Small Business Security Audit Checklist: 7 Steps (2026)
Run a practical small-business security audit with seven steps covering accounts, devices, backups, networks, vendors, monitoring, and incident response.

Affiliate Disclosure: This article contains affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you.
Reviewed for accuracy on July 21, 2026.
Security audits work best on a repeatable cadence, not only at the start of the calendar year. Run this review now if it has been 12 months since your last complete audit, or sooner after a major staffing, vendor, software, or infrastructure change. Then use the findings to set priorities for the next quarter.
This checklist is aligned with the six functions of NIST CSF 2.0 — Govern, Identify, Protect, Detect, Respond, and Recover — adapted for small businesses without a dedicated security team.
Why Your Business Needs a Security Audit Now
Your business has likely added tools, changed staff responsibilities, granted vendor access, or accumulated unpatched systems since its last review. A structured audit gives you a current baseline, identifies the highest-priority gaps, and turns security into a scheduled operating process instead of a once-a-year project.
Why This Matters
The 2026 Verizon Data Breach Investigations Report found that the non-intentional human element — including social engineering and errors — was present in 62% of breaches, while vulnerability exploitation became the leading entry point at 31%. Small businesses face the same threat landscape as larger organizations, often with fewer resources to detect and respond. A structured audit can reduce the likelihood and impact of common incidents by addressing the gaps attackers exploit most.
Your 7-Step 2026 Security Audit Checklist
1. Governance and Inventory
Before inspecting individual controls, establish who owns security decisions and what you are protecting.
Governance and Inventory Steps
Governance
- Name a security owner (even if it is the business owner or a designated manager)
- Document management sign-off on this audit and its findings
- Review or create a basic risk register listing your top five concerns
- Confirm cyber-insurance policy status and note any control requirements the insurer mandates
Asset and Data Inventory
- List all computers, mobile devices, network equipment, and IoT devices
- Document all SaaS subscriptions, cloud services, and on-premises software
- Map who has access to each system and at what privilege level
- Identify where sensitive data (customer PII, financial records, health data) is stored
- Classify data by sensitivity and note applicable retention requirements
- Review any security incidents since the last audit
Evidence to collect: Asset inventory export, SaaS subscription list, org chart with access roles, cyber-insurance policy, application/control questionnaire, applicable endorsements, and any security-control warranties or conditions.
SaaS and Cloud Configuration
If your business uses Microsoft 365 or Google Workspace, audit the security configuration as part of your inventory:
- Review admin accounts, conditional access policies, and sharing settings
- Check external sharing and forwarding rules
- Verify audit logging is enabled
- Review connected third-party apps and their permissions
The time required for this step depends on company size. A 10-person office with a handful of SaaS tools might finish in two to three hours; a 50-person business with multiple locations should expect a full day. Set the next three review dates at 90-day intervals before moving on.
2. Identity: Move from Passwords to Passkeys
Upgrade from simple passwords to passkeys and strictly enforced MFA. Password strength alone is insufficient. This step focuses on identity verification methods that resist phishing attacks, including those generated by AI tools.
Audit Steps
- Implement Passkeys: Switch compatible services (Google Workspace, Microsoft 365) to passkey authentication. Properly implemented FIDO passkeys substantially reduce phishing-based credential theft, though account-recovery abuse, session theft, and enrollment attacks remain risks that require separate controls. Workspace passkey behavior depends on administrator policy — verify that your Google or Microsoft Entra admin console has passkeys enabled for your organization.
- Audit MFA Methods: CISA ranks text- and email-based codes as the weakest MFA option. Manually entered authenticator-app codes are better but still phishable. Passkeys and FIDO security keys provide the strongest phishing resistance — require them for all admin accounts at minimum.
- Audit Credentials for Compromise, Not Age: NIST SP 800-63B Rev. 4 recommends against requiring periodic password changes unless there is evidence of compromise. Instead, audit for reused, exposed (check against breach databases), shared, default, and unmanaged credentials. Reset any that fail these checks.
- Run a password-health assessment using your business password manager's built-in tools
- Update default passwords on any equipment added since the last audit
- Review and document account-recovery procedures — recovery flows that bypass MFA are a common attack surface
Learn more about implementing passkeys and MFA in our guide to password managers and MFA.
