Small Business IT Audit: What Should You Actually Be Reviewing?
- Shay

- Feb 21, 2025
- 22 min read
Updated: Aug 27

Updated August 2026:
I originally published this article because I wanted small business owners to understand that an IT audit does not have to be something intimidating. Since then, I have refined both how I approach these reviews and how I explain them to clients. At SNL-Tech Services, I call this broader review an IT Baseline Assessment because I am not auditing one isolated piece of technology. I am looking at the business's entire technology environment, how the different pieces work together, what condition they are in, who manages and controls them, what the business is paying for, and whether the environment still makes sense for the way the company operates today.
When I conduct an IT Baseline Assessment, I am not coming in looking for reasons to tell a business owner that everything is wrong or that everything needs to be replaced. I am trying to establish an accurate starting point. What equipment does the business have? Which servers, applications and cloud services does it depend on? How old is the infrastructure? Who controls the important administrative accounts? Are backups actually working? Does the network still operate the way it was designed? Are employees using technology differently than they were a few years ago? Is the business still paying for software or services nobody uses? Are several products doing essentially the same job? What should be addressed now, and what should simply be planned and budgeted for later?
Sometimes the assessment uncovers a security problem. Sometimes it uncovers aging infrastructure, unnecessary complexity, licensing issues, poor documentation, weak backup planning, vendor dependencies or technology that has grown piece by piece without anyone stepping back to look at the whole environment. In other cases, the assessment confirms that something is working well and does not need to be changed. That is just as useful to know.
The goal is not to replace technology because something newer exists. The goal is to understand what the business has today, why it exists, how the pieces depend on one another and what deserves attention next.
What Is an IT Baseline Assessment?
An IT Baseline Assessment looks at the entire technology environment of the business. I want to understand what exists, how the systems connect to one another, what condition they are in, how employees actually use them and what dependencies need to be considered before changes are made.
That can include desktops, laptops, servers, virtualization, network equipment, firewalls, switches, wireless access points, internet connections, printers, mobile devices, Microsoft 365 or other cloud services, line of business applications, storage, backups, endpoint protection, remote access, licensing, software subscriptions, vendors, contracts, administrative accounts, warranties, documentation and other technology the business depends on.
I also want to understand the business behind the equipment. A server running an application nobody can operate without is more important than another device simply because it cost more. A secondary internet connection may be extremely important to a company whose phones and applications depend on internet connectivity. An old computer running specialized equipment or software may require a completely different strategy than an ordinary office workstation.
That is why I do not believe a useful IT assessment should begin and end with a vulnerability scan or a list of model numbers. The technology has to be evaluated in the context of the business using it.
More Than Just a Lock on the Door
I sometimes compare business technology to securing a building. You can put a very good lock on the front door, but that does not tell you whether the windows are secure, who still has keys, whether the alarm works, whether the cameras are recording or whether somebody propped open a side door six months ago and nobody noticed. Looking at one visible control can create the impression that the entire building is protected even though nobody has looked at how all of the pieces work together.
Technology environments can develop the same way. A business may have a good firewall, business endpoint protection and Microsoft 365 with MFA, but that does not automatically tell me that the entire environment is in good shape. There may be aging servers, unsupported computers, backups that have never been restored, administrative accounts nobody recognizes, laptops without encryption, unused subscriptions or network equipment that no longer supports the design the business believes it has.
Each individual piece may look fine when viewed by itself. The IT Baseline Assessment is where I start putting those pieces together.
The same idea applies beyond cybersecurity. A server can be running without anyone asking whether its workload still needs its own physical hardware. A software subscription can renew every year without anyone checking whether employees still use it. A backup dashboard can show successful jobs without anyone demonstrating that the data can actually be restored. The point of the assessment is to look past the fact that something exists and understand whether it is still doing what the business thinks it is doing.
What Does a Small Business IT Audit and Baseline Assessment Look At?
