8 min read · Updated August 14, 2026
A step-by-step checklist SMBs can run in-house to find their biggest security gaps — no big budget or dedicated security team required.
SecurityComplianceBackup/DR
Why do this yourself first
You don’t need a full audit to find out where you’re exposed. A basic assessment takes a few hours, needs no special tools, and usually surfaces the handful of issues that cause most breaches and outages: weak identity controls, unpatched systems, untested backups, and open network paths.
Treat this as a snapshot, not a certification. The goal is a prioritized list of gaps you can act on — or hand to an MSP to fix.
Step 1: Inventory what you actually have
You can’t protect what you don’t know exists. Before anything else, write down what’s in your environment.
- All devices: laptops, desktops, servers, phones, and any IoT/smart devices
- All accounts with admin or elevated access, and who holds them
- Where your data actually lives — cloud apps, file servers, backups, and any shadow IT
- Vendors and third parties with access to your systems or data
Step 2: Check identity and access basics
Most breaches start with compromised credentials, not a sophisticated exploit.
- Is MFA enabled everywhere it can be — email, VPN, admin portals, banking?
- Are there shared logins or accounts still active for former employees?
- Does anyone have admin rights they don’t actually need day to day?
- Is there a documented process for offboarding access when someone leaves?
Step 3: Review patching and endpoint protection
Unpatched software is still one of the most common ways attackers get in.
- Are OS and application updates applied on a regular, defined cadence?
- Is every endpoint running current antivirus/EDR, not just some of them?
- Are end-of-life systems (unsupported OS versions, old firewalls) still in production?
- Do you know which devices haven’t checked in or updated recently?
Step 4: Test your backups, not just their existence
A backup you haven’t restored from is a guess, not a safety net.
- Are backups running on the schedule you think they are?
- Do you have a copy that’s offsite or otherwise isolated from ransomware reaching your primary systems?
- Have you actually performed a test restore in the last quarter?
- Do you know your realistic recovery time if a server or your whole office went down today?
Step 5: Review network exposure
Walk through what’s reachable from outside your network, and by whom.
- Are there any management interfaces (firewall, router, NAS) exposed directly to the internet?
- Is remote access limited to VPN with MFA, rather than open RDP or similar?
- Are guest and internal Wi-Fi networks actually separated?
- When was the firewall ruleset last reviewed for rules nobody remembers adding?
Step 6: Check email and phishing defenses
Email is still the most common way attackers get a foothold.
- Are SPF, DKIM, and DMARC configured for your domain?
- Is there spam/phishing filtering beyond what comes free with your mailbox?
- Have employees had any phishing awareness training in the past year?
- Is there a clear, known process for reporting a suspicious email?
Step 7: Document findings and prioritize
Turn what you found into a short, ranked list — not a 40-page report nobody reads.
- Flag anything that’s an immediate risk (exposed admin panel, no MFA on email, no working backups)
- Group the rest into “fix this quarter” and “plan for next year”
- Assign an owner and a rough timeline to each item
- Set a date to redo this assessment — twice a year is a reasonable baseline
Want help applying this? Email info@1-1solutions.com with your user count, locations, and current platforms.
← Back to Blog