Recommended Business Password Managers
Pricing verified July 2026. All prices are per user/month, billed annually, and exclude taxes.
| Tool | Price | Minimum | Best For |
|---|---|---|---|
| 1Password Business | $8.99/user/month | 1 user (Teams Starter Pack: $24.95/mo for up to 10) | Teams needing SSO integration and advanced admin controls |
| Bitwarden Teams | $4.00/user/month | 1 user | Cost-effective, open-source transparency |
| Bitwarden Enterprise | $6.00/user/month | 1 user | Enterprise features with SSO and directory sync |
| NordPass Business | From $3.99/user/month | 5 users (Business); 10 users (Teams) | Budget-friendly; verify current promotional pricing and term |
Pricing changes frequently. Check vendor pages before purchasing.
Evidence to collect: MFA policy export from each identity provider, password-health report, list of accounts without MFA, recovery-procedure documentation.
Get 1Password Business3. Software Patching and Lifecycle Management
Unpatched software remains a common entry point for automated ransomware attacks. The 2026 Verizon DBIR found vulnerability exploitation is now the leading individual breach vector at 31%. Use this audit to retire unsupported software, install outstanding fixes, and automate your patching schedule.
Update Priority Framework
-
Critical Security Patches (Immediate)
- Verify that every device runs an operating-system release currently supported for its edition and continues to receive security updates (for example, the current Windows 11 feature update for your edition, or macOS Tahoe 26)
- Antivirus and endpoint-security software
- Web browsers and email clients
-
Firmware (Often Overlooked)
- Log into firewalls, routers, and wireless access points to apply outstanding firmware patches
- Network equipment firmware — check manufacturer support status
- Mobile device operating systems
-
Third-Party Applications
- Ensure browsers (Chrome, Edge) and productivity apps (Zoom, Adobe) are set to auto-update
- Feature updates for productivity software
Windows 10 Migration
General Windows 10 support ended October 14, 2025. Microsoft offers two separate Extended Security Updates (ESU) programs as a temporary migration bridge. The Consumer ESU program covers eligible personal-use devices through October 12, 2027. Organizations can purchase commercial ESU coverage for up to three years, through October 2028, starting at $61 per device for the first year, with the price doubling each subsequent year. Several LTSC editions have different lifecycle dates. ESU should be treated as a temporary bridge, not a long-term operating-system strategy. Prioritize migration to Windows 11 Pro and track remaining Windows 10 devices on a remediation timeline.
Audit Process
- Check Windows Update status on all computers
- Review Mac Software Update on Apple devices
- Verify that automatic updates are enabled where appropriate — our device-by-device automatic updates guide covers the exact settings for Windows, macOS, mobile, routers, and NAS
- Update router and network equipment firmware
- Review mobile device management policies
- Generate a supported-device report showing OS version, patch date, and support status for each endpoint
For organizations managing more than a handful of endpoints, automating this process removes manual oversight gaps. Action1's free tier covers up to 200 endpoints with automated OS and third-party patching, vulnerability scanning, and compliance reporting at no cost (free accounts use community support rather than vendor-included support). For deeper, audit-ready vulnerability assessment beyond patch status, see our Tenable Nessus review.
Evidence to collect: Patch-status report per endpoint, list of unsupported OS/software with migration timeline, auto-update policy screenshots.
4. Employee Security Training Refresher
The 2026 Verizon DBIR reports a non-intentional human element in 62% of breaches. Rather than blaming individuals, effective security programs focus on the controls that make mistakes less consequential — and on training that changes behavior.
Mimecast's 2026 State of Human Risk report surveyed 2,500 IT and security decision-makers across nine countries. Mimecast also reports that 8% of employees account for 80% of observed security incidents, supporting a targeted, role-based approach rather than one-size-fits-all training.
2026 Training Focus Areas
- Verification Procedures, Not AI Detection: Do not train staff to identify whether an email was "written by AI." Instead, train them to verify any unexpected payment, credential, MFA, data-sharing, or access request through a known secondary channel — a callback to a pre-established phone number, in-person confirmation, or dual approval for financial changes. The verification channel must be genuinely independent; if email and your messaging platform share the same identity provider, both may be compromised simultaneously.
