What the Protect function covers
Access control: the highest-impact control
Security awareness training that works
Data security and platform hardening
Key Takeaways
TL;DR
Access control with MFA is the single highest-impact security control — implement it on every system before doing anything else.
Security awareness training does not need to be expensive; focus on phishing recognition, password hygiene, and incident reporting.
Encryption, email authentication (SPF/DKIM/DMARC), and security headers are critical data security controls that CDA verifies automatically.
Patch management and tested backups are foundational controls that prevent the most common attack outcomes.
Prioritize Protect controls based on your risk assessment — address the highest risks first rather than trying to do everything at once.
FAQ
Frequently asked questions
What is the single most important security control for a small business?
Multi-factor authentication (MFA) on all accounts. It stops the majority of credential-based attacks, which are the number one attack vector for small businesses. If you do nothing else, enable MFA on email, cloud applications, and any system accessible from the internet. It is free or low-cost with most business software.
How do I know if my encryption is properly configured?
Run a Cyber Defense Agent scan on your domain. CDA checks your TLS/SSL configuration, certificate validity, protocol versions, and cipher suites. It will flag weak encryption, expired certificates, or misconfigured TLS. For internal encryption (full-disk), check your operating system settings — BitLocker on Windows, FileVault on Mac.
Is free security awareness training effective?
Yes. Free resources from NIST, CISA, SANS, and KnowBe4 provide quality training content. What matters more than the platform is consistency: train annually, supplement with monthly micro-trainings, and run phishing simulations. A free program done consistently is far better than an expensive program done once and forgotten.
What security headers should my website have?
At minimum: Content-Security-Policy (CSP), HTTP Strict-Transport-Security (HSTS), X-Content-Type-Options: nosniff, X-Frame-Options: DENY or SAMEORIGIN, and Referrer-Policy. CDA checks for all of these and provides specific recommendations. Your web developer or hosting provider can implement them, usually in minutes.
Get your Cyber Defense Score™ in 60 seconds.
100 tools. No installation. No credit card. Real evidence.