Most small business owners know they should "do something" about cybersecurity, but not where to start. Buying another tool rarely answers that question. A risk assessment does. It turns a vague worry into a short list of specific problems, ranked by how much they could hurt you.
It is also increasingly asked for. Cyber insurers, enterprise customers, and regulators want proof you have looked at your own risks. The good news is that a useful first assessment does not need a consultant or special software. It needs a spreadsheet, a few honest answers, and an afternoon.
What a risk assessment actually is
Risk is simply how likely something bad is to happen, multiplied by how much it would cost you if it did. An assessment walks through that math for the things your business depends on. It is different from a penetration test, which attacks your systems, and from a vulnerability scan, which looks only for technical flaws. An assessment covers people, process, and technology, and ends with priorities, not just findings.
1. Inventory what you are protecting
You cannot rank risks to things you have not listed. Open a spreadsheet and capture four groups:
- Data: customer records, financial files, employee information, contracts, anything regulated.
- Systems: email, line-of-business apps, file storage, accounting, phones, websites.
- Accounts: admin logins, shared logins, vendor portals, bank access.
- Devices and vendors: laptops, phones, printers, and every outside company that touches your data.
For each item, note who owns it and how badly the business would be hurt if it were unavailable for a week or exposed publicly. A basic IT asset list makes this much faster, and your vendor list covers the last group.
2. Find the threats and score them
Next to each asset, write the realistic ways it could be lost, stolen, or misused. Stick to what actually hits small businesses: phishing and business email compromise, ransomware, stolen passwords, a lost laptop, a failed backup, an unpatched system, and a vendor breach.
Then score each pairing on a simple scale:
- Likelihood: 1 = unlikely this year, 2 = possible, 3 = likely or has happened before.
- Impact: 1 = an inconvenience, 2 = costly or embarrassing, 3 = threatens the business.
Multiply the two numbers. A score of 6 or 9 goes to the top of the list; 1 or 2 can wait. Do not agonize over precision. The value is in the ranking, and the conversation that produces it.
While you score, check what is already in place for each risk: multi-factor authentication, tested backups, patching, and endpoint protection. If a control exists and works, lower the likelihood score. If it exists only on paper, leave the score alone.
3. Decide what to fix first
Sort the sheet by score and take the top five. For each, choose one of four responses: reduce the risk with a control, transfer it with cyber insurance, accept it knowingly, or avoid it by stopping the activity. Most top risks for a small business end up being reduced, and the fixes are usually inexpensive:
- Turn on MFA everywhere it is missing, starting with email and admin accounts.
- Test a backup restore instead of assuming it works.
- Remove old accounts and shared logins left behind by former staff.
- Set up automatic patching and review it monthly.
Assign every fix an owner and a due date, and write the date of the assessment at the top of the sheet. That dated record is exactly what an insurer or customer asks for. It also feeds directly into your incident response plan, and it makes a customer security questionnaire far easier to answer.
Common mistakes to avoid
- Doing it once and filing it away. Revisit it every year and after major changes.
- Assessing only technology. Many of the biggest risks are habits, such as reused passwords or unreviewed payment requests.
- Scoring everything as high. If every risk is a 9, nothing is a priority.
- Listing risks without owners and dates. A finding nobody owns will not get fixed.
The takeaway
A cybersecurity risk assessment is not paperwork for its own sake. It is the cheapest way to make sure your limited time and budget go to the problems most likely to hurt you. Block three hours, list what matters, score the threats, and fix the top five. October is Cybersecurity Awareness Month, which makes this a good time to start.
Frequently asked questions
What is a cybersecurity risk assessment?
A cybersecurity risk assessment is a structured review that lists what your business depends on (data, systems, accounts), what could go wrong with each, how likely and damaging it would be, and what you will do about it. The output is a short, ranked list of fixes.
How often should a small business do a risk assessment?
Once a year is the usual baseline, plus a quick refresh after major changes such as a new line-of-business app, a move to the cloud, a new office, or a vendor change. Many cyber insurers and customer security reviews also expect an annual assessment.
Can I do a cybersecurity risk assessment myself?
Yes. A first pass needs no special tools: an inventory list, a simple 1 to 3 scoring scale, and a few honest conversations with the people who use the systems. An outside assessor is useful when you need independent evidence for a regulator, insurer, or customer.
What is the difference between a risk assessment and a vulnerability scan?
A vulnerability scan is an automated technical check that finds missing patches and misconfigurations. A risk assessment is broader: it ranks business impact, covers people and process as well as technology, and decides priorities. A scan is one input to an assessment.
How much does a small business risk assessment cost?
A DIY assessment costs only your time, usually three to four hours. A professional assessment for a small business varies with size and scope, so ask for a fixed price and a written deliverable before you start.
Want help running your first risk assessment?
Ghosxt runs risk assessments for small businesses, turns the results into a prioritized fix list, and handles the fixes. You talk directly to the owner. See current pricing or our cybersecurity services.
Book your free assessmentPrefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.