Small business IT checklist: 45 items, with the why
A complete, copyable IT checklist for small businesses, grouped by accounts, devices, network, backup, security, vendors, and documentation.
A complete small business IT checklist covers seven areas: accounts, devices, network, backup, security, vendors, and documentation. The 45 items below are grouped that way, each with a short reason, so you can copy the list, work through it once, and then review it once or twice a year. It draws on small business guidance from CISA, the FTC, and NIST. If you only have an hour, start with the five items in the next section.
Where should you start?
These five address the problems that do the most damage:
- The business owns its domain name and email administrator accounts (items 1 and 2).
- Multi-factor authentication is on for every email account (item 4).
- Backups exist and a restore has been tested (items 24 and 27).
- Every computer runs a supported operating system with automatic updates (items 10 and 11).
- Former staff have no active accounts (item 6).
How to use this checklist
Copy it into a document or spreadsheet, add a column for the date checked and the person responsible, and mark each item done, not done, or not applicable. Not every item applies to every business. A three-person office with no server can skip a few, and a practice handling patient records will need more than this list, including a formal risk analysis.
Accounts
- 1. The domain name is registered to the business. Whoever controls the domain controls your email and website. Confirm the registrant and contact email at your registrar.
- 2. At least two trusted people hold email administrator accounts. Microsoft recommends two or more emergency access accounts so an organization cannot be locked out if one person is unavailable.
- 3. Administrator accounts are separate from everyday accounts. A compromised everyday mailbox then does not hand over control of the whole system.
- 4. Multi-factor authentication (MFA) is required for every user. MFA is a second sign-in step beyond the password. CISA asks small businesses to make it mandatory and to check for accounts that are not compliant. See why multi-factor authentication matters.
- 5. Every person has their own login. Shared logins make it impossible to tell who did what, or to remove one person’s access.
- 6. Departing staff lose access the same day. Lingering accounts are an open door. A written onboarding and offboarding process makes this routine.
- 7. Access matches each person’s role. People should reach the files and systems their job needs and no more, which limits the damage from any single compromised account.
- 8. Staff use a password manager. The FTC recommends passwords of at least 12 characters that are never reused, which is only practical with a tool. See our guide to password managers for small businesses.
- 9. Banking, payroll, and accounting logins also use MFA. These accounts move money, so they deserve the same protection as email.
Devices
- 10. Every computer runs a supported operating system. Microsoft ended support for Windows 10 on October 14, 2025, so those machines no longer receive routine security updates.
- 11. Automatic updates are on for the operating system, browsers, and key applications. Updates close the security holes attackers use. Someone should confirm they are actually installing.
- 12. Laptop and desktop drives are encrypted. BitLocker on Windows and FileVault on Mac protect data if a device is lost or stolen. CISA lists disk encryption among its steps for small businesses.
- 13. Encryption recovery keys are stored where the business can reach them. Without the key, an encrypted drive may be unrecoverable after a hardware fault.
- 14. Staff do not have administrator rights on their computers. CISA recommends removing them so that malicious software cannot install itself as easily.
- 15. Screens lock automatically after a few minutes. An unattended, unlocked computer gives anyone nearby full access.
- 16. Phones and tablets with business email have a passcode and can be wiped remotely. A lost phone should not mean lost client data.
- 17. Old devices are wiped before disposal. The FTC notes that deleting files alone does not fully remove them.
- 18. There is a replacement plan. Knowing which computers are due for replacement each year turns a surprise expense into a budget line.
Network
- 19. The router or firewall admin password has been changed from the default. Default passwords are published online.
- 20. Router, firewall, and access point firmware is up to date. Network devices need security updates just as computers do, and they rarely update themselves.
- 21. Wi-Fi uses WPA2 or WPA3 encryption with a strong password. The FTC recommends both. Older standards can be broken easily.
- 22. Guests use a separate network. Visitors and personal devices should not sit alongside business computers. Payment terminals and cameras benefit from their own network as well.
- 23. Remote access goes through a VPN or another secured method with MFA. A VPN is an encrypted connection to office systems. Remote desktop exposed directly to the internet is a well-known risk.
Backup
- 24. Everything important is backed up automatically. That includes shared files, accounting data, line-of-business databases, and any server. Manual backups get forgotten.
- 25. At least one copy is off-site or in the cloud. A fire, theft, or flood should not take the backup along with the original.
- 26. At least one copy cannot be altered from the office network. Ransomware looks for connected backups. A copy that is offline or locked against changes survives.
- 27. A restore has been tested in the past 12 months. CISA asks businesses to regularly test partial and full restores. A backup that has never been restored is unproven.
