A 30-minute security self-check for your small business

Eight quick checks that catch the gaps behind most small-business break-ins: email without two-step sign-in, reused passwords, missed updates, an exposed router and untested backups. No special tools needed.

By John E. Phillips ·

By the end of this guide, you'll have a short written list of where your business stands on the eight basics that stop most attacks, and what to fix first.

Who it's for

Owners and office managers of small businesses, roughly 1 to 50 people, without a full-time security person. You'll need admin access to your email system (Microsoft 365 or Google Workspace, for example) and your router, and about 30 minutes. Keep a notepad or a spreadsheet open: for each check, write Pass or Fix, and a note.

These checks don't replace a professional assessment, but they cover the gaps that attackers find first, because they are the easiest to find.

Steps

  1. Email: is two-step sign-in on for everyone? (5 minutes)

    Email is the key to everything else, because every password reset goes to it. In your email admin console, check that two-step sign-in (also called MFA or 2-Step Verification) is required for every account, not just available. In Microsoft 365 look for "Security defaults" or Conditional Access; in Google Workspace, 2-Step Verification enforcement.

    Pass if every account, including yours and any admin accounts, must use a second step to sign in.

  2. Passwords: are any reused or already leaked? (5 minutes)

    Ask whether everyone uses a password manager, and whether any shared passwords are written down or reused across services. Then check each business email address at haveibeenpwned.com, which shows whether it appeared in a known data breach. Any address that did should have its passwords changed everywhere they were used.

    Pass if the team uses a password manager and no reused or leaked passwords remain.

  3. Accounts: who has access, and who still should? (5 minutes)

    List who has admin rights in your email system, accounting software, website and any cloud services. Remove anyone who has left, and anyone who doesn't need admin access for their job. People who do need admin rights should use a separate admin account, not their everyday one.

    Pass if every account belongs to a current person, and admin rights are limited to the few who need them.

  4. Updates: is everything still supported and updating itself? (5 minutes)

    Check that automatic updates are on for computers, phones and web browsers. Look for anything no longer supported: for example, Windows 10 stopped getting free security updates on October 14, 2025, so any Windows 10 computer without paid extended updates is falling behind every month.

    Pass if every device is on a supported system and updates install automatically.

  5. Router: is the front door locked? (5 minutes)

    Log in to your router or firewall and check four things: the admin password isn't the one printed on the label; remote administration (managing the router from the internet) is off; the firmware is up to date; and the list of port forwards contains nothing you don't recognise. Remote desktop (port 3389) forwarded to a computer is a common way in for ransomware.

    Pass if all four are true.

  6. Backups: could you restore last week's files today? (3 minutes)

    Check that your important data is backed up automatically, that one copy is offsite, and that someone has restored a file from it in the last few months. If you're not sure, follow Set up 3-2-1 backups that actually restore.

    Pass if backups run automatically, one copy is offsite, and a restore has been tested recently.

  7. Laptops and phones: would a lost device leak your data? (2 minutes)

    Check that laptops have disk encryption turned on (BitLocker on Windows, FileVault on a Mac) and that laptops and phones lock after a few minutes and need a PIN, password or fingerprint to open.

    Pass if every laptop is encrypted and every device locks itself.

  8. A plan: who do you call? (2 minutes)

    Write down, somewhere you can reach without your computer, who to call if something goes wrong: your IT support, your bank's fraud line, your insurer (if you have cyber insurance), and how to reach your email admin. Include a rule that payment or bank-detail changes requested by email are always confirmed by phone, using a number you already have.

    Pass if the list exists, is on paper or a phone, and the team knows the payment-change rule.

Check it worked

You should have eight lines, each marked Pass or Fix. For each Fix, write who will do it and by when; the email and backup items come first, since they do the most damage when they fail. Then prove the most important one: open a private browser window and sign in to your email. You should be asked for the second step. Put a reminder in your calendar to repeat this check every three months.

Common mistakes

Want a proper assessment?

This self-check covers the basics. An ISMC assessment goes further, looking at how your network is laid out, what's exposed to the internet, and what to fix first, in plain language.

Request a consultation
← All guides