No employees doesn’t mean no liability. There are non-employer firms that have no paid employees other than the business owners, and there is also a NIST standard that could help these types of businesses be better protected when it comes to cybersecurity.

Over 81% of the 34 million small businesses in the United States operate without a single employee. Most of those owners believe compliance obligations are someone else’s problem, sized for enterprises with legal departments and security teams. That belief is wrong, and it carries real legal exposure.

FTC Act Section 5 prohibits unfair or deceptive trade practices. The FTC has used this authority repeatedly to pursue businesses, including small ones, that collected consumer data without implementing reasonable security measures. “Reasonable security” isn’t defined by headcount. A freelance accountant storing client tax data on an unencrypted laptop, a sole-proprietor healthcare consultant transmitting PHI over unsecured email, or a one-person e-commerce operation holding payment card data with default credentials: each of those scenarios creates Section 5 exposure regardless of business size.

State breach notification laws add another layer. All 50 states have them. Most impose mandatory notification timelines, typically 30 to 72 hours after discovery depending on jurisdiction, along with requirements to maintain “reasonable security procedures.” California’s CCPA, Virginia’s VCDPA, and Texas’s own breach notification statute under the Business & Commerce Code Chapter 521 don’t carve out sole proprietors. If you collect, store, or process personally identifiable information, the obligations attach.

NIST IR 7621 Rev. 2 (Initial Public Draft, May 2025) translates the NIST Cybersecurity Framework 2.0 into operationally realistic guidance for non-employer firms. The document uses plain language, checklists, and starter templates explicitly designed for low-budget, low-technical-depth environments. Every recommendation maps to the six CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, and Recover.

The compliance relevance here isn’t aspirational, it’s defensive. Documented adherence to NIST guidance is frequently cited in FTC consent orders and breach litigation as the evidentiary baseline for what constitutes reasonable security. Following IR 7621 creates a paper trail showing the business applied a recognized standard. Ignoring it, post-breach, becomes exhibit A for the plaintiff’s bar.

The framework’s practical floor starts with asset inventory. Document every device, cloud service, application, and data set you touch, and classify each by data sensitivity. This isn’t administrative overhead; it’s a prerequisite for any breach notification analysis. You can’t notify on data you didn’t know you held.

From there, the non-negotiables: phishing-resistant MFA on every account that supports it, least-privilege access everywhere (including removing default admin credentials from any vendor-supplied device or software), and automated patch management. These three controls address the attack vectors that generate the largest share of small-business breach incidents.

Backup architecture matters under both operational continuity and legal response timelines. A 3-2-1 scheme. three copies, two media types, one offsite, with tested restore capability directly supports the ability to contain and assess an incident within state-mandated notification windows. An owner who can’t determine within 48 hours whether specific consumer records were exfiltrated has already failed the notification standard in most jurisdictions.

A one-page incident response worksheet isn’t optional. It should document: what data you hold and where, who you notify (state AG, affected individuals, and any applicable federal regulator), and in what timeframe. Texas Business & Commerce Code 521.053 requires notification to affected individuals and the Texas AG for breaches over 250 residents. That clock starts at discovery, not at resolution.

IR 7621 flags cyber insurance and managed security services as supplemental controls. From a liability standpoint, these aren’t nice-to-haves. Cyber insurance policy language increasingly requires demonstrable security controls as a condition of coverage, and insurers are denying claims where basic hygiene like MFA was absent. If your policy requires certain controls and you haven’t implemented them, your coverage may not respond when you need it.

Managed service providers (MSPs) create their own exposure. A sole proprietor who outsources IT to an MSP doesn’t outsource legal liability. The contractual terms with that MSP, specifically who bears responsibility for breach response, notification costs, and regulatory fines, need to be explicit. Most standard MSP contracts disclaim this liability. If yours does and a breach originates through the MSP’s systems, the regulatory obligation still runs to you.

NIST IR 7621 doesn’t create new legal obligations, the FTC Act and state breach notification statutes already did that. What it provides is a documented, recognized path toward the “reasonable security” standard those laws require. For a sole proprietor, working through the IR 7621 checklists and retaining the completed documentation is one of the more defensible moves available before a breach happens, not after.

Oftentimes, small businesses do not think of cybersecurity and end up becoming a victim of cyberattacks or a breach. I’ve also seen small businesses with employees not take cybersecurity seriously.

Cybersecurity is critical not just for large corporations but also for any type of business. Unfortunately, not everyone understands this and businesses would rather spend money on other things and forget or neglect a cyber budget.

Let me know your thoughts on this.


Hope you found this post helpful and informative. Thanks for stopping by!

Leave a Reply

Discover more from root@cybercasta:~$

Subscribe now to keep reading and get access to the full archive.

Continue reading