Resources

How to Perform a Basic Cybersecurity Assessment for Your Business

A step-by-step checklist SMBs can run in-house to find their biggest security gaps — no big budget or dedicated security team required.

8 min read · Updated August 14, 2026

A step-by-step checklist SMBs can run in-house to find their biggest security gaps — no big budget or dedicated security team required.

SecurityComplianceBackup/DR

Why do this yourself first

You don’t need a full audit to find out where you’re exposed. A basic assessment takes a few hours, needs no special tools, and usually surfaces the handful of issues that cause most breaches and outages: weak identity controls, unpatched systems, untested backups, and open network paths.

Treat this as a snapshot, not a certification. The goal is a prioritized list of gaps you can act on — or hand to an MSP to fix.

Step 1: Inventory what you actually have

You can’t protect what you don’t know exists. Before anything else, write down what’s in your environment.

  • All devices: laptops, desktops, servers, phones, and any IoT/smart devices
  • All accounts with admin or elevated access, and who holds them
  • Where your data actually lives — cloud apps, file servers, backups, and any shadow IT
  • Vendors and third parties with access to your systems or data

Step 2: Check identity and access basics

Most breaches start with compromised credentials, not a sophisticated exploit.

  • Is MFA enabled everywhere it can be — email, VPN, admin portals, banking?
  • Are there shared logins or accounts still active for former employees?
  • Does anyone have admin rights they don’t actually need day to day?
  • Is there a documented process for offboarding access when someone leaves?

Step 3: Review patching and endpoint protection

Unpatched software is still one of the most common ways attackers get in.

  • Are OS and application updates applied on a regular, defined cadence?
  • Is every endpoint running current antivirus/EDR, not just some of them?
  • Are end-of-life systems (unsupported OS versions, old firewalls) still in production?
  • Do you know which devices haven’t checked in or updated recently?

Step 4: Test your backups, not just their existence

A backup you haven’t restored from is a guess, not a safety net.

  • Are backups running on the schedule you think they are?
  • Do you have a copy that’s offsite or otherwise isolated from ransomware reaching your primary systems?
  • Have you actually performed a test restore in the last quarter?
  • Do you know your realistic recovery time if a server or your whole office went down today?

Step 5: Review network exposure

Walk through what’s reachable from outside your network, and by whom.

  • Are there any management interfaces (firewall, router, NAS) exposed directly to the internet?
  • Is remote access limited to VPN with MFA, rather than open RDP or similar?
  • Are guest and internal Wi-Fi networks actually separated?
  • When was the firewall ruleset last reviewed for rules nobody remembers adding?

Step 6: Check email and phishing defenses

Email is still the most common way attackers get a foothold.

  • Are SPF, DKIM, and DMARC configured for your domain?
  • Is there spam/phishing filtering beyond what comes free with your mailbox?
  • Have employees had any phishing awareness training in the past year?
  • Is there a clear, known process for reporting a suspicious email?

Step 7: Document findings and prioritize

Turn what you found into a short, ranked list — not a 40-page report nobody reads.

  • Flag anything that’s an immediate risk (exposed admin panel, no MFA on email, no working backups)
  • Group the rest into “fix this quarter” and “plan for next year”
  • Assign an owner and a rough timeline to each item
  • Set a date to redo this assessment — twice a year is a reasonable baseline

Want help applying this? Email info@1-1solutions.com with your user count, locations, and current platforms.

← Back to Blog