gap, the CISA practice it maps to, the proof to check, and what to do this week.

This page is a fix map. It isn't another list of mistakes.

The five security mistakes post names five of these gaps we run into most in Houston offices. The CISA and Houston-area resources directory lists the free government pages and where to report. This one connects the two. For each gap, you get the CISA practice that covers it, a short owner step, the ticket for your IT host, and the proof that shows it's done.

It's for businesses of about 5 to 50 people. CISA (the Cybersecurity and Infrastructure Security Agency) is the U.S. agency that publishes free security guidance. The fixes come from its Four Cybersecurity Essentials for Businesses and Cybersecurity Performance Goals 2.0. CPGs (Cybersecurity Performance Goals) are baseline practices. CISA calls them voluntary and says they're meant for businesses of all sizes. Codes like 3.F are CPG 2.0 goal numbers your IT host can look up.

How does a Houston small business fix common security gaps? Match each gap to one CISA practice. Do the owner step this week, send the rest to your IT host as a ticket, and save dated proof. You don't have to do all seven at once, so start with two or three rows.

How to use this card

  • Owner step: about 15 minutes, mostly looking and asking. Don't change settings you're unsure about.
  • IT ticket: the part that needs admin access or a design decision. Send it as written.
  • Proof: what goes in the folder. A dated "not yet" is a real answer.

Gap → CISA fix map

1. MFA covers some people, not everyone

CISA practice: CPG 2.0 goal 3.F, Implement Multi-factor Authentication. MFA (multi-factor authentication) means a password plus a second step. The goal asks for MFA on all IT accounts, admins first, using the strongest method available. Phishing-resistant methods, such as a FIDO security key, come first. Next is an authenticator app with number matching. Text or voice codes are only for when nothing else works. Four Essentials also says to confirm that all remote access and admin access require MFA. NIST's SP 800-63B-4 also encourages phishing-resistant sign-in wherever it's practical.

Owner step: Run the first 12 minutes of the MFA coverage drill. Write down the enforcement setting and any admin who isn't enrolled.

IT ticket: "Enroll the listed accounts and confirm one enforcement path." In Microsoft 365, Security Defaults and Conditional Access are alternatives. Microsoft's MFA for Microsoft 365 page says you can use one or the other, but not both at the same time. Emergency (break-glass) admin accounts keep MFA too. Use a phishing-resistant method for them, such as a FIDO2 security key or passkey, and use a different phishing-resistant method than your daily admin accounts. If MFA was never turned on, start with the setup guide.

Proof: A dated coverage log and the enrollment export.

2. Backups run, but nobody has opened a restore

CISA practice: CPG 2.0 goal 3.O, Maintain System Backups & Restoration Ability. It asks for a list of all your backups and for offsite, offline storage. It also asks you to test backups and recovery on a schedule, at least once a year. The #StopRansomware Guide asks for offline, encrypted backups that you test.

Owner step: Run the 15-minute backup test on one real file.

IT ticket: "Show us which copy is offline or offsite, and who holds the keys." That's question 3 on the IT-host renewal card.

Proof: The restore log and the host's written answer.

3. Offboarding depends on who remembers

CISA practice: CPG 2.0 goal 3.D, Revoking Credentials for Departing Staff. It calls for a defined, enforced offboarding process for staff, contractors, and vendors. That includes collecting badges and tokens and removing all system and building access. It also says to disable accounts that sit unused for a set period, and it gives 30 days as an example.

Owner step: Open the active user list. Mark everyone who has left, plus every contractor and guest account. Then write down who is responsible for same-day offboarding.

IT ticket: "Disable the marked accounts, remove their admin roles, and set up an inactive-account review."

Proof: The dated list, with every marked account shown as disabled.

4. One admin account also reads daily email

CISA practice: CPG 2.0 goal 3.G, Administrators Maintain Separate User and Privileged Accounts. Everyday accounts don't get admin rights. Admins use a separate account for email and browsing, and their rights get re-checked on a schedule.

