The Business Owner’s 10-Minute Cyber Risk Check
August 7, 2026 · 6 min read · By Mark A. Putiyon

Most business owners assume cybersecurity is too technical to reason about without a specialist. In practice, the weaknesses attackers exploit most are rarely exotic — they are unlocked doors that leadership can find with a few plain questions. Here is a ten-minute check you can run today.
1. Does everyone use multi-factor authentication?
If a stolen password is all it takes to reach your email, files, or banking, you are one phishing message away from a breach. Multi-factor authentication (MFA) on email, remote access, and financial systems is the single highest-return control most organizations can turn on. If it is not everywhere, that is finding number one.
2. Are your backups tested and offline?
A backup you have never restored is a hope, not a plan. Ransomware specifically targets backups, so at least one copy must be offline or immutable. Ask when your last successful test restore was. If the answer is "never" or "I am not sure," fix that before anything else.
3. Do former employees still have access?
Accounts for people who have left are a favorite path for attackers because no one is watching them. If offboarding does not immediately disable every account and credential, you have standing risk that grows with every departure.
4. Is your critical data encrypted?
Laptops get lost and stolen. If the data on them is encrypted, a lost device is an inconvenience. If it is not, it may be a reportable breach. Whole-disk encryption is free on modern operating systems — the only question is whether it is turned on.
5. How fast do you patch?
Attackers weaponize known vulnerabilities within days of disclosure. If your systems and applications are not updated on a predictable schedule, you are leaving open doors that are already mapped on the internet.
6. Have your people been trained this year?
The overwhelming majority of breaches begin with a person clicking something. Annual, relevant security awareness training — reinforced with the occasional simulated phishing email — measurably lowers that risk. If your last training was a slideshow years ago, it does not count.
7. Who can move money, and how is it verified?
Business email compromise and wire fraud cost organizations billions each year. If a single email can trigger a payment or a change of banking details without a second, out-of-band verification, that process is a target.
8. Do you know what you actually have?
You cannot protect assets you have not inventoried — the forgotten server, the shadow SaaS account, the vendor with a login. A current inventory of systems, accounts, and third parties is the foundation everything else rests on.
9. Do you have a written incident plan?
When something goes wrong, the difference between a bad day and a catastrophe is whether people know what to do. A short, written plan — who to call, how to isolate systems, what to tell customers — is worth far more than its length.
10. Does someone actually own security?
If cybersecurity is everyone’s job, it is no one’s job. Someone — internal or a trusted partner — needs clear ownership of the program, the authority to act, and a line to leadership.
What to do with your answers
Count your "no" and "not sure" answers. Each one is a prioritized to-do. You do not have to fix everything at once; you have to fix the highest-impact gaps first — and MFA, tested backups, and offboarding are almost always at the top of that list. If you would like a second set of eyes, a professional risk assessment turns this ten-minute check into a concrete, prioritized roadmap.

Ready to Act on This?
Talk with our team about turning these ideas into a concrete plan for your organization.
Get Started