King of Cybersecurity
DOOM CLOCK 23:58
Join the Dispatch

Where to startA free cybersecurity audit for small businesses

A sixteen-point checklist and self-assessment that begins with the question that has to come first: what has the business actually got, and who can reach it? Tick only what applies to you. Most businesses have five or six of the sixteen, and the ones you do not have are the ones you can stop worrying about.

Free · no sign-up · nothing leaves your browser

Everyone has these

Any address used for work, including a free personal one. If mail for the business arrives there, it counts.

Who has access?

Business or personal, if the business’s money moves through it. Count everyone who can authorise a payment, including a bookkeeper with their own login.

Who has access?

Yours or the company’s. If work email, messages or authentication codes reach it, it is in scope.

Who uses it?

Every machine used for work, including a home one. Out of support means the maker no longer issues security updates, which is not the same as it being slow.

Who uses it?

The accounts, the customer records, the work itself. A copy nobody has ever opened is not yet a backup.

Who can reach the copy?

Most businesses have these

The name your website and email addresses end in. If you cannot say whose name it is in, that is the answer.

Who controls it?

Anything published under your name, including one page or a booking site somebody else hosts. Count whoever built it if they can still get in.

Who can change it?

Anywhere work files live other than your own computer: shared drives, file-sharing links, online backups.

Who has access?

Every account that posts as the business rather than as a person, including ones nobody has used for a year.

Who has access?

Anything holding financial or staff records. Include a bookkeeper’s system if your data goes into it.

Who has access?

Anyone with staff has these

Every login held by somebody who works for you, including part-time, casual, seasonal and family.

Who sets them up?

Phones, tablets and laptops the business does not own, with work email or work files on them.

Who manages them?

Some businesses have these

Anywhere you take card payments, and any personal data you hold about customers. Note anyone else who stores a copy.

Who can see it?

Anyone outside the business who can log in to something of yours: IT support, web developer, bookkeeper, the person who set it all up years ago.

An app, a web app, or a system built for you. Include anything a developer can change and put live without anybody else checking.

Who can deploy it?

Cyber cover, or a business policy with a cyber section. The questionnaire you answered forms part of it.

Tick what the business has on the first two steps, then come back here.

0 things ticked so far · nothing is sent anywhere

What is a cybersecurity audit?

A cybersecurity audit is a review of what an organisation has, who can reach it, and whether what protects it is what it actually needs. The formal kind is run against a standard, usually by somebody from outside the team, and produces findings the business has to answer for.

This is the informal kind, and it is the one that comes first. A self-assessment you can finish in about ten minutes without engaging anybody, so that when a real audit arrives, or an insurer's questionnaire, or a customer's security review, you already know what your own answers are. Most businesses have never written any of it down, which is why the first question here is not "are you secure" but "what have you got".

What the checklist covers

Sixteen lines in four groups, and you tick only the ones that apply to you:

For each one it asks a second question that most checklists skip: who can get to it. You, your staff, an outside supplier, or more than one of those. That second answer is what turns a list of assets into something worth acting on, because an account only you can reach and an account your web developer can also reach are different problems with different answers.

What you get back

A report, in the browser, that you can print or copy as text. It opens with where you stand, names anything that stands out about how the answers sit together, and then gives the advice in the order it is worth doing, with the reasoning for that order printed on the page. Every piece of official guidance it points at is on the NCSC's Small Business Guide.

How often to run it

Whenever something changes: somebody leaves, a supplier changes, a domain comes up for renewal, or you start doing something you were not doing before. And once a year regardless, because the answers drift even when nothing obvious happens. It takes ten minutes the first time and rather less after that.

What this is not

It is not a penetration test, and it is not a compliance audit: it will not certify you for Cyber Essentials, ISO 27001 or SOC 2, and it is not evidence for anybody who is asking for those. It is also not legal, regulatory or insurance advice. What it is good for is the step before all of that, and for knowing what you would say if somebody asked.

If what you are facing is somebody else's audit rather than your own, the court has a separate and less helpful view on passing one.

The court spent four reigns defending a castle without ever writing down how many doors it had. Do not be the court. Count the doors first, subject, and then we shall discuss the locks.

Most guidance assumes you have already decided where to begin. This does not, because there is no general answer: a business with no staff and no website has a different first thing from one with both. The order above came out of what you said you have.