The SME Cyber Security Audit Checklist
You can't fix what you can't see, and you can't prove to clients, insurers or auditors that you're secure without a structured audit. This is the checklist to work through — no jargon, no consultant needed for a first pass.
The 10 areas to review
- Asset inventory — do you know every device and service that holds data?
- Access control — individual accounts, least privilege, and leavers actually disabled.
- Passwords & MFA — no shared or default passwords; MFA on email and admin.
- Patching — OS and apps updated within 14 days.
- Malware protection — anti-malware active and updating on every endpoint.
- Firewalls — inbound access locked down, remote access restricted.
- Backups — tested, offline or immutable, and recoverable.
- Email security — spam/phishing filtering and staff awareness.
- Third parties — who has access to your systems and data.
- Incident readiness — a written plan and someone named to lead it.
How to assess each area
Score each on a simple scale — good / needs work / critical — and record the evidence. An audit isn't about producing a perfect artefacts list; it's about producing an honest gap list you can actually act on. Anything scored critical becomes an immediate fix.
Turning findings into fixes
Rank by risk (likelihood × impact), assign an owner and a deadline to each, and re-audit quarterly. The businesses that stay secure aren't the ones with the biggest budget — they're the ones that audit cyclically and actually close the gaps.
Security Audit Toolkit
The full audit toolkit: scored checklists for every control area, a findings log and a remediation tracker — everything you need to run your own audit end-to-end.
Get it now