The exact scope depends on the business. A law firm, construction company, CPA firm, medical practice, government contractor and service company may rely on very different technology. These are some of the areas I may need to review:
Area | What I May Be Looking At |
Desktops and laptops | Age, operating systems, performance, warranty status, encryption, endpoint protection, device management and replacement planning |
Servers and virtualization | Physical servers, virtual machines, server roles, operating systems, hardware age, storage, capacity, redundancy, application dependencies and possible consolidation opportunities |
Network infrastructure | Firewalls, managed and unmanaged switches, wireless access points, VLANs, network segmentation, guest networks, IoT devices, remote access and whether the network is functioning as intended |
Internet and connectivity | Primary and backup internet connections, reliability, capacity, failover requirements, remote locations and how an outage would affect operations |
Microsoft 365 and cloud services | Licensing, administration, identity, email, SharePoint, OneDrive, Teams, device management, security capabilities and how employees actually use the platform |
Business applications | Accounting, ERP, CRM, tax, medical, legal, estimating, scheduling, design and other applications, including server, identity, operating system and network dependencies |
Storage and file access | Local servers, NAS appliances, SharePoint, OneDrive, cloud storage, permissions and whether the current structure still fits how employees work |
Backups and recovery | What is protected, backup locations, retention, monitoring, offsite copies, recovery procedures and whether restore testing has been performed |
Cybersecurity | Endpoint protection, MFA, encryption, email security, administrative access, patching, remote access, monitoring and other controls appropriate to the environment |
Mobile and field devices | Phones, tablets, laptops, device management, encryption, company access, lost or stolen device procedures and connectivity away from the office |
Printers and connected devices | Printers, scanners, cameras, access control systems and other IoT equipment connected to the network |
Software, licensing and subscriptions | Applications and cloud services being paid for, actual usage, assigned versus needed licenses, unused or duplicate subscriptions, overlapping capabilities and renewals |
Vendors, contracts and agreements | Technology providers, services being delivered, technical dependencies, ownership, administrative access, renewals and whether the technology still fits the business |
Lifecycle and warranties | Equipment age, vendor support, warranty expiration, operating system lifecycle and what should be planned and budgeted for before failure |
Documentation | Asset inventory, network diagrams, vendor contacts, administrative ownership, backup information and enough documentation for another qualified IT professional to understand the environment |
Business, regulatory and contractual requirements | Cyber insurance questions, customer requirements, compliance considerations and other obligations that may affect technology decisions |
That may look like a lot, but that is the point of establishing a baseline. A business uses these systems together every day, so evaluating them as unrelated pieces can miss important dependencies.
Current NIST small business guidance makes a similar point from a cybersecurity risk perspective. Businesses need to understand the hardware, software, systems and services they depend on, who administers them, what information they can access and what losing access to them could mean to the business. An IT Baseline Assessment is broader than NIST's cybersecurity guidance, but the underlying principle fits well.
You need to understand what you have before you can make informed decisions about it.
Aging Servers Can Reveal a Bigger Infrastructure Question
Servers are a good example of why I want to understand the entire environment before recommending a replacement.
A business may have several physical servers that were purchased at different times over many years. One may handle Active Directory and DNS, another may run an accounting or ERP application, another may store files and another may support a database. Each server may still technically be running, so there may not be an obvious emergency.
That does not necessarily mean replacing each old physical server with another physical server is the best long term plan.
During an IT Baseline Assessment, I want to understand what each server is doing, which applications depend on it, which operating systems are running, how much processing power and memory the workloads actually use, how storage is configured, how everything is backed up and what the business expects to need over the next several years. Depending on what I find, it may make more sense to evaluate a properly sized hypervisor server and consolidate appropriate server workloads into virtual machines.
Virtualization is not something I recommend simply because a business owns several servers. The hardware needs to be sized correctly, applications need to support the architecture, licensing needs to be considered, networking and storage need to be designed appropriately, and backup and recovery have to account for what happens when multiple workloads depend on the same physical host.
The assessment gives me the information needed to have that conversation before several aging servers become several emergency replacements.
