A cybersecurity assessment for small businesses should do more than hand the owner a checklist and ask whether antivirus, backups, and MFA are turned on.
That difference became more visible this month after the Cybersecurity and Infrastructure Security Agency, better known as CISA, confirmed that it is retiring six free cybersecurity assessment programs previously delivered to critical-infrastructure organizations by regional staff.
The discontinued programs include Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments, and Cyber Infrastructure Surveys. CISA says organizations will instead be directed toward its Cross-Sector Cybersecurity Performance Goals and related self-assessment resources.
Those programs were not designed for every ordinary small business.
However, the change highlights a cybersecurity problem that applies directly to small companies:
Knowing what you should have is not the same as knowing whether what you have actually works.

What Did CISA Change?
CISA’s regional personnel previously helped eligible critical-infrastructure organizations work through structured cybersecurity assessments.
These reviews examined areas such as:
- Cyber resilience
- Ransomware preparedness
- Incident response
- External dependencies
- Security controls
- Operational continuity
CISA confirmed in early September that regional staff will no longer conduct six of these assessment programs. The agency said it is retiring what it considers overlapping legacy questionnaire assessments and will emphasize its Cross-Sector Cybersecurity Performance Goals instead.
The CPGs are useful.
They provide organizations with practical cybersecurity goals and questions that can help identify areas needing attention.
But some former officials and industry professionals have argued that self-assessment tools do not fully replace guided evaluations in which an experienced adviser asks questions, examines the environment, and helps the organization understand what the answers actually mean.
That distinction matters far beyond utilities and other critical infrastructure.
What Is the Difference Between a Cybersecurity Checklist and an Assessment?
A checklist asks:
Do you have backups?
An assessment asks:
What is being backed up, where is it stored, when did the last backup succeed, and has anyone tested a restore?
A checklist asks:
Do employees use MFA?
An assessment asks:
Which accounts use MFA, which authentication methods are allowed, and are any important accounts still exposed?
A checklist asks:
Do you have antivirus?
An assessment asks:
Is every device enrolled, updated, reporting correctly, and actively monitored?
That is the difference.
A checklist tells you what to look for.
An assessment investigates what is actually happening.
Why Checklists Are Still Useful
This does not mean cybersecurity checklists are bad.
They are extremely useful starting points.
CISA’s Cybersecurity Performance Goals were created to help organizations prioritize a baseline set of cybersecurity practices. CISA argues that its CPG framework shares many of the same objectives as the programs it is retiring.
For a small business, a checklist can remind the owner to review:
- MFA
- Password practices
- Backups
- Antivirus
- Software updates
- Employee training
- Incident-response procedures
- Vendor access
- Former employee accounts
That is valuable.
The problem begins when completing the checklist creates false confidence.
Checking a box does not prove the control works.
“Yes, We Have Backups” Is Not Enough
Backups are one of the clearest examples.
A business owner may confidently answer:
Yes, we have backups.
That answer sounds reassuring.
But an assessment should continue asking questions.
What computers are covered?
Are cloud files included?
Are Microsoft 365 mailboxes protected?
How often does the backup run?
Who receives failure alerts?
Can ransomware reach the backup?
When was the last successful restore test?
What would happen if the accounting computer died this afternoon?
Those questions turn “we have backups” into useful information.
That is what assessment work is supposed to accomplish.
The Same Problem Applies to Password Security
A small company may also say:
We use strong passwords.
What does that mean?
Does every employee use a unique password?
Are passwords stored in browsers?
Do employees share credentials?
Does the owner know everyone’s password?
Are former employee accounts still active?
Does the business use a password manager?
Which accounts support passkeys?
Where is MFA missing?
Password security is not one yes-or-no question.
It is a system.
That is why STS emphasizes password-first security rather than simply telling businesses to create longer passwords.
Antivirus Can Create the Same False Confidence
Another common answer is:
We already have antivirus.
Good.
Now ask:
Is every business computer protected?
Are remote laptops included?
Is the antivirus license current?
Are detections being reviewed?
Did a device stop checking in three weeks ago?
Who receives alerts?
What happens after malware is detected?
Traditional antivirus is one layer.
Managed endpoint protection and monitoring add visibility.
An assessment identifies whether that visibility exists.
Small Businesses Often Do Not Know What They Have
This is one of the largest practical IT problems for smaller companies.
Technology accumulates gradually.
A five-person company buys laptops.
Someone adds Microsoft 365.
Another employee installs cloud storage.
The bookkeeper uses an accounting service.
A vendor installs remote-access software.
Someone adds a Wi-Fi extender.
Employees create accounts for AI tools.
Years later, nobody has a complete inventory.
That makes cybersecurity difficult because you cannot properly protect systems you do not know exist.
A useful assessment starts by answering basic questions:
What devices, applications, accounts, vendors, and data does the company depend on?
