A year-end security audit gives you a clear answer to a basic business question:
Are your systems protected well enough for the risks you face today?
You do not need a large security department to run a useful audit. You need a defined scope, honest answers, and evidence for each control you review.
This checklist covers seven practical checks for small and midsize businesses. It aligns with guidance from the Cybersecurity and Infrastructure Security Agency, the NIST Cybersecurity Framework 2.0, and the Federal Trade Commission’s small business cybersecurity guidance.
For each check, mark your status:
- PASS: The control exists, works, and has recent evidence.
- NEEDS WORK: The control exists but has gaps.
- UNKNOWN: Nobody can confirm whether the control exists or works.
Unknown should not be treated as pass.
1. INVENTORY YOUR SYSTEMS, DATA, AND ACCOUNTS
You cannot protect assets you do not know about.
Start by creating or updating an inventory of the technology your business uses. Include more than office computers. Many SMBs overlook cloud applications, employee-owned devices, remote access tools, and inactive accounts.
Review:
- Laptops, desktops, servers, mobile devices, and network equipment
- Microsoft 365, Google Workspace, accounting, CRM, payroll, and industry-specific applications
- Cloud storage, websites, domains, and hosting accounts
- Backup systems and removable media
- Administrative, employee, contractor, and vendor accounts
- Customer, employee, financial, health, and proprietary data
Then document where sensitive data is stored and who owns each system.
Ask:
- Do we have a current list of all business devices?
- Do we know which applications contain sensitive information?
- Can we identify every person with administrative access?
- Are any systems or accounts owned by former employees or unknown vendors?
- Do we know which data we are required to retain, protect, or delete?
This inventory supports the Govern and Identify functions in NIST CSF 2.0. It also gives your IT team a reliable foundation for future budgeting and risk decisions.
If you find significant gaps, an IT strategy consultation from Five 9 can help you turn the inventory into a practical improvement roadmap.

2. REVIEW ACCESS, PRIVILEGES, AND MFA
A password alone is not enough to protect business systems.
Review access for email, cloud applications, remote access, financial systems, file shares, and administrative portals. Compare your user list against current HR records. Disable accounts that are no longer needed.
Pay special attention to privileged access. An employee may need access to email and a line-of-business application without needing global administrator rights.
Check that:
- Multi-factor authentication is enabled for email and cloud applications
- MFA protects administrator, VPN, remote desktop, and financial accounts
- Former employee and contractor accounts are disabled
- Shared accounts have been eliminated or formally documented
- Users have only the access required for their jobs
- Local administrator rights are limited on employee devices
- Vendor access is time-limited and reviewed regularly
- Passwords are unique, long, and stored in an approved password manager
The FTC recommends multi-factor authentication and restricted access as basic protections for sensitive business information.
If MFA is not enabled everywhere, do not wait for the full audit to finish. Start with administrator accounts, email, remote access, and systems containing financial or customer data.
3. VERIFY PATCHING AND VULNERABILITY MANAGEMENT
Outdated software creates openings attackers already know how to exploit.
Your year-end review should confirm that operating systems, applications, browsers, firmware, firewalls, and security tools are updated on a defined schedule. Automatic updates are useful, but they do not replace oversight. Some updates fail. Some devices fall out of management. Some business applications require testing before deployment.
Review:
- Operating system patch status for every managed device
- Security updates for browsers and productivity applications
- Firmware on firewalls, wireless access points, and network equipment
- Updates for internet-facing systems and websites
- Unsupported operating systems or applications
- High-risk findings from vulnerability scans
- Exceptions where patches were delayed or blocked
For every high-risk vulnerability, record:
- The affected system
- The business impact
- The person responsible
- The planned remediation date
- Any temporary compensating control
A vulnerability report without ownership is not a remediation plan.
Five 9’s security services include vulnerability management, penetration testing, and security assessments. These services can help when your internal team lacks the tools or time to validate what automated reports are telling you.
4. TEST BACKUPS AND RECOVERY
A backup is not proven until you restore from it.
Review backup coverage for critical files, databases, applications, configurations, and entire systems. Confirm that backups run as expected and that failures generate alerts.
Then test a restore.
Your audit should verify:
- Critical data is backed up on a defined schedule
- At least one backup copy is isolated, offline, or protected against modification
- Backup credentials are separate from ordinary user accounts
- Retention periods match business and compliance needs
- Backup jobs are monitored for failures
- A recent restore test was completed successfully
- Recovery time objectives and recovery point objectives are documented
- Key employees know what to do during a ransomware event
The 3-2-1 backup approach remains a useful starting point: maintain multiple copies, use different storage types, and keep at least one copy off-site or offline.
Do not assume your cloud provider handles every recovery requirement. Cloud services may provide availability, but your business may still be responsible for configuration, retention, access control, and recoverability.

