Small Business Cybersecurity Checklist: A Quarterly Security Review
small businesscybersecuritysecurity checklistrisk assessmentMFAbackupsemployee securitycyber hygiene

Small Business Cybersecurity Checklist: A Quarterly Security Review

SSafely Editorial Team
2026-08-03
7 min read

Use this quarterly small business cybersecurity checklist to review accounts, devices, backups, employees, vendors, and incident readiness.

A quarterly security review gives a small business a practical way to find weak accounts, outdated devices, risky access, and untested recovery steps before they become larger problems. Use this repeatable small business cybersecurity checklist to review the essentials without needing a dedicated security team.

Overview

Cybersecurity for small business is less about buying every available tool and more about consistently managing the basics. A quarterly review creates a fixed opportunity to confirm that the controls you already rely on still match the way your business operates.

Set aside a focused review period and assign an owner for each task. The review can be completed by an owner, operations lead, IT contact, or another trusted person with appropriate access. Keep a simple record of what was checked, what needs attention, who owns the follow-up, and the target completion date.

Work through the checklist in this order:

  1. Identify: Confirm which accounts, devices, applications, data stores, vendors, and people support the business.
  2. Reduce exposure: Remove unnecessary access, close unused accounts, update software, and fix preventable configuration problems.
  3. Protect: Use strong authentication, endpoint protection, secure sharing, and reliable backups.
  4. Prepare: Make sure employees know how to report suspicious activity and that the business can respond if a system or account is compromised.

Prioritize items that could interrupt operations, expose sensitive information, or allow an attacker to move from one account or device to another. If a task requires specialist expertise, record the issue rather than leaving it undocumented. A cybersecurity budget checklist can help you plan for tools or support that are not currently in place.

Checklist by scenario

1. Accounts and access

  • Review the list of employees, contractors, administrators, and other users with access to business systems.
  • Disable accounts belonging to people who have left or no longer need access.
  • Confirm that each person has an individual account rather than sharing credentials.
  • Check administrator accounts and reduce elevated permissions where they are not necessary.
  • Require multi-factor authentication (MFA) for email, financial services, administrator accounts, remote access, and other high-impact systems where available.
  • Review password manager access, recovery methods, and emergency contacts. A password manager for small business should have clear ownership and a documented process for adding or removing users.

Access should reflect current job responsibilities, not past roles. Use the access control checklist for small businesses when you need a more detailed review of who should have access to what.

2. Devices and endpoint protection

  • List company-owned and business-used laptops, desktops, tablets, and phones.
  • Confirm that operating systems, browsers, business applications, and security software are receiving updates.
  • Check that screen locks, device encryption, and automatic locking are enabled where supported and appropriate.
  • Remove devices that are lost, retired, or no longer managed from business systems.
  • Verify that endpoint protection is active and that alerts have an owner who reviews them.
  • Confirm that employees know how to report a lost device, suspicious pop-up, malware warning, or unusual system behavior.

Do not treat antivirus installation as the complete endpoint protection plan. The review should also cover patching, administrator rights, device inventory, secure configuration, and what happens when an alert is raised.

3. Email, phishing, and fraud prevention

  • Review recent suspicious emails, invoice requests, password-reset messages, and unexpected file-sharing notifications.
  • Confirm that employees verify payment changes, urgent requests, and sensitive information requests through a separate trusted channel.
  • Check whether email security settings, spam controls, and reporting tools are configured and monitored.
  • Remind staff not to approve MFA prompts, open unexpected attachments, or enter credentials after following an unfamiliar link.
  • Review mailbox forwarding rules and other settings that could redirect business email without authorization.

Phishing prevention for businesses works best when reporting is simple and employees are not discouraged from raising concerns. Review the business phishing scam trends hub for a practical way to discuss changing scam patterns with your team.

4. Cloud applications and documents

  • Review administrator roles and connected applications in your main productivity platform.
  • Remove inactive users and unnecessary third-party integrations.
  • Check shared folders, public links, guest users, and externally shared documents.
  • Confirm that sensitive documents are stored in approved locations and shared only with intended recipients.
  • Review e-signature workflows, recipient verification, document expiry, and completed-document storage.
  • Confirm that business-critical data is covered by a recovery plan rather than relying solely on a synchronized cloud copy.

For a platform-specific review, use the cloud security checklist for Microsoft 365 and Google Workspace. If document workflows are changing, compare controls in secure file sharing for business and secure e-signature tools.