Application dependencies can change the entire recommendation as well. I have encountered environments where a critical business application still depended on traditional on premises infrastructure. In one government contractor environment, an ERP application still required traditional Active Directory, and that dependency was confirmed with the software vendor. That became an important part of the architecture conversation because I could not simply design a cleaner looking cloud environment on paper and ignore an application employees needed to run the business.
I discuss that environment in more detail in Microsoft 365 for Small DoD Contractors: What CMMC Level 2 Actually Changes.
What Happens When a Business Cannot Replace an Unsupported Computer?
Unsupported operating systems are another thing I look for during an IT Baseline Assessment. Ideally, business computers should be running operating systems that are still supported and receiving security updates. Sometimes, however, replacing an old computer is not as simple as purchasing a new machine and moving the files.
I have a client with a computer that still runs Windows XP because specialized software the business depends on will not run on a newer operating system. Windows XP has been out of Microsoft support for many years, so I do not want that computer operating like an ordinary workstation. In this environment, the legacy machine is segmented from the rest of the business network and does not have access to the internet. Internet traffic also cannot initiate communication with it. The business can continue using the specialized application it needs without giving that unsupported system unnecessary connectivity to the rest of the environment.
I have another client with a similar challenge involving Windows 10. The computer cannot be upgraded to Windows 11, and the design software the company depends on will not work properly on Windows 11. That workstation also needs to communicate with a large format printer as part of the company's normal design workflow. I segmented the workstation from the primary business network and blocked its internet access while allowing the specific network communication it needs with the large format printer. The workstation can perform the business function it is still needed for without general access to the internet or the normal internal business network.
Windows 10 reached the end of standard support for most editions on October 14, 2025, although there are Extended Security Update options and some specialized editions follow different lifecycle schedules. This is another reason I verify the actual operating system, edition and business use rather than treating every machine labeled Windows 10 identically.
Network isolation does not turn an unsupported operating system into a supported one or eliminate the underlying risk. In these examples, it is a compensating measure used to reduce exposure while accommodating a legitimate business dependency that cannot immediately be removed. I still want the business to understand why the legacy system exists, exactly what it is allowed to communicate with, what would happen if it failed and what the eventual replacement or migration path might look like.
This is why an IT Baseline Assessment cannot simply produce a report that says, “old computer found, replace it.” I need to understand what that computer actually does first. If it runs specialized software, controls equipment, communicates with a particular device or supports a workflow employees depend on every day, removing it without understanding those dependencies can create a larger operational problem than the one we were trying to solve.
A Network Can Look Segmented on the Firewall and Still Not Work as Intended
Networks are another area where looking at one device can be misleading.
I may open a firewall and see VLANs configured for the internal business network, guest wireless, cameras, phones or other IoT devices. At first glance, that can make the network look as though it was designed with segmentation in mind.
Then I start looking at the switches and the rest of the infrastructure.
If unmanaged switches were installed later without considering the original design, or the managed switching and wireless infrastructure were not configured correctly to carry and enforce the intended VLANs, the network may no longer be segmented the way somebody believes it is. Equipment gets added over time. Someone needs another port, so a switch gets installed. A camera system is added. Another wireless access point appears. Years later, the firewall configuration may still show several networks even though the physical and logical environment underneath it has changed.
That is why seeing VLANs on a firewall is not enough for me. I want to understand what happens to the traffic throughout the network and whether the separation is actually functioning as intended.
This can become particularly important when a business has regulatory, contractual or security requirements that depend on network separation. The specific requirements vary by regulation, contract and environment, so I would not tell every regulated business that it is universally required to use VLANs. If network segmentation is being relied upon as a security control, however, it needs to function throughout the environment rather than exist only as a firewall configuration.
Even when there is no specific compliance requirement, I generally prefer to separate IoT and similar devices from the primary business network when the environment supports it. Cameras, access control systems, smart televisions, thermostats, building controls and other internet connected equipment usually do not need the same access to employee computers, servers and business information that an ordinary workstation needs.
In my opinion, a device needing internet access does not automatically mean that device belongs on the same internal network as everything else the business owns.