- 28. Cloud email and files are included. Check what your Microsoft 365 or Google Workspace plan lets you recover and for how long.
- 29. You know how long a recovery would take. If your main system would take three days to restore, it is better to know that now. Our business data backup guide helps you plan.
Security
- 30. Endpoint protection runs on every computer. This is security software that detects and blocks threats on each device. Someone should see its alerts.
- 31. Email filtering for spam and phishing is turned on and tuned. Phishing, meaning scam messages that trick people into giving up passwords or money, remains a common starting point for attacks.
- 32. Your domain has SPF, DKIM, and DMARC records. These email authentication settings make it harder for others to send mail pretending to be you. The FTC covers them in its email authentication guidance.
- 33. Staff receive short, regular security training. The FTC recommends training on a regular schedule. People who can spot a phishing email stop attacks that filters miss.
- 34. Payment changes are verified through a second channel. A request to change bank details should be confirmed using contact details you already hold, never those in the message.
- 35. There is a one-page incident response plan. CISA asks small businesses to write down what happens before, during, and after an incident: who decides, who to contact, and how to isolate a device.
- 36. You have checked your cyber insurance position. Know whether you are covered and what security measures the policy requires you to maintain.
Vendors
- 37. You have a list of every vendor with access to your systems or data. IT providers, software vendors, bookkeepers, and web designers often hold logins.
- 38. Vendor access is limited to what each one needs and uses MFA. The FTC’s vendor security guidance recommends both.
- 39. Internet provider details are on file. Account number, support contact, and circuit details save time during an outage.
- 40. Renewal dates are tracked. Domains, security certificates, software subscriptions, and warranties all expire. A lapsed domain can take email and the website down.
- 41. Contracts state that accounts, data, and documentation belong to the business. This keeps future changes simple.
Documentation
- 42. There is a current inventory of devices. Make, model, serial number, user, purchase date, and warranty status. You cannot protect or budget for what you cannot see.
- 43. There is a list of software, licenses, and who owns each subscription. It prevents paying for unused licenses and losing access when a card expires.
- 44. The network is described in writing. Internet provider, equipment, Wi-Fi network names, and address ranges, so a problem can be diagnosed by someone who did not build it.
- 45. Critical credentials are stored where the business can reach them. A business-owned password manager with access for two trusted people means nothing depends on one person’s memory.
How often should you review it?
| Task | Suggested frequency |
|---|---|
| Remove departed staff, confirm backups ran | As it happens, and weekly |
| Confirm updates are installing, review security alerts | Monthly |
| Test a file restore, review user and admin lists | Quarterly |
| Full checklist review, device replacement plan, renewals, insurance | Yearly |
These intervals are a reasonable starting point for a small office. Adjust them to how quickly your business changes.
When is this more than you need?
A one-person business using a laptop and cloud apps can cover the essentials with items 1, 4, 8, 10, 11, 12, 24, 25, and 27. The rest of the list becomes relevant as you add staff, shared systems, an office network, or regulated data.
Common mistakes
- Treating the checklist as a one-time event. Staff, devices, and vendors change, and the list goes stale.
- Ticking “backups” without testing a restore. Item 27 is the one that proves item 24.
- Turning on MFA for some people. Attackers only need the one account without it.
- Keeping the documentation in one person’s head. If it is not written down, it does not count.
Common questions
What should be on a small business IT checklist?
Seven areas: accounts (ownership, MFA, offboarding), devices (supported systems, updates, encryption), network (firmware, Wi-Fi security, guest separation), backup (automatic, off-site, tested), security (endpoint protection, email filtering, training, incident plan), vendors (access and renewals), and documentation (inventory, licenses, credentials).
How long does it take to go through?
A first pass to mark each item as done, not done, or unknown can often be done in one sitting for a small office. Fixing what you find takes longer and depends on the gaps. Later reviews are quicker because the documentation already exists.
Does this checklist make us compliant with HIPAA or PCI DSS?
No. It covers sound general practice. Regulations such as HIPAA and PCI DSS have their own specific requirements, including formal risk assessments and documentation. Use this as a foundation and work with a qualified compliance advisor for the rest.
Who should own the checklist?
One named person at the business, even if the work is done by an outside provider. CISA suggests appointing a security program manager for exactly this reason: someone inside the business should be able to see that each item is being handled.
How Coastal Growth Co. can help
We can work through this checklist with you, document what is in place, and fix the gaps as a defined project, or take on the recurring items as ongoing support. We agree the scope and price before paid work starts. See managed IT and support and networks, security, and cameras for the work involved, or get in touch to talk through your results. We are based in Laguna Hills and work with businesses across South Orange County.
- IT checklist
- small business
- cybersecurity
- backup
- documentation
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward