Skip to content

Practical guidance

Know what to fix before buying bigger security tools.

CyberBit focuses on practical website, email, domain, cloud-account, and cybersecurity foundation support for small businesses. The goal is to identify owner-actionable risks and give providers clear next steps.

This hub is educational, but it is not generic blog filler. Each section points back to a business decision: what can you check yourself, what should a provider fix, and when is the $199 Snapshot the cleaner first paid step?

Start here

A simple learning path before you buy anything.

Use this page to understand the basics, run a safe public check, and decide whether you need a paid review, cleanup help, monitoring, or questionnaire support.

1

Understand your public risk

Start with the visible signals customers, browsers, email providers, vendors, and insurers can already see.

Use the checklist
2

Check website, email, and domain basics

Use the free public check for a quick look at HTTPS, redirects, security headers, DNS, SPF, and DMARC indicators.

Run free public check
3

Decide what to fix first

If you want CyberBit to review the signals and give you a fix order, use the Website, Email & Domain Security Snapshot and compare the sample report.

Start $199 Snapshot

Common small-business risks

What to review before it becomes a vendor, customer, or insurance problem.

These checks are practical starting points, not guarantees. They help owners spot hidden setup issues and decide whether a Snapshot, cleanup sprint, service provider, or internal follow-up is needed.

Risk area

Email spoofing and DMARC

Attackers may try to send fake invoices, payment changes, or vendor messages that appear to come from your domain.

What to check

  • Confirm SPF exists and does not include unknown senders
  • Confirm DKIM is enabled for Microsoft 365, Google Workspace, and marketing tools
  • Review DMARC before moving from monitoring to enforcement

The Snapshot explains visible email-authentication gaps and turns them into vendor-ready next steps.

Review related guidance

Risk area

Weak DNS and security headers

Missing or inconsistent DNS, HTTPS, redirect, and browser-header settings can make a site harder to trust and harder to hand off.

What to check

  • Identify the registrar, DNS host, website host, and CDN
  • Check HTTPS, redirects, HSTS, CSP, frame protection, and MIME sniffing protections
  • Document who can safely make DNS and website-header changes

The Snapshot separates quick public-signal fixes from items that need a web host, DNS provider, or developer.

Review related guidance

Risk area

Website exposure

Old pages, exposed forms, unsafe redirects, or unclear platform ownership can create business risk before anyone contacts you.

What to check

  • Review contact, booking, payment, and intake forms
  • Remove stale pages, demo content, abandoned plugins, and unused integrations
  • Confirm the site owner has access to hosting, forms, analytics, and backups

The Snapshot gives a practical website-risk summary and points to cleanup, redesign, takeover, or vendor handoff when needed.

Review related guidance

Risk area

Admin and login exposure

Admin accounts, shared passwords, unmanaged MFA, and old vendor access often create the easiest path into critical business systems.

What to check

  • Require MFA for email, website, domain, payment, payroll, and cloud admins
  • Remove former staff, old vendors, and unused admin users
  • Avoid sending passwords, recovery codes, API keys, or secrets through forms or email

The Snapshot flags public-facing ownership and admin-risk questions to resolve before deeper cleanup.

Review related guidance

Risk area

Outdated plugins and platforms

Outdated CMS, plugin, theme, booking, or form platforms can turn a small website issue into a larger cleanup or takeover project.

What to check

  • List the CMS, plugins, themes, form tools, booking tools, and payment links
  • Remove unused plugins and abandoned integrations
  • Confirm update responsibility and backup/restore process

The Snapshot helps decide whether the right next step is simple cleanup, a secure redesign, or a focused takeover sprint.

Review related guidance

Risk area

Vendor questionnaire readiness

Client, insurer, and vendor questionnaires can create risk when answers claim controls that are not actually in place.

What to check

  • Gather evidence for MFA, backups, email authentication, access controls, and vendor ownership
  • Separate confirmed controls from planned or provider-dependent work
  • Avoid claiming compliance certification or guaranteed protection

The Snapshot creates a cleaner fact base before a questionnaire or a separate Client/Vendor Security Questionnaire Support engagement.

