Somewhere right now, a program is scanning the internet for a firewall that still has its factory password. It doesn't know your company's name or how many people you employ. It only needs to find one unlocked door, and AI tools now help attackers check far more doors, far faster.
This post explains the new cyber hygiene guide from the National Security Agency, the agency that protects the government's most sensitive networks, and which steps fit a business your size.
On September 3, 2026, the NSA released its Best Practices Guide for Cyber Hygiene. Cyber hygiene means the routine habits that keep your systems hard to break into, like updating software and locking down logins. The guide ranks those habits by how well they stop real attacks. It was written mainly for defense networks, but its first tier works as a starter checklist for almost any business.
In its press release, the NSA says attackers now use AI to "accelerate and scale" their attacks. They go after the same weak spots again and again: unpatched systems, weak logins, and settings left on their defaults. This is why the you need to fix the basics first, because the basics are what automated attacks look for.
The guide splits its advice into four tiers, numbered 0 through 3. Tier 0 covers what the NSA calls "high-impact, low-complexity actions." Tiers 1 through 3 move into automated response systems and red team exercises, where hired experts try to break into your network the way a real attacker would.
If your company has a few dozen employees and little or no in-house IT staff, Tier 0 is where your attention belongs. The higher tiers assume a full security team and a large budget. Tier 0 targets the recurring weak spots the NSA sees attackers exploit, and most of it is within reach for a lean team.
Here are the nine Tier 0 steps in plain English, with what each one looks like at a company with a lean IT setup. Treat the list as a starting point, since the NSA notes that these steps don't cover every possible attack.
Start with a complete list of everything on your network: computers, servers, printers, firewalls, software, user accounts, and where your data goes. The NSA calls this inventory "foundational," because you can't protect what you don't know you have. From there, limit who has admin rights, change every default password, and split your network into sections so one infected laptop can't reach everything.
Patches are software updates that fix security holes. The NSA names unpatched systems as a common way in for attackers. The guide says to update software right away and upgrade it on a schedule. Automating updates helps, but the NSA also says to check them. Someone should confirm the patches installed on servers and network gear, not only laptops.
Turn on multi-factor authentication (MFA), a login step that asks for a second proof of identity beyond your password, for every account. The NSA goes further and recommends phishing-resistant MFA, such as a physical security key. The guide lists weak MFA as a common problem. Some codes can be stolen through phishing or SIM swapping, a scam where someone takes over your phone number.
Most devices on your network keep logs, a running record of who logged in and what happened. A security information and event management (SIEM) system gathers those logs in one place and flags unusual activity. It only works if the logs actually reach it, so the NSA says to check that they do. A SIEM with missing logs has blind spots you won't see until something goes wrong.
Over time, networks collect extra pathways, like an old remote access rule or a vendor connection nobody turned off. Each one gives an attacker another way to move around once inside. The NSA recommends watching the connections between parts of your network and removing the ones you don't need.
You can't spot unusual behavior until you know what normal looks like. This step means recording typical network traffic and user activity, then setting alerts for anything outside it. Think of an employee account logging in at 3 a.m. from another country, or a user suddenly copying thousands of files. The NSA also recommends actively hunting for intruders instead of waiting for an alarm.
Endpoint detection and response (EDR) is security software on each computer and server that watches for suspicious behavior and can stop it. Installing EDR is only the start. The NSA says to refine its rules so it catches unusual activity in your specific environment. The guide also recommends connecting EDR to your threat hunting, so alerts lead to real investigation.
Application allowlisting means only software you've approved can run on your computers, and everything else is blocked. The NSA recommends it because a common attack starts when an employee clicks a phishing link and an unapproved program tries to launch. This is one of the harder steps for a small business, since every new tool needs approval. A practical first move is to start with servers and admin computers.
An incident response plan spells out who does what during an attack. It covers who gets called, which systems get shut off, and how you restore data. The NSA says to create the plan, practice it, and revise it. A plan nobody has opened won't help much during a ransomware attack at 2 a.m. on a Saturday. If an outside provider handles your security, make sure their role is written into the plan too.
You don't need to finish all nine steps this month. Start with the inventory, because every other step depends on it. Then turn on MFA and confirm your patching. The NSA names unpatched systems and weak logins among the problems attackers exploit most. Save allowlisting and activity baselines for after the basics are in place.
Next, figure out who owns each step. If you already pay an IT provider, ask them to show you where each Tier 0 item stands in your environment. You should get a clear answer for every one. If the answer is "we think so" or "that costs extra," you've found a gap.
Inzo Technologies® works with small and midsize businesses that want these basics handled without hiring a security team. From MFA, email filtering, and EDR, to SIEM monitoring and patch management, our managed IT program has cybersecurity integrated into every layer.
If you want to see where you stand today, let's grab 15 minutes for an Insight Session. No obligation or hard-sell, just a quick fit check to see how we can help you better understand your security posture.