Threat feed liveUpdated — 04.08.2026 10:27 CET86 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 04.08.2026 10:27 CET86 dossiersMITRE ATT&CK mapping

Explainer on a NIST publication: no actorlow

Owner, IT department and help desk are the same person: NIST is writing for her

Almost all cybersecurity guidance presumes an organisation: a manager, a department, policies, someone to report to. The largest category is missing — the one where owner, IT department and help desk are the same person. On 10 April 2026 NIST published a draft aimed exactly at her: CSWP 50, Small Business Cybersecurity: Non-Employer Firms. The document opens with the figure that explains the choice: in the United States there are 34.8 million small businesses and 81.9% have no employees beyond the owners. It is Cybersecurity Framework 2.0 scaled down to a one-person shop, with a detail that works as method: security is not simplified by removing controls, but by changing the question they answer.

The category missing from every manual

Take any corporate cybersecurity guide and count how often it presumes somebody else exists. The manager who approves the policy. The colleague you forward the suspicious email to. Separation of duties between whoever authorises a payment and whoever executes it. Staff training.

Now remove all of it. What is left is one person who invoices, answers customers, keeps the books, chooses the laptop, decides whether to update it and — if something goes wrong — is also the only one who can notice.

This is not an edge case. On 10 April 2026 the National Institute of Standards and Technology published the draft of CSWP 50, Small Business Cybersecurity: Non-Employer Firms, with a public comment period that closed on 14 May 2026. The document states its constituency up front: according to the US Small Business Administration's Office of Advocacy, there are 34.8 million small businesses in the United States, and 81.9% have no paid employees beyond the owners.

34.8 million
small businesses in the United States
source: SBA Office of Advocacy, cited by NIST
81.9%
have no employees beyond the owners
sole proprietors, freelancers, independent contractors
2009
first edition
then called NIST IR 7621, «Small Business Information Security»

What changed from earlier versions

This publication has a long history: it began in 2009 as NIST IR 7621, was revised in 2016, and in the current revision changes character. The declared changes tell a deliberate editorial story.

The scope narrows. Earlier versions covered information security broadly; this one focuses on cybersecurity, a subset of it. Less ground, better covered.

The audience narrows further. Based on community input, NIST dropped the "small business" category — too broad and diverse to be useful — and picked a specific reader: firms with no employees and minimal IT complexity.

Three notional use cases were added in appendices, and the layout was reworked into tabular form for readability.

The anchor is Cybersecurity Framework 2.0 and the NIST IR 8286 series on risk management.

There is a second declared audience too: consultants. Many micro-firms do not read documents like this — they rely on someone. Writing for that someone as well is a pragmatic choice worth noting.

The method, which is the transferable part

The risk in any "guide for small players" is simplification by subtraction: take the big manual, drop the hard chapters, hand over the remainder. The result is a list nobody will act on.

The Cybersecurity Framework 2.0 route is different, and the reason lies in its structure. CSF does not prescribe controls: it organises functionsGovern, Identify, Protect, Detect, Respond, Recover — that is, questions every organisation answers at its own scale. The Govern function, added in version 2.0 in February 2024, covers strategy, risk management, policy and oversight: in a ten-thousand-person company that means a committee; in a one-person firm it means having decided, once, what matters and what does not.

  1. 01
    Identify
    what you actually hold: devices, accounts, customer data, portal access
  2. 02
    Protect
    where the few defences you can maintain go: access, backups, updates
  3. 03
    Recover
    what happens the day the laptop will not start. Rehearsed, not imagined

The document also handles the next step, the most fragile moment for someone working alone: what changes when you hire the first person. The day a second account exists, the question of who can see what exists for the first time — and habits formed when there was one user tend to outlive the point at which they made sense.

Five things that apply to anyone working alone

They do not replace the document, and they are not the document: they are the operational translation of its premises.

One. The email account is the company. It is where the passwords for everything else get recovered — bank, invoicing, government portals, suppliers. If only one thing gets multi-factor authentication, it is that one, and preferably not over SMS.

Two. The backup that counts is the one you have tried to restore. An external drive permanently connected to the computer is not a backup: it is a second copy that ransomware encrypts alongside the first.

Three. Separate the operating account from the rest if you can, and turn on transaction alerts. In invoice and bank-detail fraud, the factor that changes the outcome is how fast you notice.

Four. List your access to customers' systems. People who work for others often hold credentials to someone else's platforms: those credentials are the real target, and the duty of care over them cannot be delegated.

Five. Write down on paper what you do if the computer will not start tomorrow morning. Who you call, where you restart from, which customers you tell and in what order. Someone with no colleagues also has nobody who remembers on their behalf.

Two reading caveats. First: this is a public draft — the comment period closed on 14 May 2026 and the final text may differ. Second: the document is written for a US context, and the authors themselves note it should be adapted by those operating under other legal systems. Local obligations on invoicing, retention and handling of customer data are not in there, and remain yours.

More dossiers