Use the review to find facts, not to create anxiety
A short cybersecurity review should produce a reliable list of facts. It should not become a scavenger hunt for every possible vulnerability or a performance test for staff.
Set a timer for 45 minutes. Invite the person who manages technology, the office manager, and the business owner or delegated decision-maker. If a managed service provider controls the systems, ask for read-only evidence or a live walkthrough rather than accepting a verbal summary.
Mark each item Yes, No, Unknown, or Not Applicable. “Unknown” is a useful result because it identifies where evidence is missing.
Part one: accounts and access
Check the following:
- Every employee has an individual account for email and core systems.
- Former employees and contractors are disabled.
- Shared accounts are documented and limited.
- Administrative accounts are separate from ordinary daily-use accounts.
- Multifactor authentication is enabled for email, remote access, financial systems, and administrator accounts.
- Recovery email addresses and phone numbers are current.
- At least two trusted people can manage recovery without sharing passwords.
- Vendor access is named, time-limited where practical, and reviewed.
Evidence may include an account export, access review report, screenshots, or service tickets. Do not store passwords in the review file.
Part two: devices and software
Review a sample of workstations, laptops, phones, and network devices. Confirm:
- Operating systems are supported and receiving security updates.
- Endpoint protection is installed and reporting.
- Disk encryption is enabled on portable computers.
- Automatic screen locking is active.
- Staff cannot install arbitrary software without approval where that control is appropriate.
- Lost or stolen devices can be remotely disabled or wiped.
- Network equipment uses changed administrative credentials and current firmware.
- Remote access is limited and protected by MFA.
A sample is not a full audit. Record which devices were checked and how the sample was selected.
Part three: email and collaboration
Email compromise is often a business process problem as well as a technical problem. Check whether:
- External forwarding rules are reviewed.
- Suspicious sign-in alerts have an assigned owner.
- Staff know how to report phishing.
- Payment-change requests require an independent confirmation.
- Sensitive files are shared with named users or approved groups.
- Guest access is reviewed.
- Old shared links are removed or expired where possible.
Use an out-of-band confirmation for changes to bank details, payroll, wire instructions, or vendor payment information.
Part four: backups and recovery
Ask these questions:
- What data is backed up?
- How often does the backup run?
- Where are copies stored?
- Can an attacker using an ordinary administrator account delete the backups?
- Are backups encrypted?
- How long are they retained?
- When was the last restoration test?
- Who can authorize restoration?
CISA recommends backups that are automatic and continuous where appropriate, with a copy protected from the production network. The correct design depends on the business, but the test is universal: can the office restore what it needs within a tolerable period?
Part five: response readiness
Locate the incident contact sheet. It should include:
- Internal decision-maker.
- IT provider and after-hours number.
- Cyber-insurance hotline.
- Legal counsel.
- Key software vendors.
- Law enforcement and reporting contacts.
- Instructions for preserving evidence.
- A temporary communications channel if email is unavailable.
If no sheet exists, create a draft during the review.
Scoring without false precision
Do not convert the review into a misleading “security score” unless the scoring method is defined. Instead, classify findings:
- Critical: could prevent essential operations or enable major unauthorized access.
- High: materially increases likelihood or impact of a common incident.
- Medium: weakens consistency, evidence, or recovery speed.
- Low: improvement opportunity with limited immediate impact.
For each finding, name an owner, target date, and evidence required for closure.
What is confirmed and what is uncertain
Confirmed: MFA, software updates, backups, logging, encryption, and incident planning are repeatedly emphasized in federal small-business guidance. A checklist can help identify missing evidence and ownership.
Uncertain: the review cannot establish that a business is compliant, secure, or free of compromise. It is not penetration testing, legal advice, a forensic investigation, or a substitute for a detailed risk assessment.
The output to keep
The final deliverable should be one page containing:
- Date and participants.
- Systems reviewed.
- Yes, No, Unknown, and Not Applicable results.
- Five highest-priority actions.
- Owners and due dates.
- Links or filenames for supporting evidence.
Repeat the review every quarter. A simple, repeatable process is more useful than a complex checklist that no one completes.