5. CHECK ENDPOINT, NETWORK, AND EMAIL PROTECTION
Your users interact with threats through devices, networks, and email. Review all three.
For endpoint protection, confirm that every supported laptop, desktop, and server has active security software. Look for devices that have stopped reporting, missed recent check-ins, or lack encryption.
For network protection, review:
- Firewall rules and unnecessary open ports
- Remote administration settings
- Wireless encryption, using WPA2 or WPA3
- Separation between guest Wi-Fi and the business network
- VPN access and MFA requirements
- Unsupported network equipment
- DNS filtering and malicious website protection
For email, verify that your domain uses:
- SPF: Identifies approved mail servers
- DKIM: Adds a signature to outgoing messages
- DMARC: Tells receiving systems how to handle suspicious messages
The FTC’s email authentication guidance explains why SPF, DKIM, and DMARC matter. These controls help reduce spoofing and protect customers from messages pretending to come from your company.
If you are unsure whether your email configuration is correct, have it reviewed before changing records. A poorly configured policy can interfere with legitimate messages.
6. REVIEW INCIDENT RESPONSE AND LOGGING
Your team needs a plan before an incident occurs.
An incident response plan does not need to be a hundred-page document. It does need to identify who makes decisions, who contacts technical support, who communicates with customers, and how the business continues operating.
Your plan should address:
- Phishing and stolen credentials
- Ransomware
- Lost or stolen devices
- Business email compromise
- Vendor or cloud provider incidents
- Unauthorized access to customer or employee data
- Website defacement or service disruption
Also review your logs and alerts. Confirm that you can identify unusual sign-ins, repeated failed logins, suspicious file activity, endpoint detections, and administrative changes.
Ask:
- Who receives security alerts?
- Who can isolate a device or disable an account?
- Who contacts legal counsel, insurance, law enforcement, and affected customers?
- When was the last tabletop exercise?
- Can we determine what happened if an account is compromised?
Run a short tabletop exercise before year-end. Give your team a realistic scenario, such as a compromised email account or ransomware on a shared file server. Document what worked, what failed, and what needs to change.
7. CHECK TRAINING, VENDORS, AND COMPLIANCE EVIDENCE
Security is also a people and process issue.
Review whether employees receive recurring training on phishing, password safety, remote work, data handling, and incident reporting. Track participation. New employees should receive training during onboarding, not months later.
Then review vendors that handle your data or connect to your systems.
Confirm that vendor contracts address:
- The data the vendor may access
- How the data may be used and shared
- Security expectations
- MFA and remote access requirements
- Breach notification responsibilities
- Data retention and deletion
- Access removal when the relationship ends
Finally, create a central evidence folder. Store:
- Current policies
- Asset inventories
- Access reviews
- Patch reports
- Backup and restore test results
- Security training records
- Vendor reviews
- Incident response exercises
- Risk assessments and remediation plans
Evidence helps you respond to customer questionnaires, cyber insurance requirements, and regulatory reviews. It also shows your leadership team whether security investments are producing measurable progress.

WHAT TO DO WITH THE RESULTS
Do not try to fix everything at once.
Rank each gap by:
- Likelihood of exploitation
- Potential business impact
- Regulatory or contractual importance
- Cost and effort to correct
- Dependencies on other projects
Address urgent issues first. These may include missing MFA, active unsupported systems, failed backups, exposed remote access, or former employees with active accounts.
Then create a 30-, 60-, and 90-day remediation plan. Assign an owner and target date to every task.
A security audit should improve your business, not create fear or busywork. The goal is stronger protection, faster recovery, and clearer decisions about where to invest next.
Five 9 provides cybersecurity consulting, IT consulting services, and practical small business IT support for organizations that need experienced help without adding a full internal security department.
We can assess your current posture, prioritize the risks, and explain the findings in plain English. We also transfer knowledge to your internal team, so you become more capable rather than more dependent.
Start with an honest conversation through the Five 9 contact page. No pressure. We will help you determine whether a formal audit, targeted assessment, or focused remediation plan makes the most sense for your business.
