A Small-Business Cybersecurity Check You Can Complete Before Hiring Anyone
You don't need to become a cybersecurity specialist to find the most obvious risks in your business. You do need to know which systems keep the doors open, who can get into them, and whether you could recover if one stopped working tomorrow.
This check won't prove you're secure. But it will help you find the gaps that are too important to keep assuming someone else handled.
List the systems that keep the business running
Write down computers, phones, routers, websites, email, cloud storage, accounting, payment systems, customer databases, point-of-sale devices, backups, and critical vendors.
For each item, record the owner, administrator, data stored, users with access, update responsibility, and recovery method. An account nobody recognizes cannot be managed safely.
Protect the accounts that unlock everything else
You should protect email, domain registration, hosting, cloud administration, banking, payroll, and password management first, because those accounts can reset or unlock many others and give an attacker a path through the rest of the business.
Use a unique password and multi-factor authentication for every critical account that supports it.
Remove former workers and unused administrators. Give each person only the access needed for the current job, and keep a protected record of emergency recovery information.
The FTC's small-business cybersecurity guidance recommends multi-factor authentication, regular updates, backups, encryption, restricted access, and staff training.
Check updates and unsupported software
Turn on automatic security updates where practical. Review operating systems, browsers, office software, website software, routers, security tools, and line-of-business applications.
Replace systems that no longer receive security updates or isolate them until they can be replaced. "It still works" is not a security plan when known flaws will remain unpatched.
Verify backups by restoring something
Identify the files and systems the business could not operate without. Confirm that backups run automatically, keep more than one recovery point, and are not all continuously connected to the same network.
Restore a sample file and document the result. A dashboard that says "successful" does not prove the business can recover usable data.
Record how long a full recovery might take and who can perform it. Recovery time can matter as much as whether a backup exists.
Review email and payment-change procedures
Train staff to verify unexpected requests through a known second channel. This is especially important for changes to bank details, payroll deposits, invoices, passwords, gift-card purchases, and urgent transfers.
Configure SPF, DKIM, and DMARC for business-domain email with qualified help when needed. These controls reduce domain spoofing but must be configured carefully to avoid blocking legitimate mail.
Separate guest and business access
Change default router and device passwords. Keep guest Wi-Fi separate from business systems, turn off unnecessary remote administration, and use encryption supported by current equipment.
Do not let personal or unmanaged devices connect to sensitive systems without a policy. Lost phones and old laptops often retain access long after anyone remembers granting it.
Decide how suspicious activity gets reported
Staff should know who to contact after a phishing click, lost device, strange login alert, unexpected software, or payment mistake. Fast reporting can limit damage.
Write a short incident plan with technical, legal, insurance, leadership, customer, and law-enforcement contacts. Include a way to access it when the normal network or email system is unavailable.
Know when the self-check is not enough
Get qualified help when the business handles regulated or highly sensitive data, has experienced an intrusion, cannot account for administrative access, relies on unsupported systems, or cannot restore critical operations.
Cybersecurity is not a one-time installation. Repeat the check when staff, vendors, systems, locations, or data practices change, and verify the fixes rather than assuming a box was checked.