Tech & produit

Small business backups, Wi-Fi and firewall basics from NIST and CISA

NIST's small-business fundamentals (NISTIR 7621 Rev. 1) and the CISA Cyber Essentials Starter Kit give concrete day-to-day measures for a small office. Ask the assistant about backup schedules, network setup and the first actions a leader should take.

Posez votre question

Compte gratuit requis

Chaque question est indépendante · 1 offertes par mois, puis avec l'abonnement.

Les réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.

Backups: frequency and storage

NISTIR 7621 Rev. 1 recommends a full, encrypted backup of each computer and mobile device at least once a month, shortly after a complete virus scan, plus an automatic incremental or differential backup at least once a week. Depending on how much data changes, daily or even hourly backups may be prudent.

Full backups should be stored away from the office in a protected place, so that a fire, flood or theft does not destroy them too. Keep the encryption key somewhere separate, and encrypt data before storing it in the cloud.

The guide suggests storage large enough for 52 weekly backups, which helps you recover from and trace incidents that were not noticed right away.

Wi-Fi, firewalls and the first leader actions

For a wireless router, NISTIR 7621 advises changing the default administrative password, not broadcasting the network name (SSID) and using WPA-2 with AES encryption, never WEP. Customer Wi-Fi should be separated from the business network.

It also recommends a hardware firewall between the internal network and the Internet, and an active, logging software firewall on each computer, including for employees working from home.

CISA's "booting up" actions start with inventories: the hardware and software on your network, the user accounts, vendors and partners connected to it, and the critical or sensitive information it holds.

Questions fréquentes

Which users should get multi-factor authentication first?

CISA says MFA should be required of all users, but recommends starting with privileged, administrative and remote access users.

What should be included in backups?

NISTIR 7621 lists documents, spreadsheets, databases, financial and human resources files, system logs and other business information. Back up your data, not the software applications themselves.

What does CISA say about patching?

Enable automatic updates whenever possible, test and deploy patches quickly, and replace operating systems, applications and hardware that are no longer supported.

Pour les développeurs et les agents

Intégrer / API / MCP

Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.

MCP pour vos agents

Adresse du serveur MCP de cette base (outils ask_base et search_base) :

URL MCP
https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity
Claude Code, Cursor et autres clients
Claude Code
claude mcp add --transport http kopik-nist-csf-2-small-business-cybersecurity "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity" --header "Authorization: Bearer kpk_…"
Configuration JSON (mcpServers)
{
  "mcpServers": {
    "kopik-nist-csf-2-small-business-cybersecurity": {
      "url": "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

API REST pour vos applications

mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.

curl
curl -X POST https://kopik.io/api/v1/bases/nist-csf-2-small-business-cybersecurity/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Votre question ici", "mode": "answer"}'

Pour commencer

  1. Créez une clé dans votre tableau de bord et rechargez votre crédit.
  2. Remplacez kpk_… par votre clé.
  3. Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.