Review related guidance

Risk area

Basic incident prevention

Small businesses often lose time during an incident because account ownership, backups, contacts, and provider responsibilities are unclear.

What to check

  • Document who controls domain, DNS, website, email, cloud, billing, and recovery settings
  • Test at least one important restore path
  • Write a short internal contact plan for suspicious email, payment changes, or account alerts

The Snapshot is not incident response, but it gives a practical prevention roadmap and a clearer fix order.

Review related guidance

Start with your question

Choose a topic, then learn, check, or get the right kind of help.

This navigator uses existing guides, free checks, and service routes. It keeps personal concerns separate from business requests and does not route every question to the Snapshot.

Selected topic

Website and forms

Understand public website, HTTPS, browser-header, form, and ownership basics.

28 practical topics available. Use the filters to narrow by area.

Email Security

Business Email Security

Reduce the chance that criminals can impersonate your domain, abuse business email, or trick staff and customers.

Why it matters

Email compromise and domain spoofing can lead to invoice fraud, fake messages, and lost trust.

Who should review it

Businesses that send email from their own domain or rely on Microsoft 365 / Google Workspace.

What to check

  • Check SPF, DKIM, and DMARC records
  • Turn on MFA for mailbox/admin accounts
  • Review forwarding rules and suspicious inbox filters
  • Use a separate admin account where possible

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Email Security

SPF, DKIM, and DMARC Basics

These email authentication records help receiving mail systems decide whether messages using your domain are allowed and trustworthy.

Why it matters

Weak or missing authentication can make spoofing, invoice fraud, and questionnaire follow-up harder to manage.

Who should review it

Businesses that send email from a company domain through Microsoft 365, Google Workspace, marketing tools, invoicing systems, or website forms.

What to check

  • List every service that sends email for the domain
  • Confirm SPF exists and does not include unknown senders
  • Enable DKIM for each legitimate sender where available
  • Publish DMARC in monitoring mode before enforcing stricter policy

When to ask for help

  • You are not sure which services send email for the domain
  • DMARC reports show failures you cannot explain

Email Security

DMARC in Plain English

DMARC helps domain owners tell receiving mail systems what to do when someone tries to send email that fails SPF or DKIM checks. For small businesses, it is one of the clearest public signals that business email has been reviewed.

Why it matters

Weak or missing DMARC can make it easier for criminals to spoof a domain and send fake invoices, vendor messages, or staff impersonation emails.

Who should review it

Businesses using Microsoft 365, Google Workspace, or any service that sends email from the company domain.

What to check

  • Confirm SPF exists and includes only legitimate senders
  • Enable DKIM for Google Workspace, Microsoft 365, Resend, or other senders
  • Publish DMARC and monitor results before moving to stricter enforcement
  • Review reports before changing policies to reject
  • Consider subdomains and third-party senders before tightening policy

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Website Security

Website & Domain Security

Keep your public website, contact forms, booking links, and trust signals from becoming easy business risk.

Why it matters

Website and domain gaps can create trust issues before a customer, patient, or client ever calls.

Who should review it

Businesses with websites, contact forms, booking pages, payment links, or client intake forms.

What to check

  • Confirm HTTPS works on the public website
  • Review DNS records and domain renewal ownership
  • Check basic security headers and public form handling
  • Remove unused plugins, pages, and old admin users

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Website Security

Security Headers Explained

Security headers are browser instructions that help reduce common website risks such as clickjacking, unsafe content loading, MIME sniffing, and overly broad browser permissions.

Why it matters

Headers do not make a site invincible, but missing or weak headers are visible signals that a site may need safer browser-side defaults.

Who should review it

Businesses with public websites, booking pages, client portals, forms, or embedded third-party tools.

