The five-minute security check every small business should do today
Most small businesses are not one catastrophic mistake away from a security incident. They are one overlooked detail away. A former employee whose account was never closed. A password that has not changed in three years. A router running firmware from the Obama administration.
These are not the kinds of gaps that happen because someone was reckless. They happen because the business was busy. Technology got set up when the company was smaller, the team grew, processes changed, and nobody ever went back to audit what was put in place at the beginning. That is not a character flaw. That is just how things work when every day is full.
The good news is that the most common security gaps are not complicated to identify. You do not need a consultant on retainer or a formal audit. What you need is about five minutes and an honest look at a short list. This post covers three of the most common areas where small businesses are more exposed than they realize, what good looks like in each one, and what warrants a closer look.
None of this requires a technical background. If you get through this list and realize something needs attention, the path forward is usually clearer than you expect.
---
Are your accounts actually protected?
This is the most fundamental question on the list, and it is the one with the most surface area. Account security is not just about having a strong password. It covers who has accounts, how those accounts are structured, whether they are actually protected against unauthorized access, and whether someone is actively managing the health of those credentials over time.
Does everyone have their own login?
Start here. Every person on your team should have their own individual account for every business system they use. That means email, file storage, your business banking portal, your payroll platform, your project management tool, and anything else your team logs into regularly.
Shared accounts are a common workaround, especially in businesses that started small and just never formalized things. Sometimes it starts as a deliberate cost decision. Many software platforms charge per seat, and sharing a login feels like a reasonable way to avoid paying for multiple accounts. That logic is understandable. What it does not account for is the cost of the problems it creates later. One login for the whole team, passed around because it was easier than setting everyone up individually. It feels fine until it is not.
When you cannot tell who made a change, when you need to remove access for someone who left, or when a credential is compromised and you have to figure out who had it, the shared account becomes a serious operational problem. It also means that if one person's device is compromised, everyone's access goes with it. The per-seat licensing fee starts to look very reasonable compared to that.
If your team shares any logins, that is the first thing to address.
Is MFA enabled?
Multi-factor authentication, which just means requiring a second step beyond a password to log in, is one of the highest-impact security measures a small business can put in place. It means that even if someone's password is stolen, guessed, or leaked, an attacker still cannot get in without access to their phone or authentication app.
It should be enabled on email first. Email is the master key. A compromised email account can be used to reset passwords for nearly every other system the person uses. After email, turn it on for file storage, banking, payroll, and anything else that touches sensitive business data or finances. Honestly, if a system supports it, it should be on.
Most business email and productivity platforms either require MFA by default or make it easy to enable. If you are not sure whether it is on for your team, that is worth checking today, not eventually.
Are you using a password manager, and are you actually using it?
A password manager is the foundation that makes everything else on this list achievable. It generates strong, unique passwords for every account, stores them securely, and makes them available across devices without anyone having to memorize them or write them down. If your team is not using one, the practical reality is that people are either reusing passwords, using simple ones they can remember, or storing them somewhere they should not be, like a spreadsheet, a notes app, or a sticky note on the monitor.
Getting a password manager in place is the first step. Actively using it is the second, and this is where most businesses stop short.
Every major password manager includes an audit feature. It scans your stored credentials and flags passwords that are weak, reused across multiple accounts, or that have appeared in known data breaches. If you have never run this audit, you should. It is genuinely surprising how often it surfaces credentials that have been sitting untouched for years, reused in multiple places, or that are simple enough that a basic automated attack would crack them in minutes.
The rotate feature, or the practice of periodically updating old passwords, is the follow-through. A password sitting in a manager for four years is still better than one written on a sticky note, but it is not as secure as people assume.
One thing worth saying plainly: the old standard of forcing password changes every 30 or 90 days is no longer considered good practice, and for good reason. When people are required to rotate passwords on a short cycle, they tend to make predictable, minimal changes. Password1 becomes Password2, or the month and year get appended. The result is passwords that technically changed but are no easier to protect. Current security guidance, including from the National Institute of Standards and Technology (the federal agency that publishes cybersecurity standards), recommends against arbitrary rotation schedules and instead recommends rotating passwords when there is a specific reason to: a suspected breach, a known data leak, a departure, or a credential that has been shared or used somewhere it should not have been.
