Most small businesses don't think about a cybersecurity audit until after something has already gone wrong — a locked-out account, a strange login from a country nobody's ever visited, a client asking why their invoice went to the wrong bank account. By then, an audit isn't prevention anymore. It's cleanup.
You don't need to be a target of sophisticated hackers to have a security problem. Most breaches at small businesses aren't the result of a skilled attacker breaking through strong defences — they're the result of ordinary gaps nobody got around to closing.
1. Multiple people share the same login. A shared email inbox, a shared admin password, a shared social media login passed around in a group chat. Every shared credential is a point where you lose the ability to know who actually did what — and a point that stays open long after someone who had access has left.
2. There's no offboarding process. When someone leaves — an employee, a contractor, an intern — does their access get revoked the same day, or does it just... sit there? If you're not sure, that's the answer.
3. Software is running well past its update. Old versions of WordPress plugins, outdated point-of-sale software, a server nobody's patched in over a year. Attackers don't need to find a clever way in when an old, known vulnerability is still open.
4. Nobody has tested your backups. Having backups is not the same as having backups that work. A backup you've never tried to restore from is a backup you're assuming works, not one you know works.
5. Personal devices connect to business systems with no separation. Someone's personal laptop with email access, a personal phone with the company Slack, a home computer with a saved password to the accounting system. Every one of those devices is now part of your security perimeter, whether you've accounted for it or not.
6. There's no multi-factor authentication anywhere. A password alone is one of the weakest things standing between an attacker and your systems. If MFA isn't turned on for email, banking, and admin accounts at minimum, that's the single highest-leverage gap to close — and often the cheapest.
7. Nobody actually owns security. Not "we're all responsible" in the way that quietly means no one is — an actual person whose job includes noticing when something looks wrong and knowing what to do about it.
If you counted more than two of these as "yes, that's us," the audit isn't optional anymore — it's overdue.
Strip away the jargon and an audit is really just a structured answer to one question: if someone tried to get into your systems today, where would they get in, and how much damage could they do once inside? In practice that means reviewing:
An audit produces a prioritized list, not a wall of anxiety. Some findings are quick fixes — turning on MFA, closing an unused account — that can happen the same week. Others are bigger, like restructuring how access is managed across the company, and get scoped as a proper project with a timeline. The point of the audit isn't to overwhelm you with everything that could go wrong; it's to tell you which three things actually matter first.
☐ Is MFA turned on for email, banking, and admin accounts?
☐ Does anyone share a login with someone else?
☐ Has a former employee's access ever been left active after they left?
☐ Has anyone actually tried restoring from a backup in the last 6 months?
☐ Is there one person who owns security decisions, by name?
If two or more of those made you pause, that's not a reason to panic — it's a reason to get a proper look before it becomes a reason to panic.
One-page PDF with all the warning signs and a simple scoring guide.