What to check

  • Confirm HSTS only after HTTPS is stable
  • Add CSP carefully and test forms, images, payments, and analytics before tightening
  • Use X-Frame-Options or frame-ancestors to reduce unwanted framing
  • Review Referrer-Policy and Permissions-Policy so pages share less browser context

When to ask for help

  • A scanner reports missing headers and the web host, CDN, and developer disagree about ownership
  • A CSP change could break scripts, forms, checkout, booking, or embedded widgets

Website Security

HTTPS, SSL, and TLS Basics

HTTPS is the secure browser connection people expect before submitting forms, booking appointments, or trusting a business website.

Why it matters

Broken HTTPS, mixed content, or missing redirects can make a legitimate website look unsafe and can confuse customers or providers.

Who should review it

Any business with a public website, contact form, booking flow, payment link, or customer intake path.

What to check

  • Confirm the main website loads over HTTPS
  • Confirm HTTP redirects to HTTPS
  • Check that the certificate matches the right domain
  • Ask the host or web provider to fix certificate or redirect warnings

When to ask for help

  • Browsers show certificate warnings or redirect loops
  • Multiple providers disagree about who owns the fix

Foundations

DNS Exposure and Ownership

DNS records route website, email, verification, and vendor services. Owners should know who can change them and why each record exists.

Why it matters

Unclear DNS ownership can delay security fixes, email changes, website launches, and vendor handoffs.

Who should review it

Businesses that inherited a domain, changed vendors, use multiple marketing/email tools, or are not sure where DNS is hosted.

What to check

  • Identify the registrar and DNS host
  • List major DNS records and what provider each one supports
  • Remove stale verification records after confirming they are no longer needed
  • Require MFA for accounts that can change DNS

When to ask for help

  • Nobody knows who controls DNS or renewal settings
  • A vendor asks for DNS changes and the business cannot verify impact

Foundations

WHOIS and Domain Information

WHOIS and registrar information can help owners understand who manages a domain, when it renews, and whether privacy, DNSSEC, and contact details need review.

Why it matters

Domain ownership problems can interrupt website and email service, delay DNS changes, and make vendor handoff harder.

Who should review it

Businesses that inherited a domain, switched vendors, missed renewal notices, or are unsure who controls the registrar account.

What to check

  • Identify the registrar and account owner
  • Confirm renewal status and auto-renew settings
  • Use registrar privacy where appropriate, while keeping internal ownership records clear
  • Document DNSSEC status and registrar-lock options before changing providers

When to ask for help

  • The domain is under an old vendor, employee, or unknown account
  • Renewal, privacy, DNSSEC, or registrar-lock status is unclear

Foundations

DNS, VPN, and WebRTC Visibility

Browser and network checks can show what websites may see about your current connection, including public IP, IP version, and browser-exposed WebRTC candidates.

Why it matters

These signals do not prove anonymity, but they help users understand whether a network change appears to be visible to websites.

Who should review it

Owners and staff who use VPNs, remote work networks, shared Wi-Fi, hotspots, or browsers with WebRTC enabled.

What to check

  • Check your public IP before and after enabling a VPN
  • Run the IP, DNS & WebRTC Connection Check to review basic browser and WebRTC signals
  • Use your VPN provider's own diagnostic page for resolver-specific validation
  • Treat mDNS .local WebRTC results as privacy protection, not a failure

When to ask for help

  • VPN behavior differs across browsers or devices and staff need plain-English guidance
  • A business needs remote-access cleanup rather than a consumer anonymity test

Foundations

Public IP, IPv4, IPv6, and CGNAT

A public IP is the network address websites see. It may be IPv4, IPv6, a VPN/proxy address, a mobile network, or a carrier-grade NAT address managed by an ISP.

Why it matters

Knowing what IP version and network are visible helps owners avoid confusing a normal provider change with a security issue.

Who should review it

Anyone troubleshooting VPNs, remote work, office networks, website allowlists, provider tickets, or suspicious sign-in alerts.

