The 5 Security Moves Every Founder Should Make Before Hiring IT
You built something worth protecting. Here’s how to protect it, in plain English, without an IT department.

Most small companies don’t get breached because attackers are brilliant. They get breached because nobody locked the front door.
Attackers aren’t hunting Fortune 500s. They’re hunting companies like yours — because companies like yours are easier.
Here’s the good news: most of what actually works is simple, affordable, and doable this week. These five moves stop the vast majority of real-world incidents we’ve seen across 13 years of protecting small businesses in Reno, Tahoe, and beyond.
Start at the top. Each move matters more than the one below it.
Turn on multi-factor authentication. Everywhere. Correctly.
Stops: stolen passwords becoming stolen companiesYour password will leak eventually. A vendor gets breached, someone reuses a password, a phishing email lands. MFA means a stolen password alone gets an attacker nothing.
Do this
- Turn on MFA for email first. Email is the master key to everything else.
- Then banking, payroll, cloud storage, and your website admin.
- Use an authenticator app, not text messages, wherever possible.
- No exceptions for the boss. Owner accounts are the #1 target.
Protect your email like it’s your bank account. It is.
Stops: business email compromiseForget hackers in hoodies. The most expensive attack looks like a normal email: a vendor “updating” their bank details, your bookkeeper getting a rushed wire request that looks like it came from you. One reply, one wire, six figures gone.
Do this
- Add advanced email filtering on top of what comes built in. Built-in filters miss the good fakes.
- Make one rule and never break it: any change to payment details gets verified by phone, using a number you already have — not one from the email.
- Tell your people about that rule. Then remind them quarterly.
Back up your data. Then prove the backup works.
Stops: ransomware turning into a company-ending eventHere’s what surprises most founders: your cloud data isn’t backed up just because it’s in the cloud. Microsoft and Google keep your services running. Recovering your deleted or encrypted files is your job, not theirs.
Do this
- Back up cloud data (email, files, accounting) to a separate service.
- Automate it. Backups that depend on someone remembering will fail.
- Test a restore twice a year. A backup you’ve never restored is a hope, not a plan.
Put real protection on every device.
Stops: one infected laptop taking down everything it touchesTraditional antivirus reacts after infection. Modern endpoint protection (EDR) watches how programs behave and stops attacks it has never seen before. The difference matters because new attacks are the ones that get through.
Do this
- Put EDR on every computer that touches company data — including that one personal laptop everyone forgot about.
- Keep devices updated. Unpatched software is now the #1 way attackers get in, per Verizon’s 2026 report.
- Turn on automatic updates and stop postponing restarts.
Know your first three phone calls.
Stops: a bad day becoming a fatal oneIncidents get expensive in the first hours, when nobody knows who decides, who calls the bank, or whether to shut systems down. A one-page plan beats a 40-page binder nobody reads.
Do this
- Write down: who to call first (your IT partner or security contact), your bank’s fraud line, and your cyber insurance carrier if you have one.
- If money moved, call the bank immediately. Recalls sometimes work in the first hours. Rarely after.
- Don’t wipe or reboot affected machines. You may destroy the evidence needed to recover.
- Report it at ic3.gov. It helps you and everyone after you.

Save this · Screenshot this
Your One-Week Founder Security Checklist
Seven days. One move a day. By the end, you’re ahead of most companies your size.
MFA on email, banking, and payroll. Authenticator app, not text.
Set the phone-verification rule for any payment changes. Tell your people.
Add advanced email protection beyond the built-in filters.
Set up automated cloud backup. Schedule a restore test on the calendar.
Get EDR on every device. Turn on automatic updates.
Write your one-page incident plan. Three phone numbers minimum.
Rest. You’re now ahead of most companies your size.
Want a second set of eyes on your setup?
You can do everything on this page yourself, and we hope you do. If you’d rather have someone check your work — or you’ve outgrown doing it yourself — that’s what we’re here for.
Tahoe Tech Group has been the technology partner for small and mid-sized businesses across Reno, Tahoe, and Northern Nevada since 2013. We handle the threats, the updates, and the headaches so your people can focus on what they do best.
Get a Free Security AssessmentOr call us: NV (775) 831-1141
Carl LeBlanc is the founder and owner of Tahoe Tech Group. He speaks regularly on cybersecurity for founders and small business owners, most recently at Reno Startup Week 2026.