How to do a cyber risk assessment for a small business
A cyber risk assessment answers four questions: what do we have, what could go wrong, how well are we protected today, and what do we fix first? For a business of 1 to 50 people it takes a few hours spread over two or three weeks, and you do not need to be technical to lead it.
It also pays off quickly: cyber insurance applications ask the same questions, larger clients send security questionnaires before they sign, and some rules, such as the FTC Safeguards Rule for tax preparers, auto dealers and other non-bank financial businesses, require a written risk assessment.
The frameworks, in plain English
NIST Cybersecurity Framework (CSF) 2.0, published in February 2024, organizes security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. CIS Controls v8.1 Implementation Group 1 is a set of 56 "essential cyber hygiene" safeguards aimed at small organizations. You don't need to read either cover to cover; use them as a checklist of what good looks like.
The five steps
1. Write down how the business works
Locations, staff, remote work, the systems you depend on, the sensitive data you hold (client SSNs, bank details, card data, health information) and the laws and contracts that apply.
2. Inventory what you have
Every computer, phone, server, router and printer; every cloud app (check the company card statement); your website, domain registrar and online banking. Most businesses miss the forgotten SaaS accounts and the former employee's laptop.
3. Rate the essential controls
For each control, mark it implemented, partially implemented or not implemented, and write down how you know. "We bought it" is not the same as "it is turned on for everyone".
4. Score your risks
For important assets, pick realistic threats, describe your specific weakness, and score likelihood and impact from 1 to 5. Phishing and payment fraud are "likely" for almost every business that uses email.
5. Make a remediation plan
Every high and critical risk gets an action, an owner, a date and a rough cost. Most first-year fixes are settings, not purchases.
The ten fixes that matter most
| Fix | Why |
|---|---|
| MFA on email, remote access, admin accounts and banking | Stops most account takeovers from stolen passwords. |
| Call-back verification for any change in payment details | Stops most wire and invoice fraud. |
| Backups with one offline or immutable copy, and a tested restore | Turns ransomware from a disaster into an inconvenience. |
| Endpoint detection and response (EDR) on every computer | Catches what basic antivirus misses; most insurers expect it. |
| Automatic updates; replace end-of-life systems | Most attacks use known, already-fixed weaknesses. |
| No local admin rights for everyday accounts | Limits what malware can do if someone is tricked. |
| Security awareness training with phishing simulations | Staff are both the target and the best detector. |
| Same-day offboarding and a password manager | Former staff and shared passwords are common ways in. |
| Remote desktop closed to the internet; firewall on | Exposed remote desktop remains a leading ransomware entry point. |
| A one-page incident plan with phone numbers on paper | Decisions in the first hour decide the cost of an incident. |
Free official resources
NIST CSF 2.0 Small Business Quick-Start Guide (nist.gov), CISA's Cyber Essentials and free services (cisa.gov), the FTC's Cybersecurity for Small Business pages (ftc.gov), and the FCC Small Biz Cyber Planner.
Do it in an afternoon or two
The Small Business Cyber Risk Assessment Workbook gives you 46 essential controls mapped to NIST CSF 2.0 and CIS Controls IG1, a 31-threat library, an auto-scored risk register, a remediation plan and a step-by-step guide. $79, instant download.
Get the workbook