Illustration of a padlock on a circuit board representing a cybersecurity audit

What a Small Business Cybersecurity Audit Covers (and Three Tips for Running One)

Many small businesses believe antivirus software and a firewall mean they are covered. A cybersecurity audit tests that belief. It is a structured review of how your technology, your accounts and your habits protect the information your business depends on, and it ends with a plain list of what to fix first.

What a cybersecurity audit actually looks at

An audit is wider than a scan. A vulnerability scan checks computers for known weaknesses. An audit also asks who has access to what, whether your backups work, how staff handle email, and what you would do on a bad day. A useful small business audit covers:

  • Accounts and access. Who can sign in, with what protection, and who still has access who should not, such as former employees or old vendors.
  • Devices and software. Which computers, phones and servers you have, whether they are patched, and whether any are unsupported.
  • Network and Wi-Fi. How the firewall, router and wireless networks are set up, and whether guests and business devices share the same network.
  • Email and web protection. Whether messages are filtered and whether your domain is protected against impersonation.
  • Backups and recovery. Whether backups exist, whether they are protected from ransomware, and when anyone last restored one.
  • People and process. Whether staff know how to report a suspicious message, and who decides what when something goes wrong.

Frameworks such as the NIST Cybersecurity Framework and the CIS Controls organize these checks, which keeps an audit from depending on one person’s opinion. Compliance audits for HIPAA, PCI-DSS or CMMC use their own checklists on top of that.

Tip 1: Start with an honest inventory

You cannot protect what you have not listed. Before anyone audits anything, write down your computers, servers, cloud accounts, printers, phones, and the software your team uses daily. Include the unofficial items: the personal laptop someone uses on Fridays, the old file server in the closet, the free tool someone signed up for.

Gaps in the inventory are often the first findings. An audit that only examines what you already knew about will miss the things most likely to cause a problem.

Tip 2: Decide what you are protecting and from whom

Security work without priorities becomes a long list of everything. Ask which information would hurt most to lose or expose: customer records, payment details, patient files, bank access, your accounting data. Then think about the realistic threats to it, which for most small businesses are stolen passwords, phishing emails, ransomware, and mistakes by people who are trying to help.

That short list tells the auditor where to look hardest. A dental office and a landscaping company both need protection, but they do not need the same order of work.

Tip 3: Plan for the people, not just the technology

Most break-ins that start with a person, such as a click on a fake invoice, a reused password, or a request that sounded urgent. An audit should check what your team knows and how easy it is to do the right thing.

Short, regular training beats a yearly lecture. Make it easy to report a suspicious message, and make sure that reporting one is never treated as a mistake. Then retest a few months later so you can see whether habits changed.

What good results look like

A useful audit gives you a scorecard and a prioritized list: the few items to fix this month, the ones to schedule this quarter, and the ones that can wait. It uses plain language, and each item says what the risk is and what fixing it involves. If a report is 80 pages of scanner output, it will not get acted on.

Our free security review follows this approach. We look at who can get into your systems and how accounts and passwords are protected, whether devices are kept up to date, whether your backups can be restored, and how your network and Wi-Fi are set up. You get a scorecard and a prioritized list, and a call to go over it. Request one through our free network review page, or read more about our cybersecurity services. If you need a formal assessment for HIPAA, NIST, CMMC or PCI-DSS, our compliance consulting covers that too.

Frequently asked questions

How often should a small business have a cybersecurity audit?

At least once a year, and again after major changes such as a new office, a move to the cloud, a new line-of-business system, or a security incident. Lighter quarterly checks of accounts and backups are inexpensive and catch problems early.

What is the difference between an audit, a vulnerability scan and a penetration test?

A scan automatically checks systems for known weaknesses. A penetration test has a person try to break in. An audit is broader: it reviews technology, access, backups and habits against a framework or checklist. Many businesses start with an audit and add the others later.

Will an audit disrupt our work?

A review of settings, accounts and backups usually runs in the background with little or no downtime. Anything that could affect users, such as testing a restore, is scheduled with you first.

What do we need to prepare?

A list of your main systems, the people who administer them, and any compliance requirements you have. Access to your admin accounts helps, since that is where many of the biggest findings are.

Do we need an audit if we already have cyber insurance?

Insurance helps with the cost of an incident but does not prevent one. Insurers also ask detailed questions about the controls you have, so an audit helps you answer them correctly. See cyber insurance readiness.

Sources and further reading