What is a cybersecurity audit?
A cybersecurity audit is a review of what an organisation has, who can reach it, and whether what protects it is what it actually needs. The formal kind is run against a standard, usually by somebody from outside the team, and produces findings the business has to answer for.
This is the informal kind, and it is the one that comes first. A self-assessment you can finish in about ten minutes without engaging anybody, so that when a real audit arrives, or an insurer's questionnaire, or a customer's security review, you already know what your own answers are. Most businesses have never written any of it down, which is why the first question here is not "are you secure" but "what have you got".
What the checklist covers
Sixteen lines in four groups, and you tick only the ones that apply to you:
- Everyone has these: a business email address, online banking, a phone used for work, a computer, and files you could not lose.
- Most businesses have these: a domain name, a website, cloud storage, social accounts, accounting or payroll software.
- Anyone with staff has these: staff accounts and logins, and devices staff own themselves.
- Some businesses have these: card payments or customer records, suppliers with access to your systems, software you build or have built, and insurance.
For each one it asks a second question that most checklists skip: who can get to it. You, your staff, an outside supplier, or more than one of those. That second answer is what turns a list of assets into something worth acting on, because an account only you can reach and an account your web developer can also reach are different problems with different answers.
What you get back
A report, in the browser, that you can print or copy as text. It opens with where you stand, names anything that stands out about how the answers sit together, and then gives the advice in the order it is worth doing, with the reasoning for that order printed on the page. Every piece of official guidance it points at is on the NCSC's Small Business Guide.
How often to run it
Whenever something changes: somebody leaves, a supplier changes, a domain comes up for renewal, or you start doing something you were not doing before. And once a year regardless, because the answers drift even when nothing obvious happens. It takes ten minutes the first time and rather less after that.
What this is not
It is not a penetration test, and it is not a compliance audit: it will not certify you for Cyber Essentials, ISO 27001 or SOC 2, and it is not evidence for anybody who is asking for those. It is also not legal, regulatory or insurance advice. What it is good for is the step before all of that, and for knowing what you would say if somebody asked.
If what you are facing is somebody else's audit rather than your own, the court has a separate and less helpful view on passing one.
The court spent four reigns defending a castle without ever writing down how many doors it had. Do not be the court. Count the doors first, subject, and then we shall discuss the locks.
Most guidance assumes you have already decided where to begin. This does not, because there is no general answer: a business with no staff and no website has a different first thing from one with both. The order above came out of what you said you have.