- Voice and Video Verification: Confirm your team has a verbal verification procedure for inbound financial or access requests — AI voice cloning and deepfakes have made caller identity alone insufficient for high-stakes requests. See our AI vishing guide for implementation steps.
- Shadow AI Policy: Clear guidelines on what business data employees can and cannot input into public AI tools
- Mobile Hygiene: Verifying app permissions on personal devices used for work (BYOD)
- Social Media Security: Protecting business information on personal profiles
- Remote Work Best Practices: Securing home office environments
Training Delivery and Cadence
Use two complementary activities at different cadences:
- Quarterly micro-training (10–15 minutes): Short, focused modules covering one topic — verification procedures, AI policy updates, mobile security. Delivered via platforms like KnowBe4 or Proofpoint. Adjust to monthly for high-risk roles (finance, IT admin, executives).
- Monthly simulated phishing: Automated phishing tests with immediate feedback and remedial training for employees who engage with the simulated attack.
- AI usage policy documentation acknowledged by each employee
This is a recommended cadence, not an industry standard. Adjust based on your risk profile and incident trends.
Key Metrics to Track
- Training completion rate by role
- Phishing simulation click-through and report rates
- Security incident reports before and after training cycles
- AI tool usage compliance rate
Evidence to collect: Training completion records, phishing simulation results, signed AI-usage policy acknowledgments.
5. Backup System Validation
Regular backups protect against ransomware, hardware failure, and accidental deletion. However, backups are only valuable if they actually work when needed — and if attackers cannot reach them.
Backup Testing Protocol
-
Verify Backup Completion
- Check that all scheduled backups completed successfully
- Review backup logs for any error messages
- Confirm all critical data sources are included in backup sets (databases, SaaS exports, email archives — not just file shares)
-
Test Recovery — Not Just File Restore
- Perform a representative system restore, not just a single-file test. For ransomware recovery, you need to confirm that full-system or full-application recovery works.
- Time the recovery process and compare against your Recovery Time Objective (RTO)
- Verify data integrity and completeness after restoration
- Confirm recovery meets your Recovery Point Objective (RPO) — how much data loss is acceptable?
-
Secure Backup Infrastructure
- Maintain at least one offline or immutable backup copy that ransomware cannot encrypt
- Use separate, dedicated credentials for backup administration — not the same accounts used for daily operations
- Require MFA on backup console access
- Confirm that off-site or cloud backups are functioning and accessible from a separate location
Backup Strategy: 3-2-1 Plus Immutable
The classic 3-2-1 rule (three copies, two media types, one off-site) is a valid baseline. For ransomware resilience, add an immutable or air-gapped copy and isolate backup-admin credentials.
- Cloud Solutions: iDrive, Acronis Cyber Protect, or Backblaze for automated protection
- Local Backups: Network attached storage like Synology DS925+ or UGREEN NASync for quick recovery
- Testing Schedule: Monthly representative restore tests, quarterly full-system recovery exercises
Define RPO and RTO
If you have not already, define these for your business-critical systems:
- RPO (Recovery Point Objective): Maximum acceptable data loss measured in time. If your RPO is four hours, your backups must run at least every four hours.
- RTO (Recovery Time Objective): Maximum acceptable downtime. If your RTO is eight hours, you need to confirm you can restore operations within that window.
Document which systems are highest priority for recovery and in what order.
Evidence to collect: Backup completion logs, restoration test results with timestamps, RPO/RTO documentation, backup-admin account inventory.
For detailed comparisons of backup solutions and implementation strategies, see our complete guide to business backup solutions.
6. Network Security Assessment
With hybrid and remote work as the norm, your security boundary extends well beyond the office firewall. This audit verifies that remote connections, wireless networks, and cloud access points are configured securely.
Network Checklist
- Encryption Standard: Verify all Wi-Fi access points use WPA3 where supported. WPA2-only hardware is not automatically end-of-life — check the manufacturer's support status and firmware availability for each device. Prefer WPA3 where possible, but base replacement decisions on the device's actual support lifecycle, not encryption protocol alone.