What to check

  • Run the IP, DNS & WebRTC Connection Check
  • Compare results on office Wi-Fi, mobile hotspot, and VPN
  • Ask the ISP or IT provider whether the address is static, dynamic, or behind CGNAT when allowlisting matters
  • Check IPv6 behavior separately because some VPNs handle IPv6 differently

When to ask for help

  • A vendor asks for IP allowlisting and the business does not know whether the address changes
  • IPv6 behaves differently from IPv4 when VPN, firewall, or remote access is enabled

Access Control

Admin and Login Exposure

Reduce risk from exposed admin paths, old vendor access, weak MFA coverage, and unclear account ownership.

Why it matters

A small number of overpowered accounts often control the website, email, DNS, payments, forms, and customer communication.

Who should review it

Businesses with website admins, domain/DNS admins, payment tools, cloud accounts, booking systems, former staff, or outside vendors.

What to check

  • Require MFA for website, domain, DNS, email, payment, payroll, and cloud administrator accounts
  • Remove old staff, contractor, and vendor accounts
  • Document who owns each admin account and recovery path
  • Avoid sending passwords, recovery codes, API keys, or secrets through forms or email

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Website Security

Outdated Plugins and Platform Risk

Review CMS, plugin, theme, form, booking, payment-link, and website platform exposure before small maintenance gaps become cleanup projects.

Why it matters

Outdated website components and unmanaged integrations can create trust, maintenance, and security problems that are harder to fix during a vendor handoff.

Who should review it

Businesses using WordPress, website builders, booking widgets, form plugins, marketing scripts, payment links, or vendor-managed sites.

What to check

  • List the CMS, plugins, themes, form tools, booking tools, payment links, and marketing integrations
  • Remove unused plugins, abandoned integrations, demo content, and old admin users
  • Confirm who updates the platform and who can restore the site
  • Use a Snapshot to decide whether cleanup, redesign, takeover, or vendor handoff is the right next step

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Website Security

Forms and Spam Protection

Contact, booking, newsletter, quote, and intake forms should collect only needed information and reduce automated abuse without blocking real customers.

Why it matters

Poor form handling can flood inboxes, expose sensitive requests, or train staff to ignore legitimate messages.

Who should review it

Businesses with public forms, booking widgets, quote forms, newsletters, lead magnets, or customer intake pages.

What to check

  • Keep public forms short and avoid sensitive fields
  • Use honeypots, rate limits, and neutral success responses for spam
  • Do not ask for passwords, private keys, payment cards, or customer records
  • Review where form notifications and stored submissions go

When to ask for help

  • Form spam is flooding the inbox or hiding real requests
  • A form asks for sensitive information it should not collect

Access Control

Domain Registrar Access and MFA

The registrar controls the domain registration and can affect the website, email, DNS, renewal, and ownership recovery path.

Why it matters

A lost or compromised registrar account can interrupt website and email operations or make recovery difficult.

Who should review it

Owners, office managers, web vendors, and IT providers responsible for domain renewal or domain-level changes.

What to check

  • Confirm the registrar name and billing owner
  • Turn on MFA for registrar administrators
  • Remove old vendor or staff access
  • Document recovery email, phone, and renewal contact details

When to ask for help

  • The domain is registered under an old vendor or employee account
  • Renewal, recovery, or ownership details are unclear

Vendor Risk

Client/Vendor Security Questionnaire Support

Prepare a supportable Client/Vendor Security Questionnaire Support Package when a client, customer, partner, or vendor due-diligence team asks about security controls. Insurance applications and renewals use the separate Cyber Insurance Evidence Review.

Why it matters

Unsupported questionnaire answers can create business risk and follow-up work if evidence does not match reality.

Who should review it

Businesses that use software vendors, payment processors, booking tools, IT providers, marketing agencies, payroll platforms, or outsourced staff.