Sometimes I Start With What the Business Is Paying For
One of the places I sometimes start an assessment is with the bills. What technology and services is the company paying for, and does anyone know what each one actually does?
During one assessment, that process led me into a much larger issue. The business was paying for managed technology, but it did not have administrative control of its own firewall. When a change was needed, the company had to go back through the provider that controlled it. As I continued looking through the environment, that review expanded into other areas, including backups and cybersecurity tools.
The important finding was not simply whether a particular service should stay or go. It was that the business needed a clearer understanding of what it owned, what its provider controlled and whether the technology and services it was paying for still fit its needs.
I do not automatically consider provider managed equipment a problem. There are legitimate managed service arrangements where a provider owns or controls equipment as part of the service. What matters is that the business understands the arrangement, knows what happens if the relationship ends and has appropriate continuity planning for the systems it depends on.
Are You Still Paying for Technology the Business No Longer Needs?
Technology expenses have a way of accumulating over time. A software subscription gets purchased for a project. An application is added because someone needed a particular feature. An employee leaves but a license remains assigned. A vendor agreement renews even though the business has changed how it operates. Months or years later, those charges may still be appearing on an invoice or credit card even though nobody is really using the service anymore.
Part of the IT Baseline Assessment can be figuring out why the business is paying for those things. Who uses the application? What business function does it serve? How many licenses are being purchased compared with how many are actually needed? When does the agreement renew? Is another product already in the environment providing some of the same capabilities? Does the business still need the service at all?
Sometimes the answer is that the product is important and should absolutely remain in place. Other times, I may discover software or services that have not been meaningfully used in months or even years.
Vendor contracts and agreements belong in that review too. I am not the attorney interpreting the legal terms of a contract, but from the IT side I can help identify what technology or services the agreement provides, how those services fit into the current environment, what technical dependencies exist and whether the business still appears to need the service. When legal interpretation, compliance interpretation or another specialty is required, that belongs with the appropriate professional.
There can also be opportunities to simplify the environment. A business may be paying for several separate products that were purchased at different times to solve individual problems. Before renewing all of them, I want to understand whether technology the business already owns can appropriately perform some of those functions. Microsoft 365 is a good example because the available capabilities depend heavily on the licenses the business owns and how the tenant is configured. I would never assume Microsoft 365 or another platform can replace a product simply because the feature lists appear similar. The actual business requirements, workflow, functionality, security, licensing and dependencies have to be compared first.
The goal is not simply to cut expenses. An assessment may just as easily show that a business needs to invest more in an area because an important system is unsupported, unreliable or inadequate. The goal is to make technology spending intentional. I want the owner to understand what the business is paying for, why it is paying for it and whether those services still support the way the company operates today.
If Your IT Provider Disappeared Tomorrow, Could You Access Your Own Technology?
This is one of the questions I think more business owners should ask.
If the person or company managing your technology suddenly became unavailable, could another qualified IT professional step in and understand what you have?
Who controls your Microsoft 365 tenant?
Who owns the domain registration? Where is DNS hosted?
Who administers the firewall?
Who has access to the network controller?
Who manages the backups?
Where is the website hosted?
Who controls the security platform?
Which vendors support the applications the business depends on?
The answer does not mean the owner personally needs administrator passwords for every system sitting in a notebook on the desk. It means the business should understand who controls the technology it depends on and have an appropriate continuity plan for accessing and managing it.
This is also why documentation is part of my IT Baseline Assessment. An undocumented environment becomes much harder to troubleshoot, transition or recover when the person who understands it is no longer available.
An Inventory Is More Than a List of Computers
An accurate inventory is one of the foundations of a good baseline, but I do not think inventory should mean a spreadsheet containing nothing but computer serial numbers.
I want to know what the business relies on.
That includes hardware, software, systems, cloud services and important vendors. Your inventory may include servers, NAS appliances, firewalls, switches, wireless access points, laptops, desktops, tablets and printers, but it should also account for Microsoft 365, cloud accounting platforms, line of business applications, backup services and other systems that could interrupt the business if access suddenly disappeared.