- Guest Network Isolation: A separate SSID does not prove isolation. Verify that guests cannot reach internal subnets, management interfaces, printers, or other clients. Test this by connecting to the guest network and attempting to reach internal resources.
- VPN and Remote Access: If you use a VPN, ensure it is patched and running current firmware. For organizations evaluating alternatives, CISA supports movement toward Zero Trust and SASE architectures, but ZTNA is not a drop-in replacement for every VPN workload. Base the decision on your applications, identity controls, and administrative-access requirements. Options include NordLayer Zero Trust and Cloudflare Zero Trust.
- Scan your network to identify all connected devices
- Remove or isolate any unrecognized equipment
Wi-Fi Security Review
- Verify WPA3 encryption is enabled on compatible access points
- For WPA2-only hardware, check firmware updates and manufacturer support status — schedule replacement based on lifecycle, not protocol alone
- Rotate shared Wi-Fi keys after staff or vendor turnover, suspected compromise, or unauthorized disclosure. For environments with frequent changes, consider WPA2/WPA3-Enterprise with per-user credentials instead of shared keys.
- Test guest network isolation (can a guest-network device reach internal IPs?)
- Check for rogue access points
Email Authentication
Verify that your domain has properly configured email authentication to reduce spoofing and improve deliverability:
- SPF: Confirm your DNS includes an SPF record listing authorized mail senders
- DKIM: Verify DKIM signing is enabled on your email platform
- DMARC: Publish a DMARC policy (start with
p=nonefor monitoring, move top=quarantineorp=rejectafter confirming legitimate mail passes)
Firewall Configuration
- Review firewall rules and remove outdated permissions
- Verify that unnecessary ports are closed
- Update the firewall firmware to the latest version
- Test intrusion detection/prevention systems if installed
Network Monitoring Options
| Solution | Best For | Key Features |
|---|---|---|
| UniFi Dream Machine | Small to medium businesses | Intuitive management, built-in IDS/IPS, no subscription |
| SonicWall TZ Series | Growing companies | Integrated threat prevention, VPN, and content filtering |
| Meraki MX Series | Multiple locations | Cloud-managed, centralized control (requires active subscription license) |
For businesses ready to upgrade their network infrastructure, explore our complete guide to UniFi networking equipment.
Evidence to collect: Wi-Fi encryption settings per access point, guest-isolation test results, firewall rule export, SPF/DKIM/DMARC records, connected-device inventory.
7. Vendor Access and Third-Party Risk
Third-party vendors often require access to your systems, but unmanaged vendor connections are a frequent breach vector.
Active Vendor Review
- List all vendors with system access and their current permission levels
- Verify current contracts, access needs, and data-handling terms
- Remove access for discontinued services immediately
- Require MFA for all vendor accounts
- Apply the principle of least privilege — grant the minimum access necessary for each vendor's role
- Implement time-limited access where possible
Joiner/Mover/Leaver Reviews
Access reviews should not be limited to vendors. Conduct a joiner/mover/leaver audit for internal staff:
- Joiners: Were accounts provisioned with appropriate (not excessive) access?
- Movers: When staff changed roles, was prior access revoked and new access granted to match?
- Leavers: Are all accounts for former employees fully deactivated? Check email, VPN, SaaS tools, cloud consoles, and shared credentials. Recurring issue we have observed in client assessments: offboarded employee accounts remaining active in secondary SaaS tools that were not part of the formal deprovisioning checklist.
Separate Administrator Accounts
Daily-use accounts should not have administrative privileges. Verify that admin access to critical systems (email platform, backup console, domain registrar, cloud infrastructure) uses dedicated admin accounts with MFA.
Vendor Security Terms
For each active vendor, confirm:
- Breach-notification obligations and timeline
- Subprocessor disclosure requirements
- Data deletion and return procedures upon contract termination
- Offboarding checklist for removing vendor access
Evidence to collect: Vendor access log with permission levels, contract review dates, leaver-account audit results, admin-account inventory.
Cross-Cutting Controls: Detection, Response, and Recovery
These controls span all seven audit areas and determine how quickly the business can identify, contain, and recover from an incident.
