Skip to main content

NIST CSWP 50: The First Federal Cybersecurity Guide Written for Businesses of One

9 min readMike ThriftMike Thrift
NIST CSWP 50: The First Federal Cybersecurity Guide Written for Businesses of One

If you're a freelancer, a single-member LLC, or a sole proprietor working alone, you've probably assumed cybersecurity guidance wasn't written with you in mind. Most of it reads like it's aimed at IT departments: firewalls to configure, employees to train, security teams to coordinate. You have none of those things. You have a laptop, a phone, a handful of client accounts, and not a lot of spare time.

NIST just noticed the same gap — and did something about it. In April 2026, the National Institute of Standards and Technology released a draft update to its small business cybersecurity guidance, and for the first time it's explicitly written for "non-employer firms": businesses with no paid staff other than the owner. That's not a niche category. According to the Small Business Administration, there are 34.8 million small businesses in the U.S., and 81.9% of them — more than 28 million — have zero employees. If you run a business by yourself, you are the overwhelming majority, not the edge case.

What Is CSWP 50, Exactly?

The new publication, formally titled NIST CSWP 50: Small Business Cybersecurity: Non-Employer Firms, is a revision of a document that's been around since 2009 (originally NIST IR 7621). It's built on top of the NIST Cybersecurity Framework (CSF) 2.0, which is the same risk-management framework banks, hospitals, and Fortune 500 companies use — just scaled down to something a one-person shop can actually act on without hiring a consultant.

A few things changed in this revision that matter if you've looked at NIST guidance before and found it overwhelming:

  • Narrower scope. Earlier versions tried to cover general information security. CSWP 50 focuses specifically on cybersecurity — protecting your digital systems and data from threats — which is a more manageable, concrete target.
  • Reformatted for scanning. The content is laid out in tables rather than dense prose, so you can find the one section relevant to your situation instead of reading the whole thing front to back.
  • Three real-world use cases. The draft includes worked examples showing how a very small business would apply the guidance in practice, rather than leaving you to translate abstract principles yourself.
  • Growth-aware. It acknowledges that some non-employer firms plan to stay solo forever, while others will eventually hire — and gives guidance for both paths, rather than assuming everyone is on a trajectory toward becoming a "real" company with an IT department.

The public comment period on the draft closed May 14, 2026, and NIST is expected to finalize the guidance later this year. It's still a draft, not a final standard — but the direction it signals is worth acting on now rather than waiting.

Why This Matters More Than It Might Seem

It's tempting to assume cybersecurity is a "big company" problem — that nobody is going to bother targeting a one-person bookkeeping practice or a solo web developer. The data says the opposite.

Small businesses are targeted in a large share of all cyberattacks, and industry breach reports put the annual breach rate for small businesses at roughly half of all small firms in a given year. When a breach does happen, typical costs for small and midsize businesses run from the low six figures into seven figures once you account for downtime, recovery, notification obligations, and lost client trust — and a majority of small businesses that suffer a significant breach don't survive it long-term. Ransomware is involved in a large share of these incidents, with median payments well into six figures — often more than a solo operator's entire annual revenue.

The freelancer-specific risk is real too: compromised contractor and freelancer accounts are linked to a meaningful share of breach incidents industry-wide, often because a client granted access to shared systems and nobody thought to lock it down afterward. If you do contract work for other businesses, your security posture isn't just your own risk — it's a door into theirs.

Yet the preparedness gap is enormous. Nearly half of businesses with under 50 employees report zero dedicated cybersecurity budget, and only a small fraction of small businesses carry cyber insurance. Prevention is dramatically cheaper than recovery — often estimated at 50 to 60 times less expensive — but almost nobody budgets for it until after something goes wrong.

The Six Functions, Translated for a Business of One

CSF 2.0 organizes cybersecurity work into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. For a company with a security team, each of those is a department. For a solo operator, each is more like a checklist item you revisit a few times a year. Here's what they look like in practice:

Govern — Decide, on paper (even a simple document works), what data you handle and what your risk tolerance is. If you store client financial records, medical information, or payment details, your risk tolerance should be low and your practices should reflect it.