What to check

  • Identify what the questionnaire is really asking
  • Collect evidence for MFA, backups, access, policies, and vendors
  • Avoid claiming controls that are not actually in place
  • Use plain-English notes for owner or IT provider approval

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Insurance Readiness

Cyber Insurance Readiness Questions

Plain-English guidance on common cyber insurance application topics such as MFA, backups, email authentication, admin access, and vendor documentation. This is not legal, insurance, or compliance advice.

Why it matters

Owners need to understand what insurers commonly ask for before claiming controls or submitting unsupported answers.

Who should review it

Small businesses preparing for cyber insurance applications, renewals, broker questions, or insurer follow-up requests.

What to check

  • Identify MFA coverage for business email, admin accounts, and key systems
  • Confirm backups exist and know who can restore critical files
  • Review SPF, DKIM, DMARC, and basic email-security evidence
  • Collect vendor-ready notes for IT, web, DNS, email, and software vendors

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Foundations

Security Priorities

A practical starting point for deciding what to review first when everything feels important.

Why it matters

Owners need a short, defensible fix order before spending time or money on deeper security work.

Who should review it

Every small business with email, a website, online payments, client records, or cloud accounts.

What to check

  • List the accounts, website, email provider, and files that matter most
  • Turn on MFA for owner, email, banking, payroll, and admin accounts
  • Confirm backups exist and at least one restore has been tested
  • Use a Snapshot when you need a prioritized public-facing review

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Website Security

Website Redesign Security Checklist

Security and ownership basics to include when rebuilding an outdated or confusing small-business website.

Why it matters

A redesign is the best time to clean up SSL/TLS, forms, admin access, domain/DNS ownership, and vendor handoff before old issues are rebuilt into the new site.

Who should review it

Businesses replacing a website, changing platforms, adding forms, or hiring a new web vendor.

What to check

  • Confirm who controls the domain, DNS, website hosting, and forms
  • Review HTTPS, redirects, and security headers before launch
  • Document admin accounts and MFA
  • Keep launch and owner handoff notes

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Foundations

Domain and Email Ownership Checklist

A plain-English checklist for identifying who controls the domain, DNS, email provider, senders, and account recovery paths.

Why it matters

When ownership is unclear, website, email, and security fixes take longer and can become risky during vendor transitions.

Who should review it

Owners who inherited a website, changed vendors, or are not sure where DNS and email settings live.

What to check

  • Identify the domain registrar and DNS provider
  • List the website host, email provider, and major senders
  • Confirm admin accounts and MFA status
  • Document renewal contacts and recovery paths

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Foundations

Vendor Handoff Checklist

A checklist for taking over from a web, DNS, email, marketing, or IT provider without guessing who owns what.

Why it matters

A clean handoff reduces lockout risk and makes the next provider conversation more concrete.

Who should review it

Businesses switching vendors, recovering from poor handoff, or cleaning up a messy existing setup.

What to check

  • Collect provider names and account owners
  • Confirm authorization before requesting or changing access
  • Document domains, DNS zones, hosting, forms, email, and admin accounts
  • Avoid sending passwords through email or forms

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Cloud Accounts

Microsoft 365 / Google Workspace

Tighten the basic account and sharing controls around the cloud workspace where your daily work happens, with a focused Workspace Security Baseline Report when you need help.

Why it matters

A compromised cloud account can expose client records, invoices, contracts, employee data, and internal files.

Who should review it

Businesses using Microsoft 365, Outlook, Gmail, Google Workspace, SharePoint, OneDrive, or Google Drive.

What to check

  • Require MFA for all users
  • Review admin users and shared mailboxes
  • Disable unused accounts quickly
  • Check external sharing settings

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Scam Prevention

Scams & Phishing

Build simple habits that help owners and staff slow down suspicious invoices, links, texts, and urgent requests.

Why it matters

Payment-change scams and fake login messages can move quickly if staff do not have a simple verification habit.

Who should review it

Owners, office managers, finance staff, receptionists, and anyone who handles email, invoices, texts, or calls.

