8 Steps To Perform a Cyber Security for Small Companies Risk Assessment

Cyber security risk assessment meeting for small business strategy planning

For accountants, law firms and medical practices, trust is the product. A short, structured assessment gives you clarity on where risk sits today and what to do next, without slowing delivery. 

This guide outlines a practical approach to cyber security for small companies that you can run with your team or IT partner, then refine over time.

Step 1: Define the Purpose of Your Assessment

Decide what you’re protecting. Is it client data, billing systems, email, or patient information? Clarify why it matters: continuity, privacy, or contractual obligations.

Set  a short timeframe (around two weeks) and gather a small group of stakeholders: 

  • A business lead or owner
  • IT support or your managed provider
  • A staff member who understands daily workflows

Keep scope tight so your SMB cybersecurity assessment stays achievable and results in clear next steps.

Step 2: Identify and List Your Key Business Assets

List the systems you use and what information each holds. For most firms, this includes: 

  • Email and calendars
  • Document storage
  • Practice management or case systems
  • Accounting or ERP platforms
  • Payment portals, phones, and specialist cloud tools 

Note who logs in, how (password only or MFA), and whether the system is internet‑facing or used on mobile devices. This asset list forms the foundation of cybersecurity for businesses of all sizes.

Step 3: Evaluate Common Threat Scenarios

Rather than imagining everything, focus on the four scenarios that most often affect small businesses:

  • Business email compromise leading to payment fraud or data leaks
  • Ransomware encrypting laptops and shared files 
  • Cloud misconfiguration or risky app consent exposing documents
  • Lost or stolen devices with access to sensitive business systems 

For each scenario, ask: How likely is this for us over the next year? What would the impact be on clients, operations and obligations? 

Use high, medium, and low ratings to keep ratings simple.

Step 4: Apply Simple Controls To Reduce Risk

For each scenario, map controls that lower likelihood and impact:

  • Identity and access
    • Enforce multi‑factor authentication (MFA) on email, remote access, and admin roles 
    • Remove shared logins; review access quarterly.
  • Email and domain security
    • Set SPF, DKIM and DMARC
    • Monitor auto‑forwarding and mailbox rules
    • Verify payment changes by phone
  • Patching and updates
    • Prioritise internet‑facing systems, browsers and VPNs
    • Schedule a monthly maintenance window
  • Backups and recovery
    • Keep offline or immutable copies 
    • Test both file‑level and full system restores
  • Device protection
    • Encrypt laptops and mobiles
    • Require screen locks and remote-wipe capability
  • Third‑party oversight
    • Register supplier access
    • Require unique accounts and MFA
    • Remove access when projects end

Step 5: Score and Prioritise Each Risk 

Create a simple matrix with likelihood on one axis and impact on the other. Place each scenario where it fits, and focus first on likelihood and other high-impact items. 

Confirm which controls are already in place and if it produces evidence, such as MFA reports or backup logs. Add missing items to a 60-day plan with owners and due dates.

Step 6: Build a 60‑Day Cyber Security Action Plan

Keep your first plan short – five to seven actions is enough. A practical sequence for professional firms might include:

  • Enforce MFA on email and administration accounts; remove shared logins
  • Configure DMARC to quarantine; review forwarding rules
  • Apply monthly patches to browsers and remote tools
  • Test backups and add an offline or immutable copy
  • Review supplier access; restrict new app consents
  • Draft one‑page playbooks for email compromise and ransomware 

Short bursts of measurable action keep progress visible and realistic for small teams.

Step 7: Monitor Systems and Vendors for Early Warning Signs

Enable audit logs for identity, endpoints, and key SaaS platforms. Use built‑in alerts or a managed service to detect:

  • Unusual sign‑ins
  • Mailbox rule changes
  • Mass downloads 
  • Privilege escalation

Define who investigates and who approves containment. Light-touch monitoring ensures issues are caught early and managed consistently.

Step 8: Review and Update Your Risk Assessment Regularly

Revisit the matrix quarterly. 

Have any new cloud tools been adopted? Have staff or suppliers changed? Are backups still restoring within time limits? 

Adjust your plan and roll incomplete items into the next 60‑day window. This steady rhythm turns small cyber security from a project into a habit.

Holocron Sentry Turns Intent Into Day‑to‑Day Protection

Holocron Sentry brings together the essentials that small businesses can rely on:

  • 24/7 monitoring and alerting: Continuous detection of threats and incidents
  • Email security hardening: Protection against phishing, spoofing, and malicious attachments
  • Vulnerability management: Ongoing identification and remediation of weaknesses
  • Tested backup alignment: Reliable, verified recovery readiness
  • Governance reporting: Aligned with Australian cyber security guidance

We integrate with your IT partner or internal team to make protection effortless. 

You’ve learned the steps, now make sure they hold. Holocron Sentry turns them into measurable, managed results.

Call us at 1300 650 263 or send a message today.

 

Talk to a cyber security expert today and secure your systems & data

Talk to one of our leading cyber security experts today, about how we can help you mitigate threats and safeguard your business.

30 min. free consult with a trusted security expert

Download your FREE Cyber Security Checklist Today!

We’ll send you a copy of our Cyber Security checklist and help take the stress out of protecting your business’s digital assets.  

Read our privacy policy         

Book a Consultation

Book a Consultation

Under Attack?

If you require immediate assistance for a cyber incident or data breach which your business has suffered please provide as much detail below  and we will make contact with you ASAP.

Our experienced team of specialists will be able to provide peace of mind and practical assistance to ensure the situation can be responded to and contained swiftly. All matters will be treated confidentially and in a compliant manner.