This small business cybersecurity checklist closes that gap. In about 30-45 minutes, it walks you through 30 practical checks, in plain English, so you know where your company stands. It's built for businesses with 5 to 25 employees, too big for one shared login, too small for a security team. Mark each item, then use the worksheet and score below to decide what to fix first. Treat "Unknown" as a gap until it's verified.
This checklist is general educational information, not a formal cybersecurity audit, penetration test, compliance certification, or legal opinion. Requirements vary by industry and location, and no checklist guarantees protection against every incident.
Key takeaways
Built for companies with 5–25 employees and no full-time IT staff, a self-assessment, not a formal audit.
Mark every item Complete, Needs Attention, or Unknown; treat "Unknown" as a gap.
Use the 0–60 point score and 90-day action plan to decide what to fix first.
Free to use, with no obligation to hire anyone afterward.
How to use this cybersecurity checklist
Use three statuses:
Complete (implemented and verified, not just set up once)
Needs Attention (partial or inconsistent)
Unknown (nobody can confirm it works treat as a gap)
Verification beats installation. Backups shouldn't be marked "Complete" just because software is running, the real test is whether someone has restored a file and confirmed it's intact. That logic applies throughout.
Copy the worksheet below into a spreadsheet and assign an owner and target date to anything not Complete. CISA's Cyber Essentials guide is a useful companion resource.
Accounts and authentication
Weak account security is one of the most common ways attackers get in a stolen password or unattended login can expose everything connected to it.
1. MFA is enabled on email, cloud apps, banking, accounting, VPNs, and admin accounts.Multi-factor authentication (MFA) requires a second identity check beyond a password. Enforce it, don't just offer it.
2. Every employee has a unique account. Shared logins hide who did what and can't be individually disabled.
3. Former employees' accounts are disabled promptly. Access should end the day someone leaves. Audit active accounts against your staff list today.
4. Administrator access is limited to people who need it. More admins mean more risk if one account is compromised.
5. Separate admin accounts are used for administrative work. Anyone with admin rights should use a normal account for email and browsing, so a phishing compromise doesn't hand over admin control too.
Passwords and access control
Small, practical password habits make a large difference in overall risk.
6. Business passwords are unique and not reused. One reused password exposes every account it touches if it leaks elsewhere.
7. A business password manager is available. It generates and stores strong, unique passwords so staff aren't tempted to reuse simple ones.
8. Shared passwords have been eliminated or replaced with delegated access. Shared logins can't be tracked or revoked individually.
9. Default passwords have been changed on routers, printers, cameras, and other devices. Defaults are publicly known and an easy foothold, printers and cameras are often overlooked.
10. Employees have access only to what their role requires ("least privilege"). Review shared drives and remove access to nobody's job needs.
Devices and software
Outdated or unmanaged devices are an easy entry point, since known software flaws are often public knowledge.
11. All computers and mobile devices are inventoried. You can't secure a device you don't know exists. Build a simple list of devices, owner, and OS.
12. Operating systems and applications are still supported. Past its end-of-life date, software never gets patched for new vulnerabilities.
13. Automatic security updates are enabled. Manual patching gets delayed; automatic updates close gaps faster.
14. Endpoint protection is installed, active, and updated. Antivirus/anti-malware is a basic safety net, though not a complete defense alone.
15. Full-disk encryption and automatic screen locking are enabled. An encrypted, locked laptop is far less likely to expose data if lost or stolen.
Email and phishing protection
Email remains one of the most common ways attackers reach small businesses often through convincing, targeted messages, not obvious spam.
16. Employees know how to report suspicious messages. Fast reporting can stop an attack before money moves.
17. Payment and bank account changes require independent verification. Confirm any change request through a separate channel like a call to a known number before acting. This is a top defense against business email compromise.
18. Email filtering is configured for spam, malicious links, and dangerous attachments. Heartland Computer's Cybersecurity Services can help configure this correctly.
19. SPF, DKIM, and DMARC are configured for your email domain. These records Sender Policy Framework, DomainKeys Identified Mail, and Domain-based Message Authentication, Reporting, and Conformance make your domain harder to impersonate. Getting them right usually needs IT support.
20. Employees receive recurring cybersecurity awareness training. Threats change, so one-time training isn't enough. Free resources are available from CISA.
Network and remote access
The network is the foundation everything runs on, and remote work has made its edges harder to define.
21. Business Wi-Fi uses modern encryption and a strong admin password. Use WPA2/WPA3 and change the router's default admin login.
22. Guest Wi-Fi is separated from business systems. An isolated guest network keeps a compromised guest device from reaching internal resources.
23. Router, firewall, and access-point firmware are updated. Firmware can carry vulnerabilities like any software.
24. Remote access is protected by MFA and disabled when unnecessary. VPNs and remote-desktop tools are prime targets for attackers.
25. Employees use an approved secure connection for sensitive work away from the office. Document an approved method, like a company VPN. Heartland Computer's Network setup and support can help design this.