What to check

  • Verify payment and bank-change requests out of band
  • Train staff to pause before opening links or attachments
  • Report suspicious messages internally
  • Use MFA so stolen passwords are less useful

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Resilience

Backups & Recovery

Make sure important business files can be restored after deletion, device loss, account compromise, or ransomware.

Why it matters

Recovery planning keeps a bad day from becoming a long business interruption.

Who should review it

Businesses that store documents, customer records, invoices, images, contracts, schedules, or operational files.

What to check

  • Identify critical files, systems, and cloud accounts
  • Use cloud backup, versioning, or another documented backup path
  • Test restoring a file before there is an emergency
  • Document who to call if systems go down

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Access Control

Passwords, MFA & Offboarding

Reduce risk from old accounts, shared passwords, overpowered admin access, and unmanaged staff changes.

Why it matters

Old accounts, shared passwords, weak passwords, and unnecessary admin access create easy entry points.

Who should review it

Any business with employees, contractors, vendors, shared accounts, or former staff.

What to check

  • Use a password manager
  • Avoid shared passwords where possible
  • Remove access immediately when someone leaves
  • Give admin access only when needed

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Scam Prevention

Personal Cybersecurity for Owners

Protect the owner and key decision-makers whose personal email, phone, and recovery settings often control business access.

Why it matters

Owner account compromise can affect business email, banking, domain access, social media, and customer communication.

Who should review it

Owners, partners, office managers, and family members who control business accounts, payments, devices, or recovery emails.

What to check

  • Secure the primary personal email account first
  • Turn on MFA for identity, banking, phone, and cloud accounts
  • Review recovery emails, phone numbers, and unknown devices
  • Do not send passwords, recovery codes, SSNs, or bank details through forms

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Resilience

External Security Watch

Keep website, domain, email, and public-facing security signals from drifting after a Snapshot, cleanup, rebuild, takeover, or agreed baseline.

Why it matters

Basic security hygiene can drift when domains, email tools, websites, vendors, and staff access change over time.

Who should review it

Small businesses that want scoped monthly website and public-facing security oversight without buying a full MSP, helpdesk, SOC, or MDR.

What to check

  • Document the baseline after fixes are complete
  • Review public domain, email, and website signals on a cadence
  • Track follow-up items, ownership, and vendor-ready notes
  • Use External Security Watch for scoped oversight, not 24/7 monitoring

When to ask for help

  • You are not sure who owns the setting or provider account
  • A client, vendor, insurer, or provider needs clearer evidence

Resilience

Incident and Account Compromise Triage Boundaries

Owners should know what to do first when an account, email, domain, or website looks suspicious, and when CyberBit's standard services are not emergency incident response.

Why it matters

Clear boundaries prevent delayed emergency action and keep routine cleanup separate from active incident handling.

Who should review it

Businesses seeing suspicious inbox rules, unknown admin users, payment-change messages, website defacement, or provider alerts.

What to check

  • Preserve suspicious messages, timestamps, and provider alerts
  • Change passwords and revoke sessions only through trusted provider guidance
  • Contact the affected provider, bank, insurer, or legal adviser when appropriate
  • Use cleanup or Snapshot only after immediate safety and ownership questions are stable

When to ask for help

  • Money movement, customer data, or active account compromise may be involved
  • You need emergency response beyond public-signal review or cleanup planning

Foundations

Safe Handoff to IT or Web Providers

A safe handoff gives the right provider enough context to fix website, email, DNS, and account issues without passing secrets around casually.

Why it matters

Clean handoff notes reduce lockout risk, duplicated work, and unsupported changes to critical settings.

Who should review it

Businesses switching web vendors, IT providers, marketing agencies, website platforms, or email providers.

What to check

  • List current providers and account owners
  • Confirm authorization before access changes
  • Share vendor-ready notes instead of passwords in email
  • Document what changed, who changed it, and what still needs follow-up

When to ask for help

  • A provider asks for broad admin access without explaining why
  • You need a prioritized fix order before assigning work

Next steps

Pick the right path after reading.