That inventory becomes the foundation for everything else.
Why Small Organizations Benefit Most From Outside Assessment
Large enterprises may have dedicated security teams.
Most small businesses do not.
That creates a structural problem similar to the one behind CISA’s critical-infrastructure programs.
Smaller organizations still depend on technology.
- They still face ransomware.
- They still handle financial information.
- They still have employees who can be phished.
- They simply have fewer people available to evaluate those risks.
That is one reason outside IT providers can add value.
The goal should not be to sell every available security product.
The goal should be to identify the biggest weaknesses first.
A Good Cybersecurity Assessment Should Prioritize Risk
Imagine an assessment finds these five issues:
- One employee does not use MFA.
- Three computers need routine application updates.
- The guest Wi-Fi password is weak.
- Backups have failed for six weeks.
- A former employee still has Microsoft 365 access.
All five deserve attention.
They do not necessarily deserve equal priority.
The failed backups and active former employee account may require immediate action.
The guest Wi-Fi password may matter too, but it may not be the first problem to fix.
A checklist finds issues.
An experienced assessment helps prioritize them.
That matters when a small business has limited time and budget.
What Should a Small-Business IT Security Review Examine?
At minimum, a practical review should look at:
- Computers and devices
- Operating-system versions
- Patch status
- Antivirus and endpoint protection
- Password practices
- MFA
- Employee accounts
- Administrator privileges
- Backups
- Restore readiness
- Email security
- Microsoft 365 or Google Workspace settings
- Remote-access tools
- Network and Wi-Fi security
- Critical vendors
- Employee security procedures
The objective is not perfection.
The objective is understanding where risk is concentrated.
Assessment Should Lead to Action
Another weakness of self-assessments is that the business may discover twenty problems and still not know what to do next.
A useful review should produce an action plan.
For example:
Fix immediately
Former employee account still active.
Fix this week
Backups failing.
Fix this month
Move employees from reused passwords into a business password manager.
Plan next quarter
Replace two aging computers that cannot support current security requirements.
Now the assessment becomes manageable.
It turns cybersecurity from a vague concern into a sequence of tasks.
Free Security Tools Still Have Value
CISA continues to offer useful cybersecurity frameworks and resources.
Businesses should use them.
Small companies can also benefit from checklists created by vendors, insurers, industry groups, and cybersecurity organizations.
But they should understand what those resources are designed to do.
A worksheet can identify questions.
It cannot inspect your computer, determine whether an alert is being ignored, test whether your backup restores or explain why a firewall rule exists.
And it most definitely cannot ask the follow-up question nobody thought to put on the checklist.
That requires investigation.
Frequently Asked Questions About Cybersecurity Assessments
CISA confirmed that regional staff will stop performing six programs: Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments, and Cyber Infrastructure Surveys.
No. CISA continues to provide cybersecurity resources, including its Cross-Sector Cybersecurity Performance Goals. The recent change concerns six guided assessment programs delivered through regional personnel.
The retired programs primarily served eligible critical-infrastructure organizations rather than every small business. However, the difference between self-assessment and guided assessment applies broadly to SMB cybersecurity.
A checklist is a useful starting point, but it cannot verify whether security controls are correctly configured or functioning. Businesses should periodically review the actual environment.
An annual review is a reasonable baseline for many small companies. Reviews should also happen after major technology changes, rapid hiring, a security incident, a move, or significant changes to cloud services.
The business should receive a prioritized list of risks and practical recommendations. The most important problems should be addressed first rather than attempting to fix everything at once.
A Checklist Can Start the Conversation. It Should Not End It.
CISA’s recent changes provide a useful reminder.
Cybersecurity frameworks matter.
Checklists matter.
Self-assessment tools matter.
But there is a difference between knowing what questions to ask and knowing whether your business has the right answers.
Small businesses need both.
Start with the checklist.
Then verify the environment.
Look at the computers.
Review the accounts.
Check the backups.
Confirm MFA.
Find outdated software.
Identify who has access.
Then prioritize what needs attention.
That is how cybersecurity becomes practical rather than theoretical.
Find the Gaps Before an Attacker Does
SofTouch Systems helps small Texas businesses review their current IT security, identify practical weaknesses, and prioritize the fixes that matter most.
Our goal is not to hand you another long checklist.
We help you understand what is working, what needs attention, and what should happen next.
Start with a free 15-minute IT security check.
SofTouch Systems can help you review passwords, endpoint protection, backups, updates, employee access, and other basic security controls without turning the process into enterprise-level complexity.
Schedule your free IT security check with SofTouch Systems.
Sources:
- CISA Cross-Sector Cybersecurity Performance Goals
- Cybersecurity Dive: CISA cybersecurity assessments ending
- Utility Dive: CISA assessment program changes
Discover more from SofTouch Systems
Subscribe to get the latest posts sent to your email.