The audit feature in your password manager is the tool that helps you find those specific reasons. Passwords that are old enough to have been used on platforms that may have had unreported breaches, shared with former employees, or entered into systems that are no longer in use are candidates for rotation. You do not need to rotate everything at once. Start with the highest-value accounts: email, banking, payroll, and anything that handles client data.
Green flag: Everyone has individual accounts, MFA is enabled on all major systems, the team uses a password manager, and someone has run the audit in the last six months.
Red flag: Shared logins anywhere in the business, MFA turned off or inconsistently applied, passwords stored in spreadsheets or text files, or a password manager that nobody has opened since the day it was set up.
---
Do you know who still has access?
Password hygiene is a meaningful piece of account security, but it only covers part of the picture. Changing a password does not remove access from someone who still has their own login. Enabling MFA on your account does not help if a former vendor still has an active account they created two years ago. This section is about something broader than passwords. It is about knowing, with confidence, who can currently access your business systems, and whether all of that access is intentional.
The former employee problem
This is the most common access gap we see, and it is also the most uncomfortable to think about because it requires the assumption that not every departure ends well.
When someone leaves a business, the access removal process tends to happen in proportion to how much tension was involved. If it was a planned transition with two weeks notice, access probably got removed eventually. If it was abrupt, emotional, or just busy, there is a reasonable chance some of it got missed. Even in clean departures, the process is often incomplete. The main email account gets disabled. But the payroll portal? The project management tool? The shared folder they were added to eighteen months ago for a specific project? Those frequently get overlooked.
Former employees with active credentials are not automatically a threat. Most are not. But they represent an access point you did not intend to leave open, and you probably do not know it exists.
Contractors, vendors, and service accounts
Contractors and vendors are a close second on the overlooked access list. A marketing agency that helped with a campaign six months ago. An IT consultant who got admin access to set something up and was never formally removed. A software vendor whose support team was given access to troubleshoot an issue and never asked for it back. These are real access points, and they are easy to forget because the relationship felt temporary at the time.
Service accounts, which are logins created for software integrations or automated processes rather than individual people, are in the same category. They are often created with broad permissions because it was easier at the time, and they tend to outlive the systems or integrations they were created for.
Unmanaged file shares and cloud storage
File storage is one of the easier places for access to quietly outlive its purpose. A shared folder created for a project that ended a year ago. A cloud storage account that a contractor was added to and never removed from. A folder shared with a vendor during a transition that never got cleaned up afterward.
This problem is compounded by the fact that file storage often lives in more than one place. Businesses using Microsoft 365 or Google Workspace have file sharing built into those platforms, but many teams also have standalone tools alongside them. Dropbox, Box, and similar services are common because someone signed up years ago and the habit stuck, or because a client or vendor shared something through that platform and it became the default for that relationship. These tools are not visible in your email management dashboard. They have their own permission systems, their own user lists, and their own history of who was granted access and when.
The question to ask for every file storage location your business uses is the same: who currently has access, and does every person on that list still need it? If you cannot answer that question confidently, you have a gap worth closing.
The practical test
Here is the honest question to sit with: if someone left your business this week, could you walk through every system they had access to and confirm it was removed within 24 hours? Most small businesses cannot answer yes with confidence, because there is no list. Access was granted over time, across different platforms, by different people, and nobody has ever inventoried it.
Building that list does not need to be a major project. Start with your highest-risk systems: email, file storage, banking, payroll, and your customer-facing tools. For each one, look at who has active accounts. If any of those people no longer work for the business or no longer need access, that is a gap to close.
Green flag: A current list of who has access to what, a process for removing access when someone leaves, and a recent review of contractor and vendor accounts.
Red flag: No clear picture of who has access, former employees who may still have active logins, vendor or contractor accounts that were never formally reviewed, or file storage tools with permissions that have never been audited.
---
Section 3: Are your devices still getting updates?
Security updates are not glamorous. They do not add features. They do not make anything faster. They fix vulnerabilities that attackers already know about and are actively looking for in systems that have not patched them. Every device in your business that is not receiving current security updates is a device with known, documented weaknesses that are being left unaddressed.
Most people understand this in the abstract and still click "remind me later" every time the notification appears.
Computers and phones
Every computer and phone used for business should be running a current, vendor-supported operating system and receiving regular security updates. This is not about always having the latest version of every feature. It is about staying within the window where the manufacturer is still actively fixing security problems.
