Dallas, TX · serving Dallas–Fort Worth · remote across Texas Remote support 24/7/365, including US holidays connect@crossrivertechnology.com

Dallas business IT

Cybersecurity basics for a Dallas small business

You do not need a security operations center. You need seven ordinary things done properly and kept working. Here is the short list I set up for Dallas small businesses, why each one is on it, and how to tell whether yours are really in place.

Written and reviewed by Anthony Omini, Cross River Tech·10 min read·Published · Updated

What cybersecurity does a small business in Dallas need?

A Dallas small business needs seven things, not seventy: multi-factor authentication on every account, updates applied on a schedule, endpoint protection you can actually see, email filtering, a backup someone has tested by restoring from it, everyday work done without administrator rights, and staff who report a mistake immediately because nobody gets punished for it. That list stops most of what really happens.

Answered by Anthony Omini, Cross River Tech, Dallas

Hand resting on a laptop keyboard in a bright workspace

Key takeaways

  • Most small business incidents come through a stolen password or a convincing email, not a sophisticated attack, so multi-factor authentication and email filtering do the heaviest lifting.
  • A backup only counts once someone has restored from it; an untested backup is a hope, not a control.
  • Everyday accounts should not have administrator rights, and the account that does should be separate and rarely used.
  • Staff who feel safe saying 'I think I clicked something' turn a serious incident into a five-minute fix, so the culture is a security control.
  • CISA and the FTC both publish free small business guidance that says roughly the same short list, which is a good sign you are not being sold something exotic.

What cybersecurity does a small business in Dallas need?

Seven things. Not a wall of products, not a compliance programme, not an annual penetration test. A ten-person office in Dallas that has these seven in place is a far harder target than one that has bought expensive tools and left the basics undone.

  1. Multi-factor authentication on every account, especially email and anything touching money.
  2. Updates applied on a schedule to computers, servers, phones, and the firewall and router nobody looks at.
  3. Endpoint protection that reports somewhere, so a problem on one machine is visible before its owner notices.
  4. Email filtering that catches phishing and spoofed senders before a human has to make the judgement call.
  5. Backups that have been tested by restoring from them, including your Microsoft 365 or Google Workspace data.
  6. Administrator rights separated from everyday accounts, so a bad click cannot install anything.
  7. Staff who feel safe reporting a mistake immediately, because speed is what limits the damage.

None of this is dramatic and none of it is expensive. Most of it is already included in subscriptions you pay for and simply has not been turned on. That is the honest state of a lot of small offices I look at, and it is fixable in a short project rather than a long programme. I do this work under cybersecurity, backup and disaster recovery, and for most Dallas businesses it is the first thing worth doing.

How do small businesses actually get hacked?

Overwhelmingly through a person, not a firewall. The picture in most people's heads is somebody breaking through a network defense. What I actually see is far more ordinary, and knowing the real routes tells you where to spend your effort.

How it happensWhat it looks like from your deskWhat stops it
Stolen or reused passwordSomeone signs into your email from somewhere else and reads everythingMulti-factor authentication
Phishing emailA convincing sign-in page that harvests the passwordEmail filtering, MFA, staff who report it
Invoice and payment fraudA supplier "changes" bank details by email and a payment goes to a criminalA phone-call verification rule for money changes
Unpatched softwareNothing at all, until something exploits a hole that had a fix availablePatching on a schedule
Malicious download or attachmentA file that installs something, often with the user's own rightsEndpoint protection plus no administrator rights
Exposed remote accessA remote desktop port left open to the internet and found by scanningClosing it, and using a proper remote access method
A departed employee's account left openAccess that should have ended months agoAn offboarding checklist run the same day

Look at that column of fixes. Five of the seven are the same five things on the short list above. That is why the list is short: the same small set of controls covers most of the realistic routes into a small business. When someone tries to sell a Dallas office a complicated security product before those five are in place, the priorities are wrong.

Why is multi-factor authentication the first thing to do?

Because a password on its own is no longer a meaningful defense, and multi-factor authentication is the cheapest thing on the list. MFA means that signing in needs your password plus something else: a prompt on your phone, a code from an app, or a physical key. A criminal who buys or phishes your password still cannot get in.

Where to turn it on, in priority order:

  • Email first. Microsoft 365 or Google Workspace, for every single user including the owner and the part-time bookkeeper.
  • Anything financial. Online banking, payroll, the accounting package, payment processors.
  • Administrator accounts everywhere. The tenant admin, the firewall, the remote access tool, the website hosting.
  • Your line-of-business application. The practice management, case management or agency system your work lives in.
  • Password manager and remote access. The keys to everything else.

