SMALL BUSINESS CYBERSECURITY
Small Business Cybersecurity Assessment Checklist: 12 Areas to Review
A useful cybersecurity assessment should help a business make decisions—not produce a long list of technical findings without priorities. These twelve areas provide a practical starting point for understanding exposure, strengthening essential safeguards, and building a realistic improvement plan.
1. Critical business processes
Identify the activities the company cannot operate without: receiving payments, delivering services, communicating with customers, accessing records, scheduling work, running payroll, or fulfilling orders. Document which people, systems, vendors, and data support each process. Security priorities become clearer when they are tied to business interruption rather than isolated technology.
2. Account inventory and ownership
List important email, financial, cloud, administrative, social media, domain, and vendor accounts. Each account should have an identifiable owner, a business purpose, and a recovery method the organization controls. Shared accounts, former-employee accounts, and forgotten subscriptions create avoidable access and recovery risk.
3. Multifactor authentication and password practices
Confirm that multifactor authentication protects email, administrative access, financial platforms, remote access, file storage, and other critical services. Review whether employees use unique passwords and an approved password manager. Authenticator applications or security keys are preferable for higher-risk accounts when supported.
4. Administrative and privileged access
Everyday email and web browsing should not routinely happen through unrestricted administrative accounts. Review who can change security settings, create users, install software, access backups, modify payment information, or control the company domain. Privileged access should be limited, protected, and reviewed periodically.
5. Email and payment verification
Assess protections against business email compromise, vendor impersonation, fraudulent invoices, payroll changes, and gift-card requests. Technical filtering helps, but clear verification procedures are essential. Bank-detail changes and unusual payments should be confirmed through a known, separate communication channel.
6. Computers and mobile devices
Maintain an inventory of devices that access company information. Review automatic updates, encryption, screen locks, endpoint protection, local administrator rights, backups, and the process for lost or retired equipment. If personal devices are permitted, define what business access is allowed and how that access can be removed.
7. Sensitive data
Identify where customer, employee, financial, health, payment, confidential, or regulated information is collected and stored. Review who can access it, how it is shared, how long it is retained, and whether it is duplicated in email or spreadsheets. Data that no longer serves a valid purpose should be securely deleted.
8. Backups and recovery
Confirm that critical systems and information are backed up, that backup access is protected, and that restoration has been tested. A successful backup notification does not prove the business can recover. Determine how long essential operations can be unavailable and whether the current recovery approach meets that expectation.
9. Cloud applications and connected access
Review the applications employees use, the data each application holds, and integrations connecting one service to another. Remove abandoned applications and stale connections. Important cloud services should have appropriate administrative controls, logging, recovery options, and a plan for retrieving company information.
10. Vendors and service providers
Understand which vendors can access systems, manage technology, process payments, store sensitive information, or support critical operations. Clarify responsibility for security settings, incident notification, backups, account removal, and data deletion. Outsourcing a service does not outsource the business consequence of a failure.
11. Employees, contractors, and offboarding
Security guidance should reflect the situations people actually face. Employees need a clear way to report suspicious messages, mistaken disclosures, lost devices, or unusual account activity. Access should be adjusted when responsibilities change and removed promptly when workers leave.
12. Incident response and decision authority
Document who should be contacted when an account is compromised, money is misdirected, ransomware appears, data is exposed, or a key service becomes unavailable. Identify decision-makers and current contacts for IT support, legal counsel, cyber insurance, banks, and other specialists. Practice at least one realistic scenario before an emergency.
When an independent assessment helps
A checklist is a useful starting point, but an independent assessment can reveal assumptions, responsibility gaps, and connected risks that are difficult to see from inside the business. It should translate technical issues into business decisions and distinguish urgent exposure from longer-term improvement.
The right assessment should explain what was reviewed, what was not reviewed, why each finding matters, and what sequence of action makes sense. It should never require passwords to be submitted through a public website or ordinary email.
A PRACTICAL FIRST STEP
Get a prioritized cybersecurity assessment—not a generic score.
Cyber Valet provides nationwide remote assessments for small businesses that need clear priorities, practical recommendations, and direct guidance.