Data, backups, and recovery
Backups determine whether a bad day becomes a minor inconvenience or a business-ending event.
26. The business knows where sensitive data is stored. You can't protect data you don't know you have.
27. Critical data is backed up automatically. Manual backups get skipped when things are busy.
28. Backups follow an appropriate 3-2-1 strategy- 3 copies, 2 media types, 1 offsite. This protects against hardware failure, theft, and fire, unlike one drive next to the server.
29. Backups are protected from ransomware and unauthorized access. Attackers increasingly target backups directly, so keep at least one copy offline or immutable. Heartland Computer's Backup and Disaster recovery services are built around this exact problem.
30. A real file or system restoration has been tested and documented. Untested backups sometimes fail when needed most, installing backup software isn't the same as having a working one.
Score your business
2 points - Complete and verified
1 point - Partial or inconsistent
0 points - Missing or unknown
Maximum score: 60 points.
50–60: Good baseline- keep monitoring and testing.
35–49: Moderate gaps- build a prioritized plan.
0–34: Significant gaps- start with identity/access, updates, endpoint protection, and backups.
This score is educational only, not a formal risk rating, insurance assessment, compliance result, or guarantee of protection.
Prioritized action plan
First 24 hours: Enable MFA on email and admin accounts. Remove former employees' access. Change reused or default passwords. Confirm backups are running. Update or isolate unsupported devices.
First 30 days: Complete an account and device inventory. Deploy a password manager. Review Wi-Fi and remote access. Train staff in phishing and payment verification. Test one file restoration.
Within 90 days: Fix SPF, DKIM, and DMARC. Document an incident-response plan. Review vendor and remote-access permissions. Build a patch-management process. Get a professional assessment if gaps remain.
Why this checklist still matters in 2026
Attack methods keep evolving, but these fundamentals still address what small businesses face today: AI-assisted phishing, fake AI apps disguising malware, business email compromise, deepfake voice scams, ransomware that targets backups directly, shadow AI (staff pasting sensitive data into unapproved tools), and cloud-account takeovers from stolen credentials. The FBI's Internet Crime Complaint Center has repeatedly flagged business email compromise as one of the costliest cybercrime categories.
Older threats haven't gone away- phishing, stolen credentials, weak passwords, and unpatched devices remain the most common causes of compromise. Review this checklist annually, ideally alongside fiscal-year planning.
When Should a Business Hire an IT Provider?
Consider outside help if you can't verify your backups, manage accounts and devices, secure remote access, or respond confidently to a phishing or ransomware incident. An IT provider can help close these gaps and keep your security controls maintained.
Not sure how many items on this list your business has completed or verified? Heartland Computer works with small businesses in Omaha, Nebraska, and Council Bluffs, Iowa, to review accounts, devices, networks, backups, and security processes, then help prioritize what matters most.
1. What is a small-business cybersecurity checklist?
A structured list of security controls a company reviews to understand its protections and find gaps. It's a self-assessment tool, not a certification.
2. What are the most important cybersecurity steps for a small business?
CISA and NIST point to MFA, removing former employees' access, updated software, endpoint protection, and tested backups.
3. Does a small business really need MFA?
Yes. MFA significantly reduces account-takeover risk even if a password is stolen, and it's one of the lowest-cost, highest-impact controls available.
4. Is antivirus software enough to protect a business?
No. It's one layer, best paired with MFA, updated software, employee training, and tested backups.
5. How often should a small business review its cybersecurity?
At least annually, and after any major change, new software, new staff, or an incident.
6. How often should business backups be tested?
No universal rule, but many businesses aim for at least quarterly. Testing means restoring data, not just confirming backup jobs ran.
7. What should an employee do after clicking a suspicious link?
Disconnect the device from the network, if possible, avoid entering credentials, and report it to IT or security immediately.
8. What should a business do after a suspected ransomware attack?
Disconnect affected systems, avoid paying or negotiating without guidance, and contact a qualified IT professional right away.
9. Is this checklist a formal cybersecurity audit?
No. It's educational information for self-assessment, not a formal audit, penetration test, compliance certification, or legal opinion.
10. When should a small business hire an IT provider?
When you can't verify backups work, nobody owns account management, you've had an incident, or you're simply unsure where you stand.
Disclaimer: This checklist is general educational information. It is not a formal cybersecurity audit, penetration test, compliance certification, or legal opinion. Cybersecurity requirements vary by industry and location, and no checklist can guarantee protection against every cyber incident.
Our Partners
Technicians online now
Computer trouble? We'll fix it live — right on your screen.
Connect with a technician in minutes for a secure remote session. No appointment, no waiting room, no jargon — just your problem, solved.
Thank you for trusting us with your IT services need. Did our staff do a good job of
taking care of your needs? Were you happy with the work we did? We sincerely hope our team resolved
your IT matter to your satisfaction. By sending us your feedback, you give us the opportunity to
make your experience even better the next time you join us.