Most small businesses either think they're secure when they're not, or they're paralyzed by complexity and do nothing. Below are the 20 questions I use when evaluating a small business's security posture. These map directly to the controls that, when absent, lead to the breaches I've seen take down small companies.
This is the SMB cybersecurity checklist I wish every small business owner would work through honestly. 16+ yes: reasonable shape. Under 12: meaningful exposure to address now.
Identity and access
- Is MFA enabled for all email accounts including shared inboxes?
- Is MFA enabled for all cloud services containing sensitive data?
- Are passwords managed through a company password manager?
- When an employee leaves, is access revoked within 24 hours across all systems?
- Are admin accounts used only for administrative tasks?
Devices and endpoints
- Are all devices running current, supported operating systems with automatic updates?
- Is endpoint protection installed on all laptops and desktops?
- Are personal devices that access company data subject to security requirements?
- Is the company Wi-Fi separate from the guest network?
- Are laptops encrypted with full-disk encryption?
Data and backups
- Are backups performed at least weekly?
- Are backups stored somewhere other than the primary system?
- Have you tested restoring from backup in the last 6 months?
- Do you know where all sensitive customer data lives?
Policies and awareness
- Have employees received security awareness training in the last 12 months?
- Do you have a written acceptable use policy employees have acknowledged?
- Do you have a process for employees to report suspicious emails?
Incident readiness
- Do you have a written incident response plan?
- Do you have cyber insurance?
- Do you know your legal notification obligations if customer data is compromised?
Scoring
- 16–20 yes: Fundamentals in order. Focus on documentation and awareness.
- 11–15 yes: Prioritize MFA, backups, and IR planning immediately.
- Under 11: Significant exposure. Start with MFA on email, encrypted backups, endpoint protection.
The security tools most small businesses need cost under $100/month combined. The gap between secure and insecure for most SMBs is not money. It's awareness and follow-through. Scarlet Risk can give you a live cybersecurity checklist tied to your risk register in minutes.
