Small Business Cybersecurity Audit Checklist

Answer 14 questions and get a readiness score, prioritized fixes, and an insurance-readiness check — all in your browser.

Answer the 4 core questions to get your score

MFA, backups, patching, and staff training drive most of your risk — start there.

About your business

Sets the maturity bar. Sole-operators can mark the solo options below to skip controls they don't need.

If yes, we run a pass/fail check on the 6 controls 2025–2026 underwriters treat as near-mandatory.

Enter your last audit's score to see how much you've improved.

Core controls (answer these 4 first)

Highest-weight control and an insurer hard gate. Microsoft reports MFA blocks >99.2% of automated account-compromise attacks.

The core ransomware survival control. An untested backup is effectively no backup.

Unpatched software is a top initial-access vector and an insurer requirement.

The human layer is the most common breach entry point for small businesses.

Identity & access

Underwriters require MFA on remote access and critical SaaS specifically — not just email.

Shared logins defeat MFA and break audit trails. A password manager is the cheapest fix.

Orphaned accounts are a quiet breach path. Auto-passes for true solo operators.

Protect & respond

Insurers want next-gen endpoint protection (EDR) on workstations and servers — second-most-cited reason for denial.

A named insurer requirement; counters business email compromise.

Insurers want a documented IR plan with a contact tree. A plan "in your head" doesn't count.

Data & network

Out-of-box router settings are trivially exploited.

Drives most compliance-framework and breach-notification obligations.

Small Business Cybersecurity Audit Checklist — guide & how to use

What it does

This is a vCISO-style baseline self-assessment for small businesses with no dedicated IT staff. You answer 14 questions about the controls that matter most, and the tool returns a 0–100 readiness score, a risk tier, a prioritized fix list (ordered by how much risk each fix removes), a per-domain breakdown, a framework coverage map, and — if you have or are applying for cyber insurance — an insurance-readiness pass/fail. It's the dated, printable "proof" artifact you can hand a client, insurer, or auditor instead of panicking when they ask.

How it scores

Each of the 14 items maps to a control score (100% / 50% / 0%), multiplied by a weight reflecting framework and insurer priority, then re-normalized to a 0–100 score. The highest weights go to MFA on email/admin (18), tested + immutable backups (14), patching (11), and endpoint/EDR (11) — the controls CISA names as core and insurers gate on. "Not applicable" answers (no remote access, solo operator) are excluded from the math, so a perfect solo setup still scores 100.

Worked example

A 5-person firm answers: MFA on email = Some accounts (50%), MFA remote/SaaS = No (0%), backups = exist, never tested (50%), patching = manual (50%), endpoint = basic antivirus (50%), training = never (0%), email = filtering only (50%), written IR plan = none (0%), and passwords/firewall/offboarding/data at the middle option (50%). The tool returns "Cybersecurity Readiness: 39/100 — Critical exposure," flags that MFA-everywhere, training, and the written IR plan are the high-impact gaps (the two quick wins it counts are MFA remote and training, both 0% with weight ≥ 8), and — because they're applying for insurance — shows a FAIL naming MFA, backups, EDR, email/DMARC, patching, and the missing written IR plan. The fix list puts turn on MFA everywhere and enable auto-patching near the top because they recover the most risk for the least cost.

The most common mistakes this catches

How to embed this tool on your website

No account, no coding. Copy the embed code and paste it where you want it to appear:

<iframe src="https://snaptoolsuite.com/small-business-cybersecurity-checklist/?embed=1"
  style="width:100%;max-width:640px;height:1100px;border:0;"
  title="Small Business Cybersecurity Audit Checklist" loading="lazy"></iframe>
<p>Free <a href="https://snaptoolsuite.com/small-business-cybersecurity-checklist/">Small Business Cybersecurity Audit Checklist</a> by Snap Tool Suite</p>
2 Paste it on your page
3 It just works

See it live: view a real embed example →

Frequently asked questions

What is a good cybersecurity readiness score for a small business?

This tool scores 0–100. 70–89 is "Baseline-ready" (you cover the core CISA practices and most insurer requirements) and 90–100 is "Audit-ready." Below 70 means at least one high-impact control — MFA, tested backups, patching, or EDR — is missing or partial and should be fixed first.

Does this replace a real cybersecurity audit or penetration test?

No. It is a self-assessment that reflects only what you report. It is calibrated to free public frameworks (CISA Cyber Essentials, CIS Controls v8.1 IG1, NIST CSF 2.0) but is not an official CIS/NIST score, a certification, or a penetration test.

Why are untested backups only scored 50%?

An untested backup is effectively no backup — you only find out it failed when you try to restore during a ransomware incident. Insurers specifically require immutable or isolated backups with documented test-restores, so only tested + immutable backups score 100%.

Will passing the insurance-readiness check guarantee I get cyber insurance?

No. The gate mirrors common 2025–2026 underwriting requirements (MFA, EDR, immutable tested backups, email security/DMARC, patching, written incident response plan) but is not a quote, binding indication, or coverage guarantee. Only your insurer or broker can confirm eligibility. Passing reduces denial risk; it does not eliminate it.

Is my data stored anywhere?

No. The audit runs 100% in your browser. None of your answers are transmitted or stored on a server — which matters for a tool that asks about your security weaknesses.

Does this satisfy HIPAA, PCI DSS, or CMMC?

No. Regulated industries (healthcare/HIPAA, payment cards/PCI DSS, defense/CMMC, finance) have mandatory controls beyond this baseline. Passing here is a strong hygiene signal but does not satisfy those frameworks.

Accuracy & disclaimers

This is a self-assessment, not a penetration test, audit, or certification. Output reflects only what you report — accuracy depends on honest, informed answers. The readiness score is a relative prioritization aid calibrated to free public frameworks (CISA Cyber Essentials four core practices, CIS Controls v8.1 IG1, NISTIR 7621r2 / NIST CSF 2.0); it is not an official CIS/NIST score and does not equal CIS IG1 "compliance," which requires verifying all 56 safeguards. The insurance-readiness gate mirrors common 2025–2026 underwriting requirements but is not a quote, binding indication, or guarantee of coverage — carriers differ; only your insurer or broker can confirm eligibility. The "MFA blocks >99.2% of automated attacks" figure is Microsoft's published statistic for automated account-compromise attacks; it does not cover MFA-bypass (adversary-in-the-middle) phishing, so MFA is necessary but not sufficient. Weights are expert judgment about impact-vs-effort for a typical small business, not a published industry constant; your real risk depends on your data, sector, and threat exposure. Regulated industries (HIPAA, PCI DSS, CMMC, finance) have mandatory controls beyond this baseline. This tool is 100% client-side — nothing is transmitted or stored on a server.

Related tools

🔒 This audit runs entirely in your browser. We don't store, transmit, or sell your answers.