web analytics
Home Cybersecurity Risk Assessment Checklist
Free · No signup

Small Business Cybersecurity Risk Assessment Checklist

Forty nine things to check, grouped the way an actual assessment runs. Work through it yourself, or have us do it and hand you the answers in writing.

henktek · how to use this49 checks
Time to self assess60 to 90 min
Skill neededOwner or office manager
Sections7
Cost if we run itFree, no obligation
Written summaryYes
Before you start

How to get something useful out of this

Score each line as yes, no, or don’t know. “Don’t know” counts as no. That sounds harsh but an untested backup and a missing backup fail the same way at 8am on a Tuesday.

You’re not aiming for a perfect score. A small office that can answer yes to the patching, MFA, backup and email sections is already ahead of most of the businesses we get called into after something goes wrong. Work top down, because the sections are roughly in order of how often they’re the thing that actually caused the problem.

If you’d rather not do this yourself, we’ll run it for you at no charge and send back a written summary of what’s solid, what’s risky and what to prioritize. That’s the same list, just with someone looking at the actual configuration instead of guessing.

Section 1

Patching and updates

The number one way attackers get in as of the 2026 Verizon breach report, at 31% of breaches. Start here.

  • Windows updates install automatically on every workstation, and somebody can prove it
  • Servers are patched on a schedule, not whenever someone remembers
  • The firewall firmware is current and still under a support contract
  • Switches, access points and any VPN appliance get firmware updates too
  • Third party software is patched: browsers, Adobe, Java, practice or industry software
  • No machine is still running an operating system past end of support
  • Someone reviews a patch report monthly and chases the machines that failed

The last one is where most small offices break down. Patching that nobody verifies is patching that silently stopped six months ago on the three machines that matter.

Section 2

Accounts and passwords

  • Multi factor authentication is on for Microsoft 365 or Google Workspace, for everyone, no exceptions for the boss
  • MFA is also on for remote access, VPN and the firewall admin login
  • Nobody shares a login. Every person has their own account
  • Staff don’t work day to day as local administrators on their computers
  • Former employees are actually disabled, and you could name the last one who left and prove it
  • The default admin password got changed on the firewall, the router, the NAS and the copier
  • Nobody keeps passwords on a sticky note or in a shared spreadsheet
  • There’s a password manager, or at least a plan for one

Copiers and NAS boxes are the ones people laugh at until they see one being used as a foothold. They’re full featured computers with a web login and factory credentials.

Section 3

Backups and recovery

Ransomware appears in nearly half of all breaches, and in 88% of small business breaches in the last size breakdown Verizon published.

  • Backups run on a schedule and somebody gets told when one fails
  • At least one copy is offsite or in the cloud
  • At least one copy cannot be deleted or encrypted by a machine on your network
  • A real test restore has been done in the last 90 days
  • You know roughly how long a full restore takes, in hours
  • You know what you’d lose: an hour of work, a day, a week
  • Backups cover cloud data too, including Microsoft 365 mail and files

That fourth line is the one that separates the businesses that have a bad week from the ones that have a bad year. A backup nobody has restored from is a hope. We do test restores for managed clients because “the backup was running” is what everybody says right before they find out it wasn’t usable. More on how we handle this on the backup and recovery page.

Section 4

Email security

  • Email filtering is doing more than the default spam folder
  • SPF, DKIM and DMARC records exist for your domain
  • External emails are visibly tagged so staff can tell
  • Somebody, by name, has to verbally confirm any change to banking or payment details
  • Staff have been told what business email compromise looks like
  • Nobody auto forwards company mail to a personal address

The FBI put business email compromise losses at $3.046 billion for 2025. Almost none of that involved anything technical. It’s an invoice with changed bank details, sent from a real account or a lookalike domain, and someone paid it. The verbal confirmation rule on that fourth line costs nothing and stops most of it.