Endpoint Detection and Alert Ownership
- Confirm endpoint detection and response (EDR) or managed detection is active on all endpoints
- Assign a named owner responsible for reviewing security alerts (even if it is an external MSP)
- Centralize available logs and configure near-real-time alerts for high-risk events (failed login attempts, privilege escalation, new admin accounts, disabled security controls). Review actionable alerts daily.
- At least monthly, verify that critical log sources (firewall, email platform, identity provider) are still reporting, retention is adequate, and alert rules remain enabled
Incident Response Contacts
Document and distribute:
- Internal escalation contacts (who to call first, second, third)
- External contacts: IT provider, cyber-insurance carrier, legal counsel, law enforcement
- A simple decision tree: "If you suspect X, do Y and notify Z"
- Schedule a tabletop exercise at least annually — walk through a realistic scenario (ransomware, BEC, data theft) and identify gaps in your response plan
Florida Breach Notification Requirements
Because this guide targets Miami-area businesses, a brief note on Florida law: under Florida Statutes §501.171, businesses must generally notify affected individuals within 30 days after determining that a qualifying breach occurred (with a possible 15-day extension for good cause). Breaches affecting 500 or more Florida residents also require notification to the Florida Department of Legal Affairs.
This is general information, not legal advice. Consult an attorney for guidance on your specific obligations, and ensure your incident-response contacts include legal counsel who can advise on notification requirements.
Audit Worksheet
Use this format to record findings for each control. Copy it into a spreadsheet or document and complete one row per control area.
| Control | Evidence Inspected | Status | Business Impact | Priority | Owner | Due Date | Retest Date |
|---|---|---|---|---|---|---|---|
| MFA enabled on all admin accounts | Identity provider MFA policy export | Pass / Partial / Fail / N/A | High / Medium / Low | P1 / P2 / P3 | [Name] | [Date] | [Date] |
| All endpoints on supported OS | Patch-status report | Pass / Partial / Fail / N/A | |||||
| Backup restore tested | Restoration log with timestamp | Pass / Partial / Fail / N/A | |||||
| Guest Wi-Fi isolated | Isolation test results | Pass / Partial / Fail / N/A | |||||
| Former-employee accounts deactivated | Leaver audit results | Pass / Partial / Fail / N/A | |||||
| Vendor access reviewed | Vendor access log | Pass / Partial / Fail / N/A | |||||
| EDR active on all endpoints | EDR dashboard export | Pass / Partial / Fail / N/A | |||||
| Incident response contacts documented | Contact list, decision tree | Pass / Partial / Fail / N/A | |||||
| SPF/DKIM/DMARC configured | DNS record check | Pass / Partial / Fail / N/A | |||||
| Cyber-insurance controls met | Policy, application questionnaire, endorsements | Pass / Partial / Fail / N/A |
What "Pass" looks like for each control:
- MFA: Policy export shows MFA required for all users, with phishing-resistant methods for admins
- Patching: No endpoint runs an unsupported OS. Known-exploited and internet-facing critical vulnerabilities are remediated according to vendor or CISA deadlines; all other security updates meet the company's documented, risk-based patching SLA
- Backups: Successful representative restore completed within RTO; immutable copy verified
- Network: Guest devices confirmed unable to reach internal subnets; WPA3 enabled where supported
- Access: No active accounts for former staff; all vendor access reviewed within 90 days
- Detection: Named alert owner, alerts reviewed on defined cadence, logging enabled on critical systems
- Incident Response: Contacts documented, distributed, and tested via tabletop within the past year
Creating Your Security Calendar
| Frequency | Tasks |
|---|---|
| Monthly | Review backup logs, check critical patch status, review security alerts, run phishing simulation |
| Quarterly | Credential audit, software lifecycle review, training session, vendor access review, guest-isolation test |
| Annually | Full audit using this checklist, policy review, tabletop exercise, insurance review, professional assessment |
Time required varies significantly by company size. A 10-user business with simple infrastructure might complete a quarterly review in two to three hours. A 25-user business with multiple locations and regulated data should budget a full day for quarterly reviews and two or more days for the annual audit.
Budget Considerations
The costs below are planning estimates for two example configurations. Actual costs depend on product tier, seat count, storage volume, retention, and billing term. Verify current pricing before budgeting.