Use an authenticator app or a number-matching prompt rather than text messages where you have the choice, because text codes can be intercepted through the phone carrier. Text is still far better than nothing, so if the choice is text or no MFA, take text and improve it later. Enrolment takes a few minutes per person. Doing it for a whole office including the awkward accounts is usually a single afternoon, and it is covered in more depth in Microsoft 365 security for a small business.

What does patching actually mean, and who is doing it at your office?

Patching means installing the security fixes that software makers release, on a schedule, on everything, and confirming they landed. It is unglamorous and it is the reason a lot of incidents never happen. The question worth asking yourself is simple: at your office right now, who checks that it happened? If the honest answer is nobody, that is the gap.

The things that need patching are wider than most people expect:

  • Windows and macOS on every computer, including the machine in the back room nobody uses much.
  • Servers, with a reboot window you agree in advance so it does not happen mid-afternoon.
  • Browsers and everyday applications, which are a very common way in.
  • Firewall, router, switches and access points, whose firmware often has not been touched since installation.
  • Printers and scanners, which are small computers with network access and frequently forgotten.
  • Phones and tablets that hold company email.
  • Anything past end of support, which no longer gets fixes at all and needs replacing rather than patching.

On a managed plan I do this centrally: updates go out on a schedule, I can see which machines are behind, and the ones that fail get chased rather than quietly staying broken. Leaving each employee to click "remind me tomorrow" for six months is the default outcome otherwise, and it is not their fault. It is a process problem, and processes are what a managed IT plan is really buying you.

Is the antivirus that came with Windows enough?

For a home computer, the built-in protection is decent. For a business, the missing piece is not detection quality, it is visibility. If a machine in your office finds something at 11 PM on a Saturday and nobody sees the alert, the protection did half its job. Business endpoint protection reports to a console someone actually watches.

What I look for when setting this up for a Dallas office:

  • Central reporting. One place showing every machine, its status, and anything it has blocked.
  • Behaviour-based detection, not only known-signature matching, because ransomware changes faster than signature lists.
  • Tamper protection, so a user or a piece of malware cannot simply switch it off.
  • Alerting to a person. An alert nobody reads is decoration.
  • Coverage of laptops off the network, since half your risk walks out of the building each evening.

Pair it with email filtering, because email is where most of it starts. Good filtering strips known-bad attachments, checks links at the moment they are clicked rather than only at delivery, flags mail from outside your organization, and catches display-name spoofing where a message appears to come from the owner. Both Microsoft 365 and Google Workspace include capable filtering in their business plans; the difference between a protected office and an exposed one is usually configuration, not the license tier.

How do I know my backup would actually work?

By restoring something from it. That is the whole answer, and it is the step almost nobody takes. A backup that runs every night and has never been restored is an assumption. I have opened backup consoles at new client sites showing green ticks for months against a job that had been silently backing up an empty folder.

A backup you can rely on has these properties:

  1. More than one copy, in more than one place, with at least one of them off the office network so ransomware cannot reach it.
  2. It includes your cloud data. Microsoft and Google keep your service running; they do not promise to bring back the folder an employee deleted two months ago. Mailboxes, OneDrive, SharePoint and Google Drive need their own backup.
  3. Retention that matches your business. Thirty days is not enough for a mistake discovered at quarter end.
  4. Monitoring with a human attached. Someone notices a failed job the next morning, not the next disaster.
  5. A tested restore. Pick a file, pick a mailbox, bring them back, write down how long it took.
  6. A written recovery order. What comes back first if everything is gone, and who calls whom.

Test restores are quick and I do them as routine work rather than as a project. The number that matters is not how much data you keep, it is how long you would be down and how much work you would lose. If you cannot answer those two questions today, that is where to start.

Why should nobody work in an administrator account?

Because software installed by a click runs with whatever rights the person had at the time. If the owner of a Dallas insurance agency does their email in an account that can install software across the network, one bad moment becomes a company-wide problem. If the same person is signed in as an ordinary user, the same bad moment is mostly contained.

Admin separation in a small office is not complicated:

  • Everyday accounts are standard users. Including the owner, including me when I am doing ordinary work.
  • A separate administrator account exists with a different, long, unique password, used only when a change genuinely requires it.
  • The Microsoft 365 or Google Workspace global admin is its own account, not a mailbox someone reads daily, with MFA on it and the recovery details written down somewhere you control.
  • Two people can reach the top-level admin. Usually you and me, so nobody is locked out when either person is unreachable.
  • Passwords live in a password manager, shared through the manager rather than by text message or a note in a drawer.
  • Access is reviewed once a year, alongside the rest of your annual check-up.

The objection I hear is that being a standard user is inconvenient. In practice it costs a normal employee nothing, because they are not installing software weekly. The people who notice are the ones who should be noticing.

How do I get staff to report mistakes instead of hiding them?

Say out loud, in advance, that reporting is welcome and that nobody gets in trouble for it. Then mean it the first time it happens. This is the cheapest control on the list and it is the one that most changes the outcome, because almost every incident is far easier to contain in the first ten minutes than on day three.