Identify — Make a short inventory: What devices do you use for work? What accounts hold sensitive data — email, cloud storage, accounting software, client portals? You can't protect what you haven't listed.

Protect — This is where most of the practical value sits for a solo business:

  • Use a password manager and enable multi-factor authentication on every account that offers it, especially email and financial tools — email is the recovery key to almost everything else.
  • Keep software and operating systems updated automatically rather than deferring updates.
  • Encrypt your laptop's hard drive (built into modern Windows and macOS, just needs to be turned on).
  • Back up client and financial data somewhere separate from your primary device — a cloud backup or an external drive that isn't always connected.
  • If you use contractors or subcontractors, don't hand over more system access than the specific task requires, and revoke it when the work ends.

Detect — Turn on login alerts and unusual-activity notifications for your email, bank, and major cloud accounts. As a one-person operation you won't have a monitoring system — but most major providers will tell you for free if something looks wrong, if you've opted in.

Respond — Write down, before you need it, what you'll do if you suspect a compromise: which accounts to lock first, who to notify (clients, your bank, insurer if you have one), and where your backups live. Deciding this calmly in advance is far better than deciding it during a panic.

Recover — Know how you'd restore your systems and data from backup, and actually test that the backup works before you need it. An untested backup is a hope, not a plan.

A 30-Minute Starting Checklist

You don't need to implement all six CSF functions in one sitting. If you want to act on this today, here's a realistic starting point that covers the highest-value items first:

  1. Turn on multi-factor authentication (MFA) for your email, bank, and any client-facing portal. This alone blocks the majority of account-takeover attempts, even if a password leaks.
  2. Install a password manager and stop reusing passwords across accounts. A single reused password on a breached site is one of the most common ways solo accounts get compromised.
  3. Confirm your backups actually work. Don't just trust that a cloud sync is happening — pick a file, delete it locally, and restore it from backup to prove the process works.
  4. List every place client data lives — email attachments, a shared drive, an invoicing tool, your accounting software — and check each one has MFA enabled.
  5. Write a two-paragraph incident plan. Who do you call, what do you lock down first, where are your backups. It doesn't need to be formal; it needs to exist before you're in a panic.
  6. Review contractor and app access quarterly. Revoke anything you granted for a project that's since ended.

None of these require a budget or a security background — they're closer to an afternoon of account settings than an IT project.

What Happens Next

Because CSWP 50 is still a draft, the specific wording and structure could shift before NIST finalizes it. But the direction — plain-language, use-case-driven guidance sized for a business of one — is unlikely to reverse, and the underlying CSF 2.0 functions it's built on are already final and stable. If you want a head start, the practical steps above map directly onto the framework regardless of how the final document reads, so there's little downside to starting now rather than waiting for the finalized version.

It's also a useful signal about where regulators and standards bodies are focused: solo and non-employer businesses are increasingly being treated as a distinct category worth their own guidance, not an afterthought bolted onto advice meant for companies with IT staff. Expect more of this — from data-breach notification rules to insurance underwriting — to start explicitly accounting for the fact that most "small businesses" are actually one person.

The Bookkeeping Connection

Here's where cybersecurity and financial recordkeeping intersect more than people expect: a security incident is also a financial-records incident. If your accounting data lives in a system you don't fully control, or if your books exist only as a live connection to a cloud dashboard with no exportable backup, a compromised account can mean losing your financial history at the exact moment you need it most — during incident response, an insurance claim, or a tax filing.

This is one of the underrated advantages of keeping your books in plain-text, version-controlled files rather than solely inside a proprietary platform: your financial records aren't trapped behind a single login that an attacker could lock you out of. A local, backed-up ledger file survives a compromised SaaS account in a way that a browser-only dashboard doesn't.

Simplify Your Financial Management

As you shore up your cybersecurity practices as a solo operator, it's worth extending that same "don't put all your trust in one login" thinking to your books. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in, and records you can back up and audit the same way you'd back up any other critical file. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article