Example: 10-User Office
Monthly recurring (estimated):
- Password manager (e.g., 1Password Business at $8.99/user/month): ~$90
- Backup solution (e.g., iDrive or Acronis): $50–150 depending on data volume
- Endpoint security (e.g., Bitdefender Business or ESET): $30–80
- Security training platform: $25–50
Estimated monthly total: $195–$370
One-time costs (estimated):
- Network equipment upgrade (UniFi gateway + access points): $500–1,500
- UPS backup power: $200–500
Example: 25-User Office
Monthly recurring (estimated):
- Password manager: ~$225
- Backup solution: $100–250
- Endpoint security: $75–200
- Security training platform: $50–100
- Managed detection or basic SIEM: $100–300
Estimated monthly total: $550–$1,075
One-time costs (estimated):
- Network equipment upgrade: $1,000–3,000
- UPS backup power (multiple units): $400–1,200
These estimates exclude labor for configuration, management, and ongoing monitoring. If you outsource IT management, factor in MSP costs.
When to Call in Professional Help
While this checklist covers self-assessment fundamentals, it is not a substitute for professional security testing. Understand the differences:
- Self-assessment (this checklist): Reviews configurations, policies, and processes against a framework. Useful for baseline hygiene.
- Vulnerability scan: Automated tool that identifies known vulnerabilities across your network and systems. Typically included in tools like Action1 or Nessus.
- Penetration test: Simulated attack by a security professional to identify exploitable weaknesses. Scope, methodology, and cost vary widely.
- Regulatory or assurance assessment: A formal review whose form depends on the requirement — for example, a HIPAA Security Rule risk analysis (HHS does not recognize an official HIPAA "certification"), a PCI DSS self-assessment or QSA-led validation, or a SOC 2 examination performed by a CPA firm.
Consider professional assistance if you discover:
- Evidence of unauthorized access or suspicious activity
- Complex regulatory, contractual, or assurance requirements, such as HIPAA, PCI DSS, or SOC 2
- Network infrastructure that has not been professionally reviewed in two or more years
- A need for formal penetration testing or compliance validation
- Lack of internal expertise for critical security components
Professional assessment costs are scope-dependent. A basic vulnerability scan may cost less than a configuration review, which costs less than a penetration test or formal compliance assessment. If you are evaluating iFeeltech for this work, contact us for a scoped proposal.
Schedule Security AssessmentRelated Implementation Guides
- Password Managers and MFA — detailed comparison and setup instructions
- 1Password Business Review — in-depth admin console, SSO, and cost analysis
- Action1 Patch Management — free-tier walkthrough for up to 200 endpoints
- Tenable Nessus Review — vulnerability scanning beyond patch status
- Automatic Updates Setup Guide — device-by-device configuration
- AI Vishing and Deepfake BEC Guide — voice verification protocols
- Small Business Network Security — comprehensive network protection
- UniFi Buyer's Guide — networking equipment selection
- Business Backup Solutions — backup platform comparisons
- Tech Stack Teardown — audit unused SaaS for orphaned access
This security audit checklist is designed for general small-business use and is based on publicly available frameworks including NIST CSF 2.0 and CISA guidance. Companies in regulated industries may have additional compliance requirements. The Florida breach-notification summary is general information, not legal advice. For industry-specific or legal guidance, consult with qualified professionals.
Get Your Free Security ConsultationRelated Articles
More from Cybersecurity

Are We Being Hacked or Are Our Computers Just Slow? A Business Owner's Diagnostic Guide
Learn to distinguish between normal computer performance issues and cybersecurity incidents. Systematic diagnostic framework with checklists, warning signs, and guidance on when to call professionals.
19 min read

Small Business Cybersecurity Guide: Top Tools 2026
Comprehensive guide to cybersecurity software for small businesses. Reviews platform security, network infrastructure, and endpoint protection across three implementation tiers with budget recommendations. Updated for AI threats and cyber insurance compliance.
18 min read

Passkeys for Small Business: A Practical Implementation Guide
Complete passkeys implementation guide for small businesses. ROI analysis, 90-day rollout strategy, employee training, security considerations, and cost comparison with traditional authentication.
15 min read