Section 5

Network and devices

  • Guest wifi is separated from the network your business runs on
  • The wifi password isn’t the same one you’ve had since 2019, and isn’t printed at the front desk on the same network staff use
  • Endpoint protection is installed everywhere and someone sees the alerts
  • Remote access uses VPN or a managed tool, not a port forwarded to RDP
  • You have a current list of every device on the network
  • Laptops that leave the building have disk encryption turned on
  • Personal phones with company email are covered by some kind of policy
  • Old equipment gets wiped before it’s donated, sold or trashed

RDP open to the internet still shows up in real incidents constantly. If you’re not sure whether yours is, that’s worth finding out today, not at the bottom of a checklist.

Section 6

Vendors and third parties

Third party involvement in breaches rose 60% in a year and now shows up in 48% of them.

  • You can list every outside company that touches your data or logs into your systems
  • You’ve asked at least your biggest vendor what happens to your data if they get breached
  • Vendor remote access is turned off when they’re not using it
  • Cloud services holding your data have MFA enabled on the admin account
  • Someone reviews what your industry software vendor is doing about security, even briefly

Nobody enjoys this section. It’s also the fastest growing category in the data, so it’s earning its place.

Section 7

People, policy and compliance

  • Staff have had some security awareness training this year
  • People know who to tell when something looks wrong, and won’t get yelled at for reporting it
  • There’s a written plan for what happens if systems go down, even a one page one
  • Somebody’s phone number is the one to call at 6am, and everyone knows it
  • If you handle health records, you’ve looked at HIPAA requirements in the last year
  • If you take cards, you know your PCI obligations
  • Cyber insurance exists, and the answers you gave on the application are still true
  • Someone owns IT security as part of their job, whether that’s internal or us

That last insurance line catches people. Applications ask whether you have MFA and tested backups. Answering yes and then not having them is how claims get disputed. If you handle patient data, the dental and medical side of this has its own set of requirements worth reading up on.

What to do with your score

Fixing the gaps in order

1

Anything in sections 1 to 3 first

Patching, MFA and a tested backup. Those three cover the entry points behind the large majority of real incidents at businesses your size. Everything else can wait a week.

2

Then the free ones

Verbal confirmation for payment changes, disabling old accounts, changing default passwords, separating guest wifi. These cost time and nothing else, and several of them close serious holes.

3

Then the ones that need money

Endpoint protection, email filtering, replacing an unsupported firewall or a machine still running an unsupported OS. Price them out, but don’t let the quote turn into a six month delay.

4

Then set a date to redo this

Once a year, or after any big change: new server, new office, new practice software, a staff change. Assessments go stale faster than people expect.

FAQ

Common questions

How long does this take to work through?

An hour to ninety minutes if you know your setup, longer if you have to go find answers. Most people can do sections 4 through 7 from memory and get stuck on the technical ones, which is normal and also tells you something.

What score is good enough?

There’s no pass mark, but if you can’t answer yes to everything in the patching, accounts and backup sections, that’s where the risk actually lives. A business that nails those three and fails a few of the policy items is in far better shape than the reverse.

Will you run this for us?

Yes, free and with no obligation. We review your network, security, backups and hardware age, then send a written summary of what’s solid, what’s risky and what to prioritize. We check actual configuration instead of taking anyone’s word for it, which is why our version usually finds a few surprises.

Is this a HIPAA risk assessment?

No. HIPAA requires its own formal risk analysis with specific documentation. This checklist covers a lot of the same ground and is a reasonable place to start, but a dental or medical practice needs the real thing. We work with practices on that side of it.

We use a cloud service for everything. Does this still apply?

Most of it, yes. Being in the cloud moves some responsibility to the provider and leaves you holding the rest: your accounts, your MFA, your staff, your devices, your Microsoft 365 backups. Microsoft doesn’t back up your mailbox the way people assume they do.

What if we find something bad while doing this?

Call us. If it looks like an active compromise, don’t start wiping machines, and don’t email about it from the account you think might be compromised. We can talk you through what to do first at (239) 234-2334.

We’ll run it for you, free

Same checklist, but we look at the real configuration and hand you a written summary. Serving businesses in Fort Myers, Cape Coral, Estero, Bonita Springs and North Naples.