A Cybersecurity Checklist Isn’t an Assessment: What CISA’s Latest Changes Teach Small Businesses

SofTouch Systems cybersecurity banner comparing a basic security checklist with a full cybersecurity assessment that verifies risks, priorities, and action steps.

A cybersecurity assessment for small businesses should do more than hand the owner a checklist and ask whether antivirus, backups, and MFA are turned on.

That difference became more visible this month after the Cybersecurity and Infrastructure Security Agency, better known as CISA, confirmed that it is retiring six free cybersecurity assessment programs previously delivered to critical-infrastructure organizations by regional staff.

The discontinued programs include Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments, and Cyber Infrastructure Surveys. CISA says organizations will instead be directed toward its Cross-Sector Cybersecurity Performance Goals and related self-assessment resources.

Those programs were not designed for every ordinary small business.

However, the change highlights a cybersecurity problem that applies directly to small companies:

Knowing what you should have is not the same as knowing whether what you have actually works.

SofTouch Systems cybersecurity banner comparing a basic security checklist with a full cybersecurity assessment that verifies risks, priorities, and action steps.
A cybersecurity checklist can identify what to review, but a real assessment verifies whether protections actually work and helps prioritize what to fix first.

CISA’s regional personnel previously helped eligible critical-infrastructure organizations work through structured cybersecurity assessments.

These reviews examined areas such as:

  • Cyber resilience
  • Ransomware preparedness
  • Incident response
  • External dependencies
  • Security controls
  • Operational continuity

CISA confirmed in early September that regional staff will no longer conduct six of these assessment programs. The agency said it is retiring what it considers overlapping legacy questionnaire assessments and will emphasize its Cross-Sector Cybersecurity Performance Goals instead.

The CPGs are useful.

They provide organizations with practical cybersecurity goals and questions that can help identify areas needing attention.

But some former officials and industry professionals have argued that self-assessment tools do not fully replace guided evaluations in which an experienced adviser asks questions, examines the environment, and helps the organization understand what the answers actually mean.

That distinction matters far beyond utilities and other critical infrastructure.


A checklist asks:

Do you have backups?

An assessment asks:

What is being backed up, where is it stored, when did the last backup succeed, and has anyone tested a restore?

A checklist asks:

Do employees use MFA?

An assessment asks:

Which accounts use MFA, which authentication methods are allowed, and are any important accounts still exposed?

A checklist asks:

Do you have antivirus?

An assessment asks:

Is every device enrolled, updated, reporting correctly, and actively monitored?

That is the difference.

A checklist tells you what to look for.

An assessment investigates what is actually happening.


This does not mean cybersecurity checklists are bad.

They are extremely useful starting points.

CISA’s Cybersecurity Performance Goals were created to help organizations prioritize a baseline set of cybersecurity practices. CISA argues that its CPG framework shares many of the same objectives as the programs it is retiring.

For a small business, a checklist can remind the owner to review:

  • MFA
  • Password practices
  • Backups
  • Antivirus
  • Software updates
  • Employee training
  • Incident-response procedures
  • Vendor access
  • Former employee accounts

That is valuable.

The problem begins when completing the checklist creates false confidence.

Checking a box does not prove the control works.


Backups are one of the clearest examples.

A business owner may confidently answer:

Yes, we have backups.

That answer sounds reassuring.

But an assessment should continue asking questions.

What computers are covered?

Are cloud files included?

Are Microsoft 365 mailboxes protected?

How often does the backup run?

Who receives failure alerts?

Can ransomware reach the backup?

When was the last successful restore test?

What would happen if the accounting computer died this afternoon?

Those questions turn “we have backups” into useful information.

That is what assessment work is supposed to accomplish.


A small company may also say:

We use strong passwords.

What does that mean?

Does every employee use a unique password?

Are passwords stored in browsers?

Do employees share credentials?

Does the owner know everyone’s password?

Are former employee accounts still active?

Does the business use a password manager?

Which accounts support passkeys?

Where is MFA missing?

Password security is not one yes-or-no question.

It is a system.

That is why STS emphasizes password-first security rather than simply telling businesses to create longer passwords.


Another common answer is:

We already have antivirus.

Good.

Now ask:

Is every business computer protected?

Are remote laptops included?

Is the antivirus license current?

Are detections being reviewed?

Did a device stop checking in three weeks ago?

Who receives alerts?

What happens after malware is detected?

Traditional antivirus is one layer.

Managed endpoint protection and monitoring add visibility.

An assessment identifies whether that visibility exists.


This is one of the largest practical IT problems for smaller companies.

Technology accumulates gradually.

A five-person company buys laptops.

Someone adds Microsoft 365.

Another employee installs cloud storage.

The bookkeeper uses an accounting service.

A vendor installs remote-access software.

Someone adds a Wi-Fi extender.

Employees create accounts for AI tools.

Years later, nobody has a complete inventory.

