Small business backups, Wi-Fi and firewall basics from NIST and CISA
NIST's small-business fundamentals (NISTIR 7621 Rev. 1) and the CISA Cyber Essentials Starter Kit give concrete day-to-day measures for a small office. Ask the assistant about backup schedules, network setup and the first actions a leader should take.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
Backups: frequency and storage
NISTIR 7621 Rev. 1 recommends a full, encrypted backup of each computer and mobile device at least once a month, shortly after a complete virus scan, plus an automatic incremental or differential backup at least once a week. Depending on how much data changes, daily or even hourly backups may be prudent.
Full backups should be stored away from the office in a protected place, so that a fire, flood or theft does not destroy them too. Keep the encryption key somewhere separate, and encrypt data before storing it in the cloud.
The guide suggests storage large enough for 52 weekly backups, which helps you recover from and trace incidents that were not noticed right away.
Wi-Fi, firewalls and the first leader actions
For a wireless router, NISTIR 7621 advises changing the default administrative password, not broadcasting the network name (SSID) and using WPA-2 with AES encryption, never WEP. Customer Wi-Fi should be separated from the business network.
It also recommends a hardware firewall between the internal network and the Internet, and an active, logging software firewall on each computer, including for employees working from home.
CISA's "booting up" actions start with inventories: the hardware and software on your network, the user accounts, vendors and partners connected to it, and the critical or sensitive information it holds.
Frequently asked questions
Which users should get multi-factor authentication first?
CISA says MFA should be required of all users, but recommends starting with privileged, administrative and remote access users.
What should be included in backups?
NISTIR 7621 lists documents, spreadsheets, databases, financial and human resources files, system logs and other business information. Back up your data, not the software applications themselves.
What does CISA say about patching?
Enable automatic updates whenever possible, test and deploy patches quickly, and replace operating systems, applications and hardware that are no longer supported.
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurityClaude Code, Cursor and other clients
claude mcp add --transport http kopik-nist-csf-2-small-business-cybersecurity "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-nist-csf-2-small-business-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/nist-csf-2-small-business-cybersecurity/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_…with your key. - Full details (responses, errors, JS and Python examples): developer docs.