Cybersecurity

Small Business Cybersecurity Assessment Checklist

August 30, 20269 min read
Cybersecurity AssessmentRisk ManagementSmall Business

A useful cybersecurity assessment does more than run a scanner and produce a list of technical findings. It identifies what the business depends on, who owns each protection, how an incident would be detected and handled, and which improvements should happen first. This checklist gives a small business a practical starting point for that conversation.

1. Define the business scope before testing controls

List the services, systems, locations, people, and vendors that keep the business operating. Include cloud applications, email, workstations, mobile devices, networking equipment, websites, payment systems, customer portals, and any operational technology. A security review cannot cover an asset nobody knows exists.

Identify the information each system holds or can reach. Customer records, employee information, financial data, credentials, contracts, health information, and proprietary work may require different handling. Record where important data is created, shared, stored, backed up, and deleted.

Connect the inventory to business impact. Ask what happens if each system is unavailable for a day, if its data is exposed, or if an attacker changes it. This helps the assessment prioritize business risk instead of treating every technical finding as equally urgent.

2. Review identity and administrator access

Confirm that every active account belongs to a current user or an approved service, and remove accounts that no longer have a purpose. Shared logins make accountability difficult, so replace them with named accounts where the system allows it.

Check multi-factor authentication for email, remote access, financial systems, administrative tools, password managers, and other high-impact services. Review whether recovery phone numbers, personal email addresses, backup codes, or trusted devices could bypass the intended protection.

Administrative access should be limited and separate from ordinary daily work. Record who can create users, reset passwords, change security settings, access backups, or disable logging. Make sure the company can recover control if a primary administrator is unavailable.

3. Inventory devices, software, and updates

Create a current list of laptops, desktops, servers, phones, tablets, firewalls, access points, printers, and other connected devices. Record ownership, operating system, assigned user, location, support status, and who is responsible for updates.

Review how operating systems, browsers, business applications, firmware, and security tools receive updates. Unsupported products and repeatedly delayed patches should be visible in the risk plan, along with the business reason they remain in use and the date they will be replaced.

Confirm what happens when a device is lost, stolen, or assigned to a new employee. Disk encryption, screen locking, endpoint protection, remote management, and secure data removal are only effective when they are configured and checked consistently.

4. Examine email, files, and data sharing

Email is both a critical business system and a common path into other accounts. Review phishing protections, domain email authentication, mailbox forwarding rules, third-party app access, and the process employees use to report suspicious messages.

Inspect external file sharing, public links, guest users, shared drives, collaboration sites, and personal storage accounts. Company information should remain under company ownership, with access removed when a worker or vendor no longer needs it.

Define how sensitive information may be sent, downloaded, printed, or stored on mobile devices. If the business has contractual or regulatory obligations, map each requirement to an actual technical or procedural control and identify the person who maintains evidence.

5. Prove backups and recovery

Document which systems and data are backed up, how often backups run, where copies are stored, how long they are retained, and who can alter or delete them. A synchronized cloud folder is not automatically a complete backup strategy because deletions or damaging changes may also synchronize.

Review separation between daily administrator accounts and backup administration. Important backups should be protected from the same credentials and systems an attacker could compromise during an incident.

Perform a restore test and record the result. Choose representative files and at least one critical system, restore them to a safe location, and confirm that the recovered information opens and supports the intended work. Recovery evidence is more useful than a green backup dashboard alone.

6. Assess vendors and connected applications

List vendors that store company data, connect to company systems, manage devices, process payments, provide remote support, or hold administrative credentials. Record what each vendor can access and how that access is removed.

Review contracts and service descriptions for security responsibilities, incident notification, data return, data deletion, availability commitments, backup ownership, and support escalation. A vendor using a secure platform does not automatically make the business's configuration or workflow secure.

Check connected applications and OAuth permissions in major cloud platforms. Remove integrations that are unused, unrecognized, or broader than the business purpose requires.

7. Test incident readiness

Write down who employees contact when they suspect an incident, who can authorize containment actions, which outside providers must be involved, and how leaders will communicate if normal email or phones are unavailable.

Prepare current contact information for technology providers, cyber insurance, legal counsel, key vendors, and relevant authorities. Store an accessible copy outside the systems most likely to be affected.

Use a short tabletop exercise to walk through a realistic scenario such as a compromised mailbox, stolen laptop, fraudulent payment request, or ransomware event. The exercise should reveal missing decisions and access problems while there is still time to fix them.

Turn the checklist into a prioritized plan

Do not end the assessment with an unranked list. For each gap, record the business impact, likelihood, affected systems, current safeguards, recommended action, owner, target date, and any dependency. Separate urgent exposure from longer-term maturity work.

NIST's Cybersecurity Framework 2.0 organizes outcomes around Govern, Identify, Protect, Detect, Respond, and Recover. CISA's voluntary Cybersecurity Performance Goals provide a prioritized baseline of practices. A small business can use those resources to structure improvement without pretending that every organization has the same risks or requirements.

An assessment is a decision tool, not a certificate that the business is secure. Revisit the plan when systems, vendors, locations, regulations, or operations change, and verify completed actions with evidence.

Sources and further reading

Ready to put this to work?

F09 Tech helps Savannah and Coastal Georgia businesses turn ideas like these into a working plan. Start with a free Business Technology & AI Assessment.

Start Your Assessment