5. Backups and ransomware protection

  • Identify the systems and files the business would need to resume operations.
  • Confirm that backups run as intended and that failures generate a notification.
  • Ensure backup access is protected separately from ordinary user accounts.
  • Test restoring a representative file or system instead of checking only whether a backup job is marked complete.
  • Record who can approve a restore and where recovery instructions are stored.

Ransomware protection for SMBs depends on more than backups. Combine recoverable copies with MFA, patching, endpoint controls, limited permissions, and a clear process for isolating affected devices.

6. Vendors, remote work, and incidents

  • Review vendors that handle business, employee, customer, payment, or other sensitive information.
  • Confirm which vendor accounts and integrations are still necessary.
  • Check contract contacts, support channels, notification procedures, and data return or deletion expectations.
  • Review remote access, home-office devices, Wi-Fi practices, and use of personal equipment.
  • Update the incident contact list and confirm who makes decisions if email, payments, or a key SaaS service is unavailable.
  • Practice the first few steps for a compromised account, lost device, fraudulent payment request, or suspected ransomware event.

A short tabletop exercise is often more useful than an incident response plan that nobody has read. For continuity planning, see the business continuity checklist for cyber incidents and SaaS outages.

What to double-check

Some security issues are easy to miss because they sit outside the main tool dashboard. During each quarterly security review, double-check:

  • Old access: Former employees, temporary contractors, shared mailboxes, and forgotten administrator accounts.
  • Recovery paths: Personal email addresses, phone numbers, backup codes, and other methods used to recover business accounts.
  • External sharing: Public links, guest accounts, calendar invitations, and files shared with personal addresses.
  • Payment changes: Whether staff verify new bank details or urgent transfers independently of the original request.
  • Backup reality: Whether a restore has actually been completed and whether the restored data is usable.
  • Policy alignment: Whether your cybersecurity policy template, data handling rules, and employee instructions still describe current tools and workflows.
  • Privacy obligations: Whether new systems collect, store, or share personal information in ways that require a policy or process review. Cybersecurity controls support privacy compliance for small business, but they do not replace legal advice or a jurisdiction-specific assessment.

For every unresolved item, record the risk in plain language. “Former contractor still has access to shared storage” is more actionable than “access issue.” Give each item an owner and a deadline.

Common mistakes

  • Checking boxes without testing: A backup, alert, or policy is not dependable until someone verifies that it works.
  • Focusing only on technology: Payment verification, reporting habits, approvals, and staff training are part of the security system.
  • Ignoring small tools: A niche SaaS application, plugin, browser extension, or personal device can still hold sensitive business information.
  • Giving everyone broad access: Convenience can create unnecessary exposure. Start with the access needed for the role and expand it deliberately.
  • Leaving exceptions undocumented: If a system cannot use MFA or a device cannot be updated, document the reason, compensating controls, and a review date.
  • Writing a plan nobody can use: Incident instructions should include names, phone numbers, decision points, and first actions, not just general principles.
  • Treating the quarterly review as a one-time project: New hires, vendors, tools, offices, and workflows can change risk between reviews.

When to revisit

Run this small business security checklist at least once each quarter, preferably before seasonal planning cycles or periods of higher transaction volume. Revisit the relevant sections sooner when you:

  • Hire staff, end a contract, or change someone’s responsibilities.
  • Adopt a new cloud application, payment platform, remote-access tool, or document workflow.
  • Move offices, change devices, or allow more personal equipment for work.
  • Experience a suspicious login, phishing attempt, lost device, malware alert, or payment fraud attempt.
  • Change a vendor that stores, processes, or accesses business information.
  • Receive new insurance, customer, contractual, or compliance requirements.

To put the review into practice, schedule the next date now. Before then, choose one person to maintain the asset and account list, one person to track open actions, and one person to coordinate incident contacts. At the end of each review, complete the highest-impact fixes first: protect administrator and financial accounts with MFA, remove unnecessary access, update exposed devices, verify backups, and brief employees on current scams. Then save the completed checklist with its date and carry unresolved items into the next review.

Related Topics

#small business#cybersecurity#security checklist#risk assessment#MFA#backups#employee security#cyber hygiene
S

Safely Editorial Team

Cybersecurity and Privacy Editor

Senior editor and content strategist. Writing about technology, design, and the future of digital media. Follow along for deep dives into the industry's moving parts.