The 12-Point Small Business Security Audit (Run It in Under 1 Hour)
Most small businesses get hacked not because of sophisticated attacks, but because of basic security gaps they didn't know they had.
43% of cyberattacks target small businesses. 60% of small businesses go out of business within 6 months of a major breach.
This 12-point audit covers the essentials. You can run it in under an hour.
1. Credential Management
- [ ] Every employee has a password manager
- [ ] No passwords shared via email, Slack, or spreadsheets
- [ ] Default passwords on all devices changed
- [ ] Service accounts use generated passwords
2. Access Controls
- [ ] Access is role-based, not person-based
- [ ] Departed employees' access revoked within 24 hours
- [ ] Admin access limited to those who need it
- [ ] Quarterly access review process
3. Data Classification
- [ ] Data classified: Public, Internal, Confidential, Restricted
- [ ] Restricted data encrypted at rest
- [ ] You know where all data lives (cloud, on-prem, SaaS)
- [ ] Data retention policy exists and is followed
4. Incident Response Plan
- [ ] Written incident response plan exists
- [ ] Plan includes who to call (legal, PR, law enforcement)
- [ ] Plan has been tested (tabletop exercise)
- [ ] Everyone knows where to find the plan
5. Backup Verification
- [ ] Backups automated and daily
- [ ] Backups stored offline or in separate system
- [ ] Tested a restore in last 6 months
- [ ] Retention covers at least 30 days
6. Patch Management
- [ ] OS updates within 30 days of release
- [ ] Application updates within 14 days
- [ ] Security patches within 72 hours
- [ ] Software inventory maintained
7. Network Segmentation
- [ ] Guest WiFi separate from internal network
- [ ] IoT devices on separate VLAN
- [ ] Server networks separated from user networks
- [ ] Firewall rules documented and reviewed
8. Phishing Awareness
- [ ] Phishing training in last 6 months
- [ ] Phishing simulation test conducted
- [ ] Employees know how to report suspicious emails
- [ ] Email filtering in place (SPF, DKIM, DMARC)
9. Device Management
- [ ] Full-disk encryption on all devices
- [ ] Remote wipe configured for mobile devices
- [ ] Device inventory maintained
- [ ] BYOD devices have MDM or containerization
10. Third-Party Risk
- [ ] List of all vendors with data access
- [ ] Vendor security reviews for new vendors
- [ ] Vendor access reviewed quarterly
- [ ] Data processing agreements in place
11. Monitoring
- [ ] Login alerts for admin accounts
- [ ] Anomaly detection on critical systems
- [ ] Log retention of at least 90 days
- [ ] Someone responsible for reviewing alerts
12. Governance
- [ ] Someone designated as security owner
- [ ] Security policies documented and accessible
- [ ] Security audits conducted at least annually
- [ ] Security discussed in leadership meetings
Scoring
- 48/48: Excellent. Ahead of 95% of small businesses.
- 36-47: Good. Fix the gaps.
- 24-35: At risk. Prioritize immediately.
- Below 24: Critical. Fix this today.
Get the full audit template with scoring rubrics and remediation guides: Small-Team Ops Audit
Free resource: The First 30 Minutes - free incident quick-start checklist.
Use code LAUNCH50 for 50% off anything in the store.
Top comments (0)