Forty nine things to check, grouped the way an actual assessment runs. Work through it yourself, or have us do it and hand you the answers in writing.
Score each line as yes, no, or don’t know. “Don’t know” counts as no. That sounds harsh but an untested backup and a missing backup fail the same way at 8am on a Tuesday.
You’re not aiming for a perfect score. A small office that can answer yes to the patching, MFA, backup and email sections is already ahead of most of the businesses we get called into after something goes wrong. Work top down, because the sections are roughly in order of how often they’re the thing that actually caused the problem.
If you’d rather not do this yourself, we’ll run it for you at no charge and send back a written summary of what’s solid, what’s risky and what to prioritize. That’s the same list, just with someone looking at the actual configuration instead of guessing.
The number one way attackers get in as of the 2026 Verizon breach report, at 31% of breaches. Start here.
The last one is where most small offices break down. Patching that nobody verifies is patching that silently stopped six months ago on the three machines that matter.
Copiers and NAS boxes are the ones people laugh at until they see one being used as a foothold. They’re full featured computers with a web login and factory credentials.
Ransomware appears in nearly half of all breaches, and in 88% of small business breaches in the last size breakdown Verizon published.
That fourth line is the one that separates the businesses that have a bad week from the ones that have a bad year. A backup nobody has restored from is a hope. We do test restores for managed clients because “the backup was running” is what everybody says right before they find out it wasn’t usable. More on how we handle this on the backup and recovery page.
The FBI put business email compromise losses at $3.046 billion for 2025. Almost none of that involved anything technical. It’s an invoice with changed bank details, sent from a real account or a lookalike domain, and someone paid it. The verbal confirmation rule on that fourth line costs nothing and stops most of it.
RDP open to the internet still shows up in real incidents constantly. If you’re not sure whether yours is, that’s worth finding out today, not at the bottom of a checklist.
Third party involvement in breaches rose 60% in a year and now shows up in 48% of them.
Nobody enjoys this section. It’s also the fastest growing category in the data, so it’s earning its place.
That last insurance line catches people. Applications ask whether you have MFA and tested backups. Answering yes and then not having them is how claims get disputed. If you handle patient data, the dental and medical side of this has its own set of requirements worth reading up on.
Patching, MFA and a tested backup. Those three cover the entry points behind the large majority of real incidents at businesses your size. Everything else can wait a week.
Verbal confirmation for payment changes, disabling old accounts, changing default passwords, separating guest wifi. These cost time and nothing else, and several of them close serious holes.
Endpoint protection, email filtering, replacing an unsupported firewall or a machine still running an unsupported OS. Price them out, but don’t let the quote turn into a six month delay.
Once a year, or after any big change: new server, new office, new practice software, a staff change. Assessments go stale faster than people expect.
An hour to ninety minutes if you know your setup, longer if you have to go find answers. Most people can do sections 4 through 7 from memory and get stuck on the technical ones, which is normal and also tells you something.
There’s no pass mark, but if you can’t answer yes to everything in the patching, accounts and backup sections, that’s where the risk actually lives. A business that nails those three and fails a few of the policy items is in far better shape than the reverse.
Yes, free and with no obligation. We review your network, security, backups and hardware age, then send a written summary of what’s solid, what’s risky and what to prioritize. We check actual configuration instead of taking anyone’s word for it, which is why our version usually finds a few surprises.
No. HIPAA requires its own formal risk analysis with specific documentation. This checklist covers a lot of the same ground and is a reasonable place to start, but a dental or medical practice needs the real thing. We work with practices on that side of it.
Most of it, yes. Being in the cloud moves some responsibility to the provider and leaves you holding the rest: your accounts, your MFA, your staff, your devices, your Microsoft 365 backups. Microsoft doesn’t back up your mailbox the way people assume they do.
Call us. If it looks like an active compromise, don’t start wiping machines, and don’t email about it from the account you think might be compromised. We can talk you through what to do first at (239) 234-2334.
Same checklist, but we look at the real configuration and hand you a written summary. Serving businesses in Fort Myers, Cape Coral, Estero, Bonita Springs and North Naples.