Owner step: Count the Global Admins (the top Microsoft 365 role). Note which of them also use that account for daily email.

IT ticket: "Create separate admin accounts with MFA. Remove admin rights from the daily mailboxes."

Proof: A dated admin role list.

5. Shared passwords and "office@" logins

CISA practice: CPG 2.0 goal 3.C, Create Unique Credentials. Separate credentials for each service, no password reuse, and admin passwords that differ from everyday ones. Four Essentials adds three more: passwords of at least 16 characters, a company-wide password manager, and changing default passwords.

Owner step: List every shared login: the bank portal, the office@ mailbox, the router, vendor portals. Write down who knows each one.

IT ticket: "Give each person their own sign-in where the service allows, check whether staff can open office@ from their own accounts, and move the rest into a business password manager."

Proof: The login list, with each item marked own account, in the password manager, or still shared.

6. Remote access and patching leftovers

CISA practice: CPG 2.0 goals 3.S, Secure Internet Facing Devices, and 2.B, Mitigate Known Vulnerabilities. Keep internet-facing systems few and patched, and keep management pages off the public internet. The #StopRansomware Guide says not to expose RDP (Remote Desktop Protocol, the Windows remote desktop service) on the web.

Owner step: Ask your IT host two questions. When was the last patch window for the firewall, the VPN, and anything with a public login page? And can RDP be reached from the internet?

IT ticket: "Close or limit exposed remote access, require MFA on what stays open, and send the latest patch report."

Proof: A dated patch report and a written "RDP is not exposed."

7. "We trained once"

CISA practice: Four Essentials says once-a-year training isn't enough. It says to reinforce safe habits regularly and make sure staff know who to report suspicious email to and how. CPG 2.0 goal 3.J, Implement Cybersecurity Training, adds training for new hires before they get a login.

Owner step: Put a short, recurring reminder slot on the calendar. Name the one person staff should report odd messages to.

IT ticket: This one is optional. Ask whether your email has a "report phishing" button.

Proof: The date of the last reminder and the name of the reporting contact.

Printable fix-map card

Copy or print this table. Leave blanks as unknown. Don't guess.

#GapCISA practiceOwner stepIT ticketProofDone / date
1Partial MFACPG 3.FCoverage drill (12 min)Enroll gaps; Security Defaults or Conditional Access; break-glass keeps MFACoverage log
2Untested restoreCPG 3.OOpen one restored fileName offline copy + key holderRestore log
3Informal offboardingCPG 3.DMark leavers, contractors, guestsDisable; inactive reviewDisabled list
4Admin reads emailCPG 3.GCount Global AdminsSeparate admin accountsRole list
5Shared loginsCPG 3.CList shared loginsOwn sign-ins; password managerMarked list
6Remote access / patchesCPG 3.S, 2.BAsk: patch date, RDPClose or limit; patch reportPatch report
7One-time trainingFour EssentialsReminder slot; reporting contactReport-phishing buttonReminder date

Card date: YYYY-MM-DD · Filled by: · Rows picked this week:

Why leftovers pile up in a busy Houston office

These gaps come from ordinary business. Seasonal hires keep their accounts after the season ends. A contractor's login for one job site stays active after the job is done. The vendor who set up the router years ago still knows the password. This card is a way to catch those leftovers on a calm week.

Evidence folder for insurance renewals

This is a folder habit, not legal or coverage advice. Name each pass fix-map-YYYY-MM-DD. Save one file for each row you close, such as 01-mfa-coverage-YYYY-MM-DD, along with the IT host's dated written answers. Keep the folder next to your IT-host renewal card and ransomware prep checklist.

Related guides


Educational content only — not legal, insurance, or compliance advice.

Need help implementing this in Houston?

Houston Secure IT can walk through MFA, backups, and a practical baseline with you.

713-364-8666 — Houston Secure IT / shop line