My Small Business IT Checklist and Systems Inventory is a good place to start if your immediate question is simply, Do we actually know what technology our business has?
An IT Baseline Assessment takes that information further by looking at how those systems are configured, how they depend on one another and whether the overall environment still supports the business.
Backups Need to Be Evaluated as Part of the Business
I hear “we have backups” fairly often.
The next questions are what matter.
What exactly is being backed up?
How often? Where is it stored?
Is there another copy somewhere else?
Who receives failure notifications?
How long is information retained?
Are Microsoft 365, local servers, NAS data and cloud applications accounted for appropriately?
Most importantly, has anyone demonstrated that the information can actually be restored?
A successful job in a backup dashboard does not tell me everything I need to know about the business's ability to recover.
The IT Baseline Assessment is a good time to compare the backup design with how the business actually operates. A company that could work for several days without one system has a very different recovery problem from a business whose employees cannot function when its ERP database is unavailable. I want the recovery strategy to reflect those differences.
Microsoft 365 May Need Its Own Deeper Review
Microsoft 365 is often one part of the broader IT Baseline Assessment, but it can become an entire environment of its own.
During a baseline review, I may identify questions around Microsoft 365 licensing, administrative access, MFA, device management, SharePoint, OneDrive, email security or the way accounts are being managed. That tells me Microsoft 365 deserves more attention, but the broad baseline assessment is not intended to replace a detailed tenant review.
That is where my Microsoft 365 Audit and Tenant Security Review is different. The Microsoft 365 Audit goes deeper into the tenant itself, including identity, administrative access, authentication, Conditional Access, Defender, email security, Intune, SharePoint, OneDrive, third party applications, backup and recovery, licensing and other areas relevant to the particular environment.
The distinction is fairly simple.
An IT Baseline Assessment asks: What does the business's overall technology environment look like, how does it work together and what needs attention?
A Microsoft 365 Audit asks: How is the Microsoft 365 tenant itself licensed, configured, secured and managed?
A business may need one or both depending on what it is trying to understand.
Cybersecurity Is Part of the Baseline, Not the Entire Baseline
Security absolutely belongs in the assessment, but I do not want a business owner to hear “IT Baseline Assessment” and think I am simply running a cybersecurity scan.
I want to know whether devices have appropriate endpoint protection, whether laptops are encrypted, how MFA is being used, how administrative access is handled, whether important equipment is receiving updates, how remote access works and whether the firewall and network design still make sense.
But I am also looking at infrastructure, reliability, lifecycle, performance, licensing, capacity, documentation, ownership, applications, vendors and business continuity.
Sometimes the most important finding is a security gap. Another time it may be three aging servers. It may be unreliable internet service. It may be an unsupported operating system running a critical application. It may be that the company is paying for overlapping software products. It may be a network that grew without documentation. It may simply be that nobody can clearly explain how the environment is put together anymore.
If the assessment shows that the broader concern is cybersecurity, your next step may be to look more closely at what security controls the business actually has in place rather than assuming the presence of antivirus or a firewall tells the whole story.
What Should You Fix First After an IT Baseline Assessment?
Finding twenty things that could be improved does not mean twenty things need to happen tomorrow.
Prioritization is one of the most important parts of the process. I want to look at business impact, risk, reliability, lifecycle, dependencies, cost and urgency rather than simply sort everything by age.
An older switch that is still supported, appropriately configured and working reliably may not be the first thing I recommend replacing. A newer backup system that nobody has ever successfully restored from may deserve attention sooner. An aging server supporting the company's critical ERP system may require significant planning even if it has not failed yet.
A network segmentation problem may move higher on the list if the business is relying on that separation for a contractual, regulatory or security requirement.
I generally want the findings to help the business think in three practical timeframes:
What needs attention now? These are issues that create an immediate or significant business, security, reliability or compliance concern.
What should we plan for? These are items that may not be emergencies today but need a project, budget or replacement strategy.