That makes cybersecurity difficult because you cannot properly protect systems you do not know exist.

A useful assessment starts by answering basic questions:

What devices, applications, accounts, vendors, and data does the company depend on?

That inventory becomes the foundation for everything else.


Large enterprises may have dedicated security teams.

Most small businesses do not.

That creates a structural problem similar to the one behind CISA’s critical-infrastructure programs.

Smaller organizations still depend on technology.

  • They still face ransomware.
  • They still handle financial information.
  • They still have employees who can be phished.
  • They simply have fewer people available to evaluate those risks.

That is one reason outside IT providers can add value.

The goal should not be to sell every available security product.

The goal should be to identify the biggest weaknesses first.


Imagine an assessment finds these five issues:

  1. One employee does not use MFA.
  2. Three computers need routine application updates.
  3. The guest Wi-Fi password is weak.
  4. Backups have failed for six weeks.
  5. A former employee still has Microsoft 365 access.

All five deserve attention.

They do not necessarily deserve equal priority.

The failed backups and active former employee account may require immediate action.

The guest Wi-Fi password may matter too, but it may not be the first problem to fix.

A checklist finds issues.

An experienced assessment helps prioritize them.

That matters when a small business has limited time and budget.


At minimum, a practical review should look at:

  • Computers and devices
  • Operating-system versions
  • Patch status
  • Antivirus and endpoint protection
  • Password practices
  • MFA
  • Employee accounts
  • Administrator privileges
  • Backups
  • Restore readiness
  • Email security
  • Microsoft 365 or Google Workspace settings
  • Remote-access tools
  • Network and Wi-Fi security
  • Critical vendors
  • Employee security procedures

The objective is not perfection.

The objective is understanding where risk is concentrated.


Another weakness of self-assessments is that the business may discover twenty problems and still not know what to do next.

A useful review should produce an action plan.

For example:

Fix immediately

Former employee account still active.

Fix this week

Backups failing.

Fix this month

Move employees from reused passwords into a business password manager.

Plan next quarter

Replace two aging computers that cannot support current security requirements.

Now the assessment becomes manageable.

It turns cybersecurity from a vague concern into a sequence of tasks.


CISA continues to offer useful cybersecurity frameworks and resources.

Businesses should use them.

Small companies can also benefit from checklists created by vendors, insurers, industry groups, and cybersecurity organizations.

But they should understand what those resources are designed to do.

A worksheet can identify questions.

It cannot inspect your computer, determine whether an alert is being ignored, test whether your backup restores or explain why a firewall rule exists.

And it most definitely cannot ask the follow-up question nobody thought to put on the checklist.

That requires investigation.


What cybersecurity assessment programs did CISA retire?

CISA confirmed that regional staff will stop performing six programs: Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments, and Cyber Infrastructure Surveys.

Did CISA stop offering cybersecurity guidance?

No. CISA continues to provide cybersecurity resources, including its Cross-Sector Cybersecurity Performance Goals. The recent change concerns six guided assessment programs delivered through regional personnel.

Are small businesses eligible for these CISA assessments?

The retired programs primarily served eligible critical-infrastructure organizations rather than every small business. However, the difference between self-assessment and guided assessment applies broadly to SMB cybersecurity.

Is a cybersecurity checklist enough for a small business?

A checklist is a useful starting point, but it cannot verify whether security controls are correctly configured or functioning. Businesses should periodically review the actual environment.

How often should a small business complete an IT security review?

An annual review is a reasonable baseline for many small companies. Reviews should also happen after major technology changes, rapid hiring, a security incident, a move, or significant changes to cloud services.

What should happen after an assessment?

The business should receive a prioritized list of risks and practical recommendations. The most important problems should be addressed first rather than attempting to fix everything at once.


CISA’s recent changes provide a useful reminder.

Cybersecurity frameworks matter.

Checklists matter.

Self-assessment tools matter.

But there is a difference between knowing what questions to ask and knowing whether your business has the right answers.

Small businesses need both.

Start with the checklist.

Then verify the environment.

Look at the computers.

Review the accounts.

Check the backups.

Confirm MFA.

Find outdated software.

Identify who has access.

Then prioritize what needs attention.

That is how cybersecurity becomes practical rather than theoretical.


SofTouch Systems helps small Texas businesses review their current IT security, identify practical weaknesses, and prioritize the fixes that matter most.

Our goal is not to hand you another long checklist.

We help you understand what is working, what needs attention, and what should happen next.

Start with a free 15-minute IT security check.

SofTouch Systems can help you review passwords, endpoint protection, backups, updates, employee access, and other basic security controls without turning the process into enterprise-level complexity.

Schedule your free IT security check with SofTouch Systems.

SofTouch Systems Simplifying technology, maximizing results

Sources:



Discover more from SofTouch Systems

Subscribe to get the latest posts sent to your email.

What do y'all think?

Discover more from SofTouch Systems

Subscribe now to keep reading and get access to the full archive.

Continue reading