Cybersecurity in a small business: a practical IT audit
Basic cybersecurity audit helps detect deficiencies in accounts, updates, backups and remote access. Here are ten areas a small business can check in a structured way.

A small company doesn't have to start improving security with an expensive system. First, it should know which accounts, devices and data it has, who has access to them and whether it can restore the most important resources. The following review helps identify basic deficiencies, but does not replace an audit tailored to the specific environment and risk.
1. Resource inventory
You can't protect a system that no one remembers exists. Prepare a list of computers, phones, servers, network devices, cloud applications, domains and administrative accounts. For each item, indicate the owner, purpose, support status, and method of updating.
The result should be a registry that can be updated regularly, rather than a one-off list that is filed away.
2. Accounts and authentication
Each person should use their own account. Shared accounts make it difficult to track who made the change and complicate revoking access after the collaboration ends.
Check if:
- passwords are unique and stored in the password manager;
- multi-factor authentication protects email, cloud services, VPN and administrative accounts;
- only those who need them receive administrator privileges;
- There are securely stored methods to regain access;
- inactive accounts are disabled.
Wherever possible, it's a good idea to prefer phishing-resistant methods, such as dongles or passkeys. The SMS code is usually better than having no second component, but does not provide the same protection as stronger methods.
3. Granting and revoking access
The employee onboarding procedure should specify who approves access and what its scope is. The procedure for terminating cooperation must include disabling accounts, taking back sessions, devices and keys, and changing access data that was shared.
At least periodically, actual entitlements should be compared with employees' current responsibilities. A change of position should not lead to the indefinite accumulation of old entitlements.
4. Updates and lifecycle
Operating systems, applications, browsers, network devices and server software require updates. Simply enabling automatic updates is not enough if no one checks for installation errors or devices outside the management mechanism.
Determine:
- who evaluates and implements patches;
- how quickly critical patches are installed;
- when the service window falls;
- how the update result is checked;
- what happens to hardware and software after manufacturer support ends.
5. Device protection
Corporate computers should have active, updated endpoint protection. Its specific scope depends on the system, licence and risk. In addition to protection against malware, it is worth checking disk encryption, screen lock, limiting local administrator rights and the ability to remotely lock the managed device.
It is not enough to confirm that the program was once installed. The administrator should have reliable information about the protection status of the entire fleet and respond to devices that have stopped reporting.
6. Backup and recovery
A backup is only valuable when a company can restore data from it in the required time. The scope of the copy should result from the established RPO and RTO parameters, i.e. acceptable data loss and process recovery time.
Check:
- what data and configurations are copied;
- whether copies are separated from accounts and production systems;
- whether incorrect or missing tasks create an alert;
- who views reports;
- when the last documented recovery test was performed.
The 3-2-1 Principle can be a helpful starting point, but it is not a substitute for threat analysis, retention, or testing. We describe more in the guide about in-house backups.
7. Email and phishing resistance
Email hijacking can lead to payment fraud, data theft and company impersonation. In addition to MFA, you should check SPF, DKIM and DMARC configuration, automatic forwarding rules, accounts with access to mailboxes and unusual logins.
Employee training should cover real-world scenarios: an account number change, an urgent request from a manager, a fake login panel, and a suspicious attachment. Important financial changes should be confirmed through an independent channel using a previously known contact number.
8. Network and remote access
The guest network, IoT devices, employee computers and administrative infrastructure should not form one unrestricted zone by default. Segmentation requires correct firewall rules and isolation tests.
Remote access should only be provided to the resources you need, MFA protected and logged. A VPN may be part of the solution, but it is not automatically needed for every cloud service and does not fix a compromised device.
9. Event logging and response
The company should know where it will receive the first information about a problem. Logs and alerts must be stored for a sufficient period of time, device time must be synchronised and responsibility for reviewing them must be assigned.
The brief response procedure should indicate:
- decision maker;
- contact details of the IT team, suppliers, bank and insurer;
- a way to isolate a suspicious device without destroying evidence;
- system recovery order;
- rules for documenting the event and assessing reporting obligations.
A copy of the procedure should also be available when email and core company systems are down.
10. Legal and contractual requirements
GDPR requires risk-appropriate measures, but does not impose one identical configuration on all companies. A personal data breach is not always subject to reporting to the supervisory authority; this depends on an assessment of the risks to the rights and freedoms of persons. If reporting is required, the regulation provides for a deadline of 72 hours from the discovery of the violation. The specific event should be assessed by a data protection officer or lawyer.
In Poland, obligations arising from NIS2 were introduced by amending the Act on the national cybersecurity system. Coverage is determined by sector, size and detailed criteria, not solely by the number of employees. The company may also receive security requirements from the customer as a supply chain participant. Publishes current information Ministry of Digitization.
This article is for informational purposes only and does not constitute legal advice.
What to do after the audit
Not all deficiencies have the same effect. First, it is worth removing those that are likely to have serious consequences, such as the lack of MFA on the administrative account, the lack of a working copy of key data, or a publicly available, unsupported service.
For each task, record the owner, due date, method of confirmation of completion, and risk remaining after the change. An audit without a recovery plan is only a description of the problem.
NexaIT performs cybersecurity audits and implementations after determining the scope of the environment. Contact usif you need a technical assessment and a structured change plan.