What that looks like in a small Dallas office:

  • A written line in the welcome sheet. "If you think you clicked something, tell me straight away. You will not be in trouble." I cover the rest of that sheet in the IT onboarding checklist for your first employees.
  • One number to call. Not a form, not a queue. A person.
  • A visible response when it happens. Password changed, sessions revoked, mailbox rules checked, and a thank-you rather than a lecture.
  • A verification rule for money. Any change to bank details or any unusual payment request is confirmed by voice on a known number, never by replying to the email.
  • Short, occasional reminders using real examples from your own inbox, rather than an annual training video nobody remembers.

If someone at your office has already clicked something, the immediate steps are in what to do after someone clicks a phishing email. The short version is: do not wait to see what happens, and do not start by deleting the evidence.

Where do CISA and FTC guidance fit, and what does this cost?

Both are free, both are written for people who are not IT specialists, and both land on a short list very close to the one above. CISA, the federal Cybersecurity and Infrastructure Security Agency, publishes plain-language material for small organizations, and the Federal Trade Commission publishes small business cybersecurity guidance aimed at owners rather than engineers. If you want to sanity-check anything an IT provider tells you, those are good places to read for half an hour. When a proposal you are given looks nothing like that short list, ask why.

On cost, here is the honest shape of it for a small Dallas office:

  • MFA, admin separation and a reporting culture cost nothing but time. They are configuration and habit.
  • Patching and endpoint monitoring are included in a managed IT plan, quoted per user or per device after a short conversation, month-to-month with no lock-in.
  • Backup for cloud data and servers is a small per-user or per-workload subscription, and it is the line I would cut last.
  • One-off remediation work, if you are starting from nothing, is hourly at $100 per hour remote or $150 per hour onsite during business hours, with a one-hour minimum.

What you get is not immunity. Anyone promising that is selling something. What you get is that the ordinary attacks that hit ordinary businesses stop working on you, that you can answer a cyber-insurance questionnaire or a client security review honestly, and that when something does go wrong you find out quickly and recover from a backup you have already tested. I work onsite by appointment across Dallas and the metroplex and remotely anywhere in Texas. If you want a straight assessment of which of the seven you already have, tell me a bit about your setup and I will walk through it with you.

Questions people ask

Is a small Dallas business really a target?

Most attacks are not aimed at anyone in particular. Automated scanning and mass phishing hit whatever answers, and a small business with weak sign-in security is easier to monetise than a large one with a security department. You are rarely targeted by name. You are targeted by being reachable and unprotected, which is exactly what the basics fix.

We already pay for Microsoft 365. Does that cover security?

It includes most of the tools, and that is the good news. Multi-factor authentication, email filtering, device management and encryption are largely in the subscription you already have. The gap is almost always configuration: features that ship off, admin accounts with no MFA, and no backup of the data itself. Turning on what you own is usually the cheapest improvement available.

How often should staff have security training?

Little and often beats an annual session. A two-minute note when a convincing phishing message actually reaches your office teaches more than an hour of generic video, because it is real and it is yours. Add a short walkthrough for every new hire, and one clear rule that any change to bank details is confirmed by phone on a known number.

What is the single most important thing if I can only do one?

Multi-factor authentication on email, for everyone including the owner. Email is the account that resets every other account, it is the account criminals want most, and MFA is included in what you already pay for. It takes a few minutes per person. Nothing else on the list gives you as much protection for as little effort or money.

Do we need cyber insurance, and will this help us get it?

Whether to buy a policy is a business decision for you and your broker. What I can tell you is that carriers now ask direct technical questions about multi-factor authentication, backups, endpoint protection and admin access before they quote. Having the basics genuinely in place helps you meet those requirements and answer the questionnaire honestly, which is the part that matters at claim time.

How long does it take to get these basics in place?

For a typical ten-person office, the configuration work is a few days spread over a couple of weeks, most of it done remotely and outside working hours. MFA enrollment is the part that needs your people, and it is a few minutes each. Backup and patching then run continuously rather than as a project, which is the point of them.

Anthony Omini

Written and reviewed by

Anthony Omini, founder of Cross River Tech

Over 15 years in IT across many industries, now running Cross River Tech, a small owner-led managed IT company in Dallas. Every article is written from his own client work and checked by him before it is published.

Want to know which of the seven you already have? Tell me how many people you have and what you run. I will go through the short list with you and tell you plainly what is missing.

Let's fix it — or plan it.

Call, or send a short request and I will get back to you personally.

Call now Get a quote

Free, no-obligation quote

Tell me what is going on

Three quick steps. I read every request myself and reply personally, usually the same business day.

What can I help with?

Pick the closest option. There is room to explain in a moment.

or call (214) 612-7080