Small Practice Security

How to do a cyber risk assessment for a small business

Updated October 2026 · Small Practice Security

A cyber risk assessment answers four questions: what do we have, what could go wrong, how well are we protected today, and what do we fix first? For a business of 1 to 50 people it takes a few hours spread over two or three weeks, and you do not need to be technical to lead it.

It also pays off quickly: cyber insurance applications ask the same questions, larger clients send security questionnaires before they sign, and some rules, such as the FTC Safeguards Rule for tax preparers, auto dealers and other non-bank financial businesses, require a written risk assessment.

The frameworks, in plain English

NIST Cybersecurity Framework (CSF) 2.0, published in February 2024, organizes security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. CIS Controls v8.1 Implementation Group 1 is a set of 56 "essential cyber hygiene" safeguards aimed at small organizations. You don't need to read either cover to cover; use them as a checklist of what good looks like.

The five steps

1. Write down how the business works

Locations, staff, remote work, the systems you depend on, the sensitive data you hold (client SSNs, bank details, card data, health information) and the laws and contracts that apply.

2. Inventory what you have

Every computer, phone, server, router and printer; every cloud app (check the company card statement); your website, domain registrar and online banking. Most businesses miss the forgotten SaaS accounts and the former employee's laptop.

3. Rate the essential controls

For each control, mark it implemented, partially implemented or not implemented, and write down how you know. "We bought it" is not the same as "it is turned on for everyone".

4. Score your risks

For important assets, pick realistic threats, describe your specific weakness, and score likelihood and impact from 1 to 5. Phishing and payment fraud are "likely" for almost every business that uses email.

5. Make a remediation plan

Every high and critical risk gets an action, an owner, a date and a rough cost. Most first-year fixes are settings, not purchases.

The ten fixes that matter most

FixWhy
MFA on email, remote access, admin accounts and bankingStops most account takeovers from stolen passwords.
Call-back verification for any change in payment detailsStops most wire and invoice fraud.
Backups with one offline or immutable copy, and a tested restoreTurns ransomware from a disaster into an inconvenience.
Endpoint detection and response (EDR) on every computerCatches what basic antivirus misses; most insurers expect it.
Automatic updates; replace end-of-life systemsMost attacks use known, already-fixed weaknesses.
No local admin rights for everyday accountsLimits what malware can do if someone is tricked.
Security awareness training with phishing simulationsStaff are both the target and the best detector.
Same-day offboarding and a password managerFormer staff and shared passwords are common ways in.
Remote desktop closed to the internet; firewall onExposed remote desktop remains a leading ransomware entry point.
A one-page incident plan with phone numbers on paperDecisions in the first hour decide the cost of an incident.

Free official resources

NIST CSF 2.0 Small Business Quick-Start Guide (nist.gov), CISA's Cyber Essentials and free services (cisa.gov), the FTC's Cybersecurity for Small Business pages (ftc.gov), and the FCC Small Biz Cyber Planner.

Do it in an afternoon or two

The Small Business Cyber Risk Assessment Workbook gives you 46 essential controls mapped to NIST CSF 2.0 and CIS Controls IG1, a 31-threat library, an auto-scored risk register, a remediation plan and a step-by-step guide. $79, instant download.

Get the workbook
This guide is educational and is not legal or insurance advice.