For phones, this is relatively straightforward. Major smartphone platforms push updates fairly aggressively, and most people install them eventually. The gap is usually in older devices that have aged out of support. A phone that is five or six years old may no longer receive security updates from its manufacturer even if it still works fine for everyday tasks. Working fine and being supported are two different things.
This is a place where the cost of not acting tends to get underestimated. A new phone feels like an expense. A security incident, the downtime, the recovery work, the potential data exposure, and the client trust that gets affected along the way, costs significantly more. The same math applies to computers. Holding onto hardware past its support window to avoid the replacement cost is a trade-off that rarely works out in the business's favor when something actually goes wrong.
For computers, the picture is more complicated, and one specific situation deserves a plain-language callout.
The Windows 10 situation
Microsoft ended support for Windows 10 in October 2025. As of this writing, we are now several months past that date, which means a significant number of Windows 10 devices are currently running an operating system that is receiving no security patches.
This matters because Windows 10 is still running on a large portion of the small business computers in use today. The machines work. They boot up, they run the applications people need, and there is no flashing warning light telling you something is wrong. But in the background, any new vulnerabilities discovered in Windows 10 after October 2025 are not being fixed. They are being documented, and they are being exploited.
Microsoft did create an Extended Security Updates program that allows some businesses to continue receiving patches past the end-of-life date, but it comes with a cost and conditions that most small businesses have not navigated. If your business enrolled in that program deliberately, you likely know it. If you are not sure, the safe assumption is that your Windows 10 machines are not covered. Assuming coverage you do not have is a riskier mistake than discovering you need to act.
The path forward is upgrading to Windows 11. Whether a specific machine can run Windows 11 depends on its hardware. Microsoft has published the requirements, and many machines purchased before 2021 do not meet them, which means an upgrade requires new hardware, not just a software update. That is a real cost, and it is one that a lot of small businesses have not yet budgeted for because nobody told them the deadline was coming.
If you are not sure whether any of your machines are running Windows 10, it is worth checking. If they are, it is worth having a conversation about what an upgrade path looks like before waiting any longer.
Business software and applications
Operating systems get most of the attention, but business applications matter too. Accounting software, communication tools, and industry-specific platforms regularly release security updates. Most of them have auto-update settings that handle this quietly, but it is worth confirming that updates are actually being applied and that no key applications are running versions that are no longer supported by the vendor.
The forgotten category: network equipment
Routers, wireless access points, and network switches are the most consistently overlooked items on the device update list. They are physical objects that get plugged in and forgotten. They do not prompt you for updates. They sit in a closet or on a shelf and most people never think about them again after initial setup.
Network equipment runs its own internal software, often called firmware, and that software has vulnerabilities. Attackers specifically target unpatched network equipment because it sits at the edge of everything. A compromised router is a compromised network.
The practical question is simple: when was the last time someone logged into your router or access point and checked for a firmware update? For most small businesses, the honest answer is never or not recently enough.
Green flag: All computers and phones are running vendor-supported operating systems with automatic updates enabled, Windows 10 machines have been addressed or are on a documented upgrade path, and network equipment has been reviewed and updated recently.
Red flag: Any Windows 10 machine without a clear upgrade plan, devices running operating systems past their support end date, key business applications running old versions, or network equipment that has never been updated.
---
What to do with what you found
If you worked through this list and everything looked good, that is genuinely worth something. A lot of small businesses cannot say that with confidence. If you found gaps, you are in good company. These are not exotic problems. They are the most common things we see when we sit down with a new client for the first time.
Most of what surfaces here has a straightforward fix. Password managers can be set up and deployed relatively quickly. Access reviews are tedious but not complicated. Software updates can often be enabled or accelerated with modest effort. The most involved piece is typically hardware replacement for machines that cannot run Windows 11, and even that is a solvable problem with the right planning and a reasonable timeline.
Some gaps will feel bigger once you start pulling at the thread. That is okay. Knowing what you are dealing with is better than not knowing. A business that has identified its gaps is in a far stronger position than one that assumes everything is fine.
If this list raised more questions than it answered, or if the answers made you realize the gaps are larger than you can address on your own, that is exactly what a discovery call is for. We are not here to sell you a solution before we understand your situation. We are here to help you figure out where you stand and what, if anything, actually needs to happen next.