The Snapshot is the default paid diagnostic. Use services, cleanup, or contact when you already know what needs to happen or have a deadline-driven request.

Website, Email & Domain Security Snapshot - $199

Best first paid step when you want a plain-English report, prioritized findings, and vendor-ready next steps.

Sample report

Preview the type of findings, business-risk explanations, and recommended fix order CyberBit provides.

Services

Compare the $750 cleanup path, Business Security Remediation Sprint From $1,500, External Security Watch $99/month or From $499/month, and questionnaire support.

Business Security Remediation Sprint - From $1,500

Use this when you already know the gaps and need implementation, provider coordination, or cleanup documentation.

Ask CyberBit

Contact CyberBit when you have a deadline, vendor question, insurance request, or are unsure which service fits.

Need questionnaire-specific support? Client/Vendor Security Questionnaire Support — From $1,500. Need ongoing public-signal oversight after fixes? View External Security Watch.

What to check first

A practical small-business security checklist.

This is a plain-English starting point, not a full audit. It helps you organize website, email, domain, admin, and vendor questions before asking someone to make changes.

The Snapshot uses an 11-check Snapshot model, but this checklist is free guidance and does not equal a complete Website, Email & Domain Security Snapshot report.

Is the website reachable over HTTPS?

Does HTTP redirect visitors to HTTPS?

Are basic browser security headers present?

Are SPF and DMARC present for the sending domain?

Is DMARC only monitoring, or is it moving toward enforcement after review?

Do you know who controls DNS and the domain registrar?

Are admin/login pages intentionally public and protected?

Is MFA enabled for domain, email, website, and cloud administrator accounts?

Do you know who can change website, email, DNS, form, and payment-link settings?

Can you explain the setup to a client, vendor, insurer, or security questionnaire reviewer?

Do you have a clean fix order before asking a provider to make changes?

Common problems by business type

Different businesses run into different security questions.

These are practical examples, not client claims or guarantees. Use them to decide where to start.

Dental or medical office

Common risk

Patient-facing forms, online scheduling, email, and vendor portals often depend on multiple providers.

Why it matters

Ownership confusion can slow down secure fixes and make insurance or vendor questions harder to answer.

Start with the Free Website, Email & Domain Check or Website, Email & Domain Security Snapshot, then use cleanup help if website/email/DNS changes are needed.

Start $199 Snapshot

Law or accounting firm

Common risk

Email spoofing, document sharing, client portals, and vendor questionnaires can create trust and evidence gaps.

Why it matters

Clients may ask for clear answers about MFA, backups, email authentication, access, and provider controls.

Review DMARC and admin access first, then compare Client/Vendor Security Questionnaire Support if a client request is active.

View questionnaire support

Contractor or local services business

Common risk

A basic website, branded email, booking forms, and payment-change messages can all affect customer trust.

Why it matters

Missing HTTPS, weak email authentication, or old vendor access can make scams and handoff problems more likely.

Use the public check for quick signals, then request Focused Security Cleanup if fixes are already clear.

View cleanup service

Ecommerce or online store

Common risk

Plugins, redirects, forms, checkout links, tracking scripts, and admin access can drift as tools change.

Why it matters

A small website change can affect customer confidence, payment flow, and vendor handoff notes.

Use the Snapshot for a prioritized review before cleanup, redesign, or provider coordination.

Start $199 Snapshot

Nonprofit or community organization

Common risk

Shared admin access, volunteer turnover, donation links, and old web vendors can leave ownership unclear.

Why it matters

Clear access and recovery notes reduce disruption when people or providers change.

Start with domain, DNS, email, MFA, and handoff checks before any redesign or cleanup work.

View cleanup sprint

Startup or vendor-facing business

Common risk

Clients may ask for questionnaire answers before the security evidence is organized.

Why it matters

Unsupported answers can create follow-up work and credibility problems later.

Use the Snapshot to establish the facts, then use Client/Vendor Security Questionnaire Support for answer drafting and gaps.

View questionnaire support

Glossary

Plain-English cybersecurity terms owners actually see.

