The SME Cyber Security Audit Checklist

You can't fix what you can't see, and you can't prove to clients, insurers or auditors that you're secure without a structured audit. This is the checklist to work through — no jargon, no consultant needed for a first pass.

The 10 areas to review

  1. Asset inventory — do you know every device and service that holds data?
  2. Access control — individual accounts, least privilege, and leavers actually disabled.
  3. Passwords & MFA — no shared or default passwords; MFA on email and admin.
  4. Patching — OS and apps updated within 14 days.
  5. Malware protection — anti-malware active and updating on every endpoint.
  6. Firewalls — inbound access locked down, remote access restricted.
  7. Backups — tested, offline or immutable, and recoverable.
  8. Email security — spam/phishing filtering and staff awareness.
  9. Third parties — who has access to your systems and data.
  10. Incident readiness — a written plan and someone named to lead it.

How to assess each area

Score each on a simple scale — good / needs work / critical — and record the evidence. An audit isn't about producing a perfect artefacts list; it's about producing an honest gap list you can actually act on. Anything scored critical becomes an immediate fix.

Turning findings into fixes

Rank by risk (likelihood × impact), assign an owner and a deadline to each, and re-audit quarterly. The businesses that stay secure aren't the ones with the biggest budget — they're the ones that audit cyclically and actually close the gaps.

Security Audit Toolkit

The full audit toolkit: scored checklists for every control area, a findings log and a remediation tracker — everything you need to run your own audit end-to-end.

Get it now