DEV Community

Hive80-lab
Hive80-lab

Posted on

The 12-Point Small Business Security Audit (Run It in Under 1 Hour)

The 12-Point Small Business Security Audit (Run It in Under 1 Hour)

Most small businesses get hacked not because of sophisticated attacks, but because of basic security gaps they didn't know they had.

43% of cyberattacks target small businesses. 60% of small businesses go out of business within 6 months of a major breach.

This 12-point audit covers the essentials. You can run it in under an hour.

1. Credential Management

  • [ ] Every employee has a password manager
  • [ ] No passwords shared via email, Slack, or spreadsheets
  • [ ] Default passwords on all devices changed
  • [ ] Service accounts use generated passwords

2. Access Controls

  • [ ] Access is role-based, not person-based
  • [ ] Departed employees' access revoked within 24 hours
  • [ ] Admin access limited to those who need it
  • [ ] Quarterly access review process

3. Data Classification

  • [ ] Data classified: Public, Internal, Confidential, Restricted
  • [ ] Restricted data encrypted at rest
  • [ ] You know where all data lives (cloud, on-prem, SaaS)
  • [ ] Data retention policy exists and is followed

4. Incident Response Plan

  • [ ] Written incident response plan exists
  • [ ] Plan includes who to call (legal, PR, law enforcement)
  • [ ] Plan has been tested (tabletop exercise)
  • [ ] Everyone knows where to find the plan

5. Backup Verification

  • [ ] Backups automated and daily
  • [ ] Backups stored offline or in separate system
  • [ ] Tested a restore in last 6 months
  • [ ] Retention covers at least 30 days

6. Patch Management

  • [ ] OS updates within 30 days of release
  • [ ] Application updates within 14 days
  • [ ] Security patches within 72 hours
  • [ ] Software inventory maintained

7. Network Segmentation

  • [ ] Guest WiFi separate from internal network
  • [ ] IoT devices on separate VLAN
  • [ ] Server networks separated from user networks
  • [ ] Firewall rules documented and reviewed

8. Phishing Awareness

  • [ ] Phishing training in last 6 months
  • [ ] Phishing simulation test conducted
  • [ ] Employees know how to report suspicious emails
  • [ ] Email filtering in place (SPF, DKIM, DMARC)

9. Device Management

  • [ ] Full-disk encryption on all devices
  • [ ] Remote wipe configured for mobile devices
  • [ ] Device inventory maintained
  • [ ] BYOD devices have MDM or containerization

10. Third-Party Risk

  • [ ] List of all vendors with data access
  • [ ] Vendor security reviews for new vendors
  • [ ] Vendor access reviewed quarterly
  • [ ] Data processing agreements in place

11. Monitoring

  • [ ] Login alerts for admin accounts
  • [ ] Anomaly detection on critical systems
  • [ ] Log retention of at least 90 days
  • [ ] Someone responsible for reviewing alerts

12. Governance

  • [ ] Someone designated as security owner
  • [ ] Security policies documented and accessible
  • [ ] Security audits conducted at least annually
  • [ ] Security discussed in leadership meetings

Scoring

  • 48/48: Excellent. Ahead of 95% of small businesses.
  • 36-47: Good. Fix the gaps.
  • 24-35: At risk. Prioritize immediately.
  • Below 24: Critical. Fix this today.

Get the full audit template with scoring rubrics and remediation guides: Small-Team Ops Audit

Free resource: The First 30 Minutes - free incident quick-start checklist.

Use code LAUNCH50 for 50% off anything in the store.

Top comments (0)