5 Things in Your Business You Assume Are Secure – But Probably Have Not Checked Lately

small business cybersecurity assessment

October brings a flood of cybersecurity advice. Most of it is familiar: use strong passwords, enable multifactor authentication, train employees, patch systems, and back up data. None of that is wrong. The problem is that many businesses have already heard it – and many believe they already have it covered. 

That belief can create a dangerous gap between what leadership thinks is in place and what is actually happening across the business today. 

A mature cybersecurity program is not built on assumptions. It is built on verification. Tools change. Employees leave. Vendors gain access. Policies age. New applications appear. Insurance requirements evolve. What was true six or twelve months ago may no longer be true now. 

Here are five areas worth checking again – even if you are reasonably sure they are fine. 

1. Your Backups Exist – But Can You Restore What Matters? 

Seeing a successful backup job is not the same as proving the business can recover. The better question is whether your organization has tested how quickly critical systems, files, cloud data, line-of-business applications, and configurations can be restored after an outage or cyber incident. 

For a manufacturer, that may mean restoring ERP data, production documentation, file shares, or systems that support the shop floor. For an architectural or construction firm, it may mean project files, drawings, collaboration platforms, and field data. For a professional-services firm, client records, email, document systems, and billing data may be the priority. 

A useful backup conversation should answer three things: what gets restored first, how long restoration is expected to take, and when the restoration process was last tested. 

What to verify 

  • The most recent successful restore test – not just the most recent backup 
  • Which systems and cloud applications are included and excluded 
  • Who has authority to start recovery 
  • How long the business can operate without each critical system 
  • Whether recovery priorities still match how the business operates today 

2. MFA Is Turned On – But Is It Turned On Everywhere It Matters? 

Many organizations can truthfully say they use multifactor authentication while still having important gaps. MFA may be enforced for Microsoft 365 but not for a legacy application. Administrators may have different rules from standard users. Remote tools, financial systems, cloud consoles, VPN access, or vendor portals may sit outside the original rollout. 

The issue is not whether the business has MFA. The issue is coverage. A single high-value account without an additional layer of authentication can become the exception that matters most. 

What to verify 

  • Every administrator and privileged account 
  • Remote access tools and VPN connections 
  • Cloud platforms that contain sensitive business or customer information 
  • Accounting, payroll, banking, HR, and other high-value SaaS applications 
  • Any exception that exists because a system is old, inconvenient, or difficult to integrate 

3. Former Employees Are Gone – But Is Their Access Really Gone? 

Offboarding is easy to describe and surprisingly difficult to execute perfectly. An employee may be disabled in the primary directory while still having access to a third-party SaaS platform, shared password, project site, mobile device, customer portal, or vendor system. 

Contractors, interns, temporary staff, and outside consultants make the problem harder because their access may not follow the same HR process as a full-time employee. 

A strong offboarding process connects people, identity, devices, applications, and business ownership. It should also include a way to find accounts the organization forgot it had. 

4. Your Vendors Are Trusted – But How Much Access Do They Still Have? 

Vendors often receive access for a legitimate reason: an ERP consultant needs server access, a copier company installs scanning software, a payroll provider integrates with HR, or a construction platform connects to project systems. The problem is that temporary access has a way of becoming permanent. 

Business leaders should know which outside organizations can reach company systems, what level of access they have, who approved it, and whether that access is still required. This is especially important when a vendor can reach systems that contain customer information, financial data, intellectual property, or operational technology. 

5. Your Cyber Insurance Application Was Accurate – When You Signed It 

Cyber insurance applications often ask about controls such as MFA, backups, endpoint security, privileged access, employee training, and incident response. The business may answer accurately at renewal and then change technology, users, vendors, or processes months later. 

That creates a simple executive question: if you filled out the application again today, would every answer still be accurate? 

This does not mean leadership needs to become an insurance expert. It means technology, security, operations, and insurance should not operate as four separate conversations. 

The Better October Cybersecurity Question: What Have We Verified? 

Cybersecurity maturity is not demonstrated by the number of products in the stack. It is demonstrated by the organization’s ability to explain what matters, show that controls are working, identify exceptions, and make informed decisions about risk. 

Instead of asking, “Do we have backups?” ask, “When did we last prove we can restore?” Instead of asking, “Do we use MFA?” ask, “Where are the exceptions?” Instead of asking, “Did we disable that employee?” ask, “How do we know every path of access was removed?” 

Those questions turn cybersecurity from an annual awareness exercise into an operational discipline. 

Frequently Asked Questions 

What should a small business cybersecurity assessment include? 

It should review identity and access, backups and recovery, endpoint and network controls, cloud and SaaS security, vendor access, security policies, incident readiness, and any contractual or insurance requirements that affect the organization. 

How often should a business review cybersecurity controls? 

Critical controls should be monitored continuously where possible, while leadership-level reviews should occur on a defined schedule and whenever the business experiences major changes such as hiring, acquisitions, new locations, new applications, or insurance renewal. 

Is having a backup enough for ransomware recovery? 

No. A backup is only useful if the data is recoverable, the recovery path is understood, and the organization knows how long restoration of critical systems is likely to take. 

Why is vendor access a cybersecurity concern? 

Vendors may have remote, administrative, application, or data access that can create risk if permissions are broader than necessary, poorly monitored, or left active after the original need has ended. 

What is the difference between having a security control and verifying it? 

Having a control means the organization believes a safeguard exists. Verifying it means there is current evidence that the control is configured correctly, covers the intended systems and users, and performs as expected.