Small Business Cybersecurity Checklist: 20 Things to Review Every Year

By J. Mesa

The start of a new year is a good time to check your locks. Staff changed, you added software, a vendor came and went. Each change can leave a gap.

This checklist covers twenty items in five groups. Set aside an afternoon, work through it, and write down what you find.

Why review your security every year?

  • People join and leave, and their access lingers
  • Software reaches the end of its support
  • New services get added without a security review
  • Backups fail without anyone noticing
  • Insurers and clients ask for proof

A yearly review catches what daily work misses.

Accounts and access

1. List every account and who can use it. Include email, banking, cloud storage, your website, your domain, and social media.

2. Remove access for former employees and vendors. Check shared mailboxes and shared passwords too.

3. Confirm multi-factor authentication is on for every account that offers it. Start with email, banking, and administrator accounts.

4. Check for shared or reused passwords. Give each person their own login and a password manager.

5. Review administrator rights. Few people should have them, and nobody should use an administrator account for daily work.

Devices and software

6. Inventory your devices. List every computer, phone, tablet, server, router, and printer.

7. Confirm automatic updates are on for operating systems, browsers, and applications.

8. Identify anything that no longer receives security updates and plan its replacement.

9. Check that security software is installed and current on every computer.

10. Confirm laptops and phones are encrypted and lock after a few minutes.

Network

11. Update your router and firewall, and change any default password.

12. Check your Wi-Fi. Use WPA2 or WPA3 with a strong password, and keep guests and smart devices on a separate network.

13. Review remote access. Close anything exposed to the internet that you don’t need, and require multi-factor authentication for the rest.

Data and backups

14. Know where your sensitive data lives. Customer records, employee files, and financial information.

15. Test a restore from backup. Time it. Confirm one copy sits offline or offsite.

16. Delete data you no longer need, and dispose of old devices and paper securely.

17. Review cloud sharing settings and remove public links.

People and plans

18. Train every employee on phishing and safe data handling, and record who attended.

19. Review your incident response plan. Update the names and phone numbers, and print a copy.

20. Review your vendors, your insurance, and your compliance duties. Confirm who holds your data, what your cyber policy requires, and which rules apply to you.

How long does the checklist take?

For a business with fewer than 25 people, plan on three to four hours for the first pass. It goes faster each year, because you keep the lists you made.

Who should do it?

Name one person to lead, often the owner or the office manager, and involve whoever handles IT. Ask your IT provider for the device and update reports. The person who leads does not need to be technical. They need to ask each question and write down the answer.

What should I do with the results?

Sort what you find into three groups:

  1. Fix now. Missing multi-factor authentication, active accounts for former staff, failed backups.
  2. Fix this quarter. Unsupported devices, missing training, an outdated plan.
  3. Plan and budget. Larger replacements and projects.

Assign each item an owner and a date.

What are the most common problems this review finds?

  • An email account without multi-factor authentication
  • A former employee who can still log in
  • A backup that stopped running months ago
  • A router that has never been updated
  • A shared password that everyone knows
  • An incident plan with phone numbers for people who left

Any one of these is an open door.

How do I prove I did the review?

Keep a dated copy of the completed checklist, with notes on what you found and fixed. Insurers, clients, and auditors accept this kind of record as evidence of a security program.

Should I review more than once a year?

Some items deserve a shorter cycle.

  • Monthly: confirm that updates and backups ran
  • Quarterly: review who has access to what
  • Yearly: the full checklist, training, and the plan
  • After any change: a new system, a new vendor, or a departing employee

Is a checklist the same as a risk assessment?

No. A checklist confirms that basic controls are in place. A risk assessment looks at your specific business: what data you hold, what could go wrong, how likely it is, and what it would cost. The checklist is the starting point. An assessment tells you where to invest next.

What if I find something I can’t fix?

Write it down with the reason, and reduce the risk another way. An old system you can’t replace yet can be taken off the internet and restricted to the people who need it. A documented risk with a plan is far better than an unknown one.

Does this checklist cover compliance?

It covers the basics that most standards share. If you accept payment cards, handle health information, or provide financial services, you have added duties under PCI-DSS, HIPAA, or the FTC Safeguards Rule. Use this list as a foundation and check the specific requirements that apply to you.

Where do I start if I am short on time?

Do these five first. They take under an hour.

  1. Turn on multi-factor authentication for email.
  2. Disable accounts for former staff.
  3. Check that your last backup succeeded.
  4. Confirm automatic updates are on.
  5. Print your emergency contact list.

How long does this checklist take?

Plan for one working day. Most owners finish the account review and the backup test before lunch, then spend the afternoon on updates and the phone call to the bank. Put the date on your calendar now and invite the person who handles your IT. A checklist you schedule gets done. A checklist you save for a slow week waits until after the breach.

Your next step

Put the review on your calendar this month and work through all twenty items. If you want an outside view, Cerberus Cybersecurity performs risk and compliance assessments that cover this checklist and go deeper into the risks specific to your business. Contact us to schedule yours.