What can stay as it is? Technology that is supported, appropriate and doing its job does not need to be replaced simply because I performed an assessment.
That last category matters. An assessment should not exist to manufacture projects. It should help the business decide which projects are actually worth doing.
When Does an IT Baseline Assessment Make Sense?
I do not believe there is one universal rule that says every small business must complete the same IT assessment on the same schedule. The timing should reflect the business, its technology and any regulatory, contractual or insurance requirements that apply.
There are, however, several situations where establishing or refreshing the baseline makes a lot of sense:
Nobody has ever documented the entire environment.
The business is changing IT providers.
The company has grown significantly or added locations.
Several servers, computers or network devices are aging at the same time.
A major server, cloud or infrastructure project is being considered.
Employees are working differently than they did when the environment was originally designed.
The business has added mobile or field employees.
A cyber insurance renewal is exposing questions nobody can confidently answer.
New regulatory or contractual requirements affect the technology.
The business has experienced an outage, security incident or near miss.
Multiple vendors have added technology over the years and nobody has stepped back to look at the environment as a whole.
Software, licensing and vendor expenses have accumulated and nobody is sure what is still being used.
The owner simply cannot get a clear answer to the question, “What do we actually have and what needs attention?”
Once the baseline exists, periodic review is valuable because the environment continues to change. That does not mean every piece needs to be reassessed on an arbitrary calendar. Major business changes, equipment lifecycle, new applications, new locations, security requirements and operational problems can all be reasons to revisit part or all of the baseline.
What Should You Know After an IT Baseline Assessment?
I do not think a useful assessment should leave a business owner with a technical report full of findings and no idea what any of them mean.
The business should come away with clearer answers to practical questions such as:
What technology do we actually have?
What is working well?
What needs attention now?
What can wait?
What should we budget for?
What equipment is approaching replacement?
Which systems and applications depend on one another?
What are we paying for that we no longer use or need?
Are we paying for multiple products that solve the same problem?
Who controls our important technology and accounts?
Where could the environment be simplified?
Are there areas that need a more focused technical or security review?
The recommendations should reflect priority and business context. A five year old switch that is still supported and functioning normally is not automatically more urgent than a two year old backup system nobody has ever tested. Technology age matters, but so do business impact, risk, dependencies and what happens if something fails.
The assessment should help the owner understand those differences.
An IT Baseline Assessment Is About Making Better Technology Decisions
When I originally wrote about IT audits, I wanted owners to know they did not have to be afraid of someone coming in and looking at their technology. I still believe that.
But I think the more important point now is that a business cannot make good technology decisions when nobody has a complete picture of the environment.
It is difficult to plan server replacements if nobody has documented what the servers actually do. It is difficult to rely on network segmentation if nobody has verified that the switches and wireless infrastructure still support the design. It is difficult to decide what to do with an unsupported computer if nobody understands the specialized application keeping it there. It is difficult to answer cyber insurance questions when nobody can verify the controls. It is difficult to build an incident response plan when nobody knows who controls the systems. It is difficult to evaluate technology spending when software and vendor agreements have been accumulating for years. And it is very difficult to budget intelligently when technology gets replaced only after it breaks.
An IT Baseline Assessment gives us a place to start.
Sometimes the recommendation is a major infrastructure project. Sometimes it is server consolidation or virtualization. Sometimes it is replacing aging network equipment. Sometimes it is correcting a configuration, documenting an environment, isolating a legacy system, eliminating an unnecessary subscription, improving backups or scheduling equipment replacements over several budget cycles.
And sometimes the finding is that something is working exactly as it should and there is no reason to change it.
That matters too.
“An IT Baseline Assessment isn’t about finding reasons to replace technology. It’s about understanding the entire environment so you can make better decisions about what to keep, what to improve and what to plan for next.”Shay Stoddard, SNL-Tech Services
If you are not sure what technology your business has, how the pieces fit together or what should be addressed first, an IT Baseline Assessment can establish that starting point across the entire business technology environment.
Frequently Asked Questions About IT Baseline Assessments
Is an IT Baseline Assessment the same as a cybersecurity assessment?
