Most owners I talk to describe their security the same way: "We're probably fine, but honestly, I don't know." A cybersecurity assessment exists to replace that sentence with an actual answer. Here's what one involves for a business with 1–100 employees — and just as important, what it shouldn't involve.

First, what an assessment is not

The five domains a real assessment examines

Names vary between providers, but for a small business the ground that has to be covered is consistent. Our version scores 29 controls across these five:

1. Identity and access

Who can log into what, and how hard is it to steal that ability? Multi-factor authentication coverage (every account, not just admins), admin account separation, password practices, and the one everyone forgets: whether people who left the company are actually gone from your systems.

2. Email security

Email is where most small business incidents start — not because of sophisticated hacking, but because a mailbox got compromised or an invoice got convincingly faked. An assessment checks your phishing protections, your domain's anti-spoofing records (SPF, DKIM, DMARC), and mailbox rules — the quiet auto-forwards attackers plant to read your mail for weeks.

3. Devices

Every laptop is a copy of your business that can be left in a coffee shop. Are drives encrypted? Do updates actually install? Do screens lock? If a workstation walks away, is it an inconvenience or a breach?

4. Data protection

Where does your sensitive data actually live — and who can reach it? Client files in personal OneDrives, "anyone with the link" sharing, thirteen people with access to payroll: this domain finds the gaps between where you think data is and where it really is.

5. Backup and recovery

The honest question isn't "do you have backups?" — almost everyone says yes. It's "have you ever tested a restore?" An assessment verifies that recovery actually works, covers the right systems (including Microsoft 365, which most people wrongly assume backs itself up), and would survive ransomware that targets backups first.

What you should walk away with

If a provider's deliverable is mostly a quote for software, that wasn't an assessment.

What it costs — and what actually drives the price

I won't pretend there's a universal number, because honest pricing is scoped. What moves it: headcount (more people, more accounts and devices to examine), system complexity (one Microsoft 365 tenant is simpler than three platforms and a legacy server), and industry obligations (a dental practice handling patient data has more ground to cover than a design studio).

Here's the part that surprises people: the remediation that follows is usually cheaper than expected, because roughly 90% of what assessments find is fixed by configuring tools the business already pays for — especially Microsoft 365. The expensive version of security is buying products. The effective version is mostly turning things on.

Five checks you can do yourself, today, for free

  1. Count the accounts in your business without MFA. The answer should be zero.
  2. Ask whoever manages IT when anyone last audited mail forwarding rules.
  3. Look up your domain's SPF, DKIM, and DMARC records (free checkers abound). Missing records make you easy to impersonate.
  4. Ask when a backup restore was last tested — not run; tested.
  5. List everyone who's left the company in two years, and check whether their accounts are disabled.

If all five come back clean, genuinely: you're ahead of most. If a couple made you wince, that's not a crisis — it's just the gap between "probably fine" and "measured."

Do you need a consultant for this — or can your IT provider do it?

Maybe they can; ask them. But understand the difference in jobs: your IT provider or MSP keeps things running, and security posture is a separate discipline — measuring, prioritizing, verifying. When we run an assessment, the client's existing IT provider stays and often executes the roadmap. Independence also matters: an assessor who profits from selling you software has a thumb on the scale.

Run a dental or healthcare practice? The same assessment doubles as the security risk analysis your industry expects — here's how it works for practices.

Replace "probably fine" with a number.

Our assessment takes about two weeks, barely interrupts your team, and ends with a score, a plan, and a partner to execute it. Tell us about your business — or call (949) 802-4831.