Use these definitions when a provider, insurer, vendor, or questionnaire uses technical language.

DNS

The settings that tell the internet where your website, email, and other domain services live.

Registrar

The company where your domain is registered and renewed. Registrar access should use MFA.

SPF

An email record that lists which services are allowed to send mail for your domain.

DKIM

An email signature method that helps prove a message was authorized by your sending service.

DMARC

A policy that tells mail receivers what to do when SPF or DKIM checks fail for your domain.

HTTPS

The secure website connection browsers expect before users submit forms or trust a site.

SSL/TLS

The encryption technology behind HTTPS. Owners usually see this as the website certificate.

Security headers

Browser instructions that reduce common web risks such as framing, sniffing, or unsafe loading.

MFA

Multi-factor authentication. It adds a second proof beyond a password for important accounts.

Admin exposure

Login or administrator areas that are reachable publicly and need intentional protection.

Vendor questionnaire

A client or partner form asking what security controls your business has in place.

Public-signal review

A safe review of what can be checked from outside, without passwords, exploit testing, or private access.

FAQ

Small-business cybersecurity questions

Is this a penetration test?

No. The Cybersecurity Center, free public check, and Website, Email & Domain Security Snapshot focus on safe public-signal review, business context, and practical remediation guidance. Authorized testing of a customer-controlled custom application is a separate specialized service with written scope and Rules of Engagement.

What can I check myself first?

Start with HTTPS, HTTP-to-HTTPS redirects, basic security headers, SPF, DMARC, domain registrar ownership, DNS ownership, admin MFA, old vendor access, and whether you can explain who controls website, email, and DNS changes.

What should I never submit in a form?

Do not submit passwords, recovery codes, API keys, private keys, payment details, customer records, medical records, legal files, or private screenshots through public forms. CyberBit can start with public signals and non-sensitive business context.

What is DMARC?

DMARC is an email-domain policy that helps receiving mail systems decide what to do when a message claiming to be from your domain fails SPF or DKIM checks. It should be reviewed carefully before moving from monitoring to stricter enforcement.

What are security headers?

Security headers are browser instructions sent by a website. They can help reduce risks such as clickjacking, unsafe content loading, MIME sniffing, and overly broad browser permissions.

Why does Client/Vendor Security Questionnaire Support matter?

Vendor questionnaires often ask for evidence around MFA, backups, access control, policies, vendors, and email security. Support helps organize accurate answers and identify gaps without promising vendor approval.

Should I start with the Free Website, Email & Domain Check or the Snapshot?

Use the free public check when you want quick public signals. Use the $199 Website, Email & Domain Security Snapshot when you want CyberBit to review the 11 areas, explain business impact, prioritize findings, and give vendor-ready next steps.

What if I already know something is broken?

If the issue is clear, compare Focused Security Cleanup or Business Security Remediation Sprint instead of buying a diagnostic first. If you still need a fix order or plain-English report, start with the Snapshot.

Can this help with cyber insurance questions?

It can help you understand common control questions and organize vendor-ready notes, but it does not guarantee insurance approval, lower premiums, compliance status, or acceptance by an insurer.

What happens after a Snapshot?

You can share the report with your website, DNS, email, IT, or software provider. If you want CyberBit to help implement fixes, the next step may be Focused Security Cleanup, Business Security Remediation Sprint, External Security Watch, or Client/Vendor Security Questionnaire Support.

Prioritize the work

Want a prioritized review instead of guessing?

The Website, Email & Domain Security Snapshot gives you a plain-English report with public-facing findings, severity, business impact, recommended fixes, and next steps for cleanup, redesign, workspace setup, External Security Watch, questionnaire support, or vendor handoff.

Scope note

CyberBit Solutions LLC provides practical website, email, domain, cloud-account, and cybersecurity foundation guidance for small businesses. This page is general guidance, not penetration testing, breach detection, compliance certification, legal advice, incident response, or a guarantee of security.