No. Cybersecurity is one part of the assessment, but an IT Baseline Assessment looks at the entire technology environment. That can include computers, servers, networks, internet connectivity, Microsoft 365, applications, licensing, vendors, backups, documentation, equipment lifecycle, security and the business processes that depend on those systems.
Does an IT Baseline Assessment mean I will have to replace old equipment?
No. Finding older technology does not automatically mean I recommend replacing it. I first want to understand what the equipment does, whether it is still supported, what depends on it and what risk or operational concern it creates. Sometimes replacement is appropriate. Sometimes the better answer is planning for a future replacement, changing the architecture or putting compensating controls around a legacy system that cannot immediately be removed.
Can an IT Baseline Assessment find technology we're paying for but no longer using?
Yes, that can be one of the things an assessment uncovers. I may review software licensing, subscriptions, vendor services and agreements to understand what the business is paying for and whether those services are still being used. I may also identify overlapping capabilities that deserve further evaluation. That does not mean every overlapping product should be eliminated. Business requirements, functionality, security, licensing and dependencies need to be considered before making that decision.
What should a business know after an IT Baseline Assessment?
The business should have a much clearer understanding of what technology it depends on, how the environment fits together, what is working properly, what needs attention, what can wait and what should be planned and budgeted for in the future. The assessment should help prioritize technology decisions rather than simply produce a list of problems.
RELATED SNL-TECH SERVICES RESOURCES
Microsoft 365 Audit and Tenant Security ReviewA deeper look specifically at Microsoft 365 licensing, identity, authentication, administrative access, Conditional Access, Defender, Intune, SharePoint, OneDrive, email security and other tenant configuration.
Small Business Incident Response Checklist: Would Your Business Know What to Do?A practical readiness resource and free workbook for documenting emergency contacts, IT responsibilities, Microsoft 365 access, cyber insurance information, recovery priorities and other information a business should have before an incident occurs.
Cyber Insurance Requirements for Small BusinessesExplains the technical questions insurers may ask and the difference between a focused Cyber Insurance Readiness Assessment and the broader IT Baseline Assessment.
AI Governance for Small BusinessLooks at why businesses should understand the underlying technology, identities, data and security environment before connecting AI more deeply into company systems.
Microsoft 365 for Small DoD Contractors: What CMMC Level 2 Actually ChangesA real client example showing why application dependencies, servers, Active Directory, Microsoft 365, networking and business workflow need to be understood before major architecture decisions are made.
ADDITIONAL RESOURCES
National Institute of Standards and Technology: NIST Cybersecurity Framework 2.0 Small Business Quick Start Guide
Current NIST guidance designed to help small and medium sized businesses understand and manage cybersecurity risk, including identifying important technology assets, systems and services.NIST Cybersecurity Framework 2.0 Small Business Quick Start Guide
NIST Small Business Cybersecurity Corner
Additional NIST resources specifically intended to help small businesses understand and manage cybersecurity risks.NIST Small Business Cybersecurity Corner
Federal Trade Commission: Cybersecurity for Small Business
FTC guidance for small businesses covering cybersecurity planning, data and systems, vendors, backups and other foundational considerations.FTC Cybersecurity for Small Business
Microsoft Learn: Hyper V Overview
Microsoft's current technical overview of Hyper V and virtualization in Windows Server.Microsoft Learn: Hyper V Overview
Microsoft: Windows 10 Support Has Ended
Microsoft guidance explaining the October 14, 2025 end of support for Windows 10 and available options for organizations that still have Windows 10 devices.Microsoft Windows 10 End of Support Guidance
Microsoft Lifecycle: Windows XP
Microsoft's lifecycle record documenting the end of support for Windows XP.Microsoft Windows XP Lifecycle Information
CISA and NSA: Top Cybersecurity Misconfigurations
Joint guidance that includes network segmentation and the risks created when network architecture allows unnecessary movement between systems.CISA and NSA Top Cybersecurity Misconfigurations




Comments