← All insights

Practical checklist or tool

The Small-Office Security Review Sheet: 24 Questions That Produce Useful Evidence

A manager-friendly review tool for checking access, devices, email, backups, vendors, and response readiness in one structured session.

Office manager using a printed cybersecurity review worksheet beside a laptop

How to use this review

Set aside 45 to 60 minutes with the office manager, technology provider, and one business owner. The goal is not to create a perfect audit. The goal is to identify what is known, what is missing, and what needs a decision.

For every question, mark one answer:

  • Yes: evidence was reviewed.
  • Partial: a control exists but is incomplete or inconsistent.
  • No: the control is absent or not verified.
  • Unknown: no one can currently confirm the answer.

Unknown should not be treated as yes. It is a management task.

Accounts and access

  • Is there a current list of employees, contractors, and service accounts?
  • Are former employees disabled promptly?
  • Are shared accounts documented and minimized?
  • Is multifactor authentication enabled for email, cloud storage, remote access, and administrators?
  • Are privileged accounts separate from everyday email accounts?
  • Are administrator actions logged and reviewed?

Evidence to collect includes an account export, recent termination example, MFA report, and list of privileged roles. Do not place passwords or recovery codes in the worksheet.

Devices and software

  • Is every business laptop, desktop, and mobile device assigned to a person or purpose?
  • Are operating systems supported and receiving updates?
  • Is endpoint protection active and centrally managed?
  • Is disk encryption enabled on portable devices?
  • Are local administrator rights limited?
  • Are unauthorized remote-access tools prohibited or monitored?

A device list should show owner, operating system, encryption status, management status, and last check-in date. If a device is missing from management, determine whether it is retired, offline, or unmanaged.

Email and collaboration

  • Are email domains protected with SPF, DKIM, and DMARC appropriate to the organization’s setup?
  • Is external forwarding restricted or reviewed?
  • Are suspicious messages easy to report?
  • Is payment or bank-account change information verified through a second channel?
  • Are sensitive files shared with named recipients rather than public links?
  • Are dormant shared mailboxes and groups reviewed?

The most important evidence may be a written business procedure. Technology cannot determine whether a legitimate-looking payment request is actually authorized.

Data and backups

  • Has the business identified its most important data?
  • Does each critical system have a documented recovery method?
  • Are backups protected from ordinary user and administrator access?
  • Is at least one backup copy offline or otherwise isolated from routine compromise?
  • Has a file or system restore been tested recently?
  • Does management know the acceptable amount of data loss and downtime?

Record the test date, system, restoration result, time required, and unresolved issues. A screenshot saying “backup successful” does not prove that a usable restore is possible.

Vendors and cloud services

  • Is there a current list of vendors with access to business data?
  • Are contracts clear about security responsibilities and incident notification?
  • Are vendor administrator accounts reviewed?
  • Is there a process for removing access when a contract ends?
  • Does the business know how to obtain its data if a service is unavailable?
  • Are critical vendors included in continuity planning?

Review the services that can change payment details, reset accounts, export customer records, or access regulated information. These are often more important than the number of applications in use.

Detection and response

  • Does everyone know how to report a suspicious email or account prompt?
  • Is there a written incident contact list outside the affected system?
  • Can the business isolate a device or disable an account quickly?
  • Are legal, insurance, vendor, and law-enforcement contacts identified?
  • Has the response plan been discussed or tested?
  • Are lessons from tests and incidents tracked to completion?

Keep a paper copy or protected offline copy of essential contacts. A plan stored only inside a locked account may be unavailable when it is needed.

Turning results into action

Group findings into three categories:

  • Immediate: active compromise, missing MFA on privileged access, unknown administrator accounts, failed backups, unsupported critical systems.
  • Near-term: incomplete inventory, excessive access, weak payment verification, untested response procedures.
  • Planned: policy updates, vendor reviews, replacement of aging systems, advanced monitoring.

Assign every action an owner, due date, evidence requirement, and status. Avoid vague tasks such as “improve security.” Use statements such as “remove former contractor access from the accounting platform and retain the access-review record.”

What is confirmed and what is uncertain

NIST and CISA support risk-based, prioritized cybersecurity practices for smaller organizations. The exact settings and evidence will vary by platform, contract, and business model. This worksheet is not a legal compliance assessment or penetration test.

The review is successful when it exposes uncertainty and creates accountable next steps. Reuse it quarterly, after a major system change, and after significant staff turnover.

Sources