Most businesses have never actually inventoried what they run, and the first assessment almost always surprises the owner: forgotten admin accounts, a server out of warranty, backups that quietly stopped months ago. This checklist walks the same territory a professional IT and network assessment covers, so you can either work it yourself or know exactly what a good provider should be checking.
The checklist
Print it, or paste it into a doc and work through it as a team. An item you can’t answer is a finding in itself.
1. Inventory and hardware
- Every workstation, laptop, server, and mobile device is listed, with owner, age, and operating system
- No machines running an unsupported OS (Windows 10 reached end of support in October 2025)
- Servers and network gear are under warranty or have a documented replacement plan
- You know which machines are older than 5 years and what replacing them costs
- Software licenses are inventoried and match what’s installed
2. Network
- The firewall is a business class device, under support, with firmware current
- No remote access ports (RDP, VNC) open to the internet
- Wi-Fi is segmented: guest traffic can’t reach business systems
- Switch and wiring closet gear is labeled and documented
- Internet bandwidth matches actual usage, and there’s a failover plan if the primary line drops
- Remote workers connect through a VPN or secured cloud access, not exposed services
3. Accounts and identity
- Multi factor authentication is enforced on every email account, not just some
- MFA also covers VPN, remote access, and admin logins
- Former employees’ accounts are disabled, verified against a current staff list
- Admin rights are limited to people who need them, and nobody works daily from an admin account
- No shared logins for business systems
- Company credentials have been checked against known breach dumps
4. Security controls
- Every device runs endpoint protection (EDR, not just legacy antivirus) and someone reviews its alerts
- Operating systems and applications are patched on a schedule, with stragglers chased down
- Email filtering and spoofing protection (SPF, DKIM, DMARC) are configured
- A payment change or wire request requires verbal verification before money moves
- Staff receive recurring security awareness training, not a single onboarding video
- Laptops and portable drives are encrypted
5. Backups and recovery
- You know exactly what is backed up, and what isn’t
- At least one backup copy is off site and immutable, so ransomware can’t encrypt or delete it
- Microsoft 365 (email, OneDrive, SharePoint) has its own third party backup
- Someone has actually restored from backup in the last quarter, and timed it
- A written recovery plan exists: what comes back first, how fast, and who does it
6. Documentation and vendors
- Network diagrams, passwords, and vendor contacts are documented somewhere that survives a disaster
- You know who to call, and in what order, when something breaks
- Cyber insurance is in place, and the application’s answers are actually true
- Compliance obligations (HIPAA, FTC Safeguards, client security requirements) are identified and mapped to controls
How do you score it?
Don’t average it. Rank the misses by what they’d cost you. An unchecked box in accounts, security, or backups is urgent, because those are the three areas that turn a bad day into a closed business: a phished password with no MFA behind it, a machine with no endpoint protection, or a backup that doesn’t restore. Inventory and documentation gaps matter, but they hurt you slowly; the security and recovery gaps hurt you all at once.
If more than a handful of boxes are unchecked, or unanswerable, that’s normal. Most 10 to 100 person businesses we assess start there. The point of the checklist is that the fixes now have an order.
Where a professional assessment goes further
Self assessment finds the visible gaps. A professional network assessment adds the parts that need tooling: scanning every device instead of trusting the list, verifying MFA coverage account by account, checking whether your credentials already circulate in breach dumps, testing whether backups genuinely restore, and reviewing firewall rules line by line. It also produces the documentation, which is increasingly what clients and cyber insurers want to see.
Braintek offers this as a free risk assessment for Houston and Dallas-Fort Worth businesses, performed with an independent third party so the findings are objective rather than a provider grading its own work. You get a prioritized, plain English report, what’s exposed, what it would cost you, and what to fix first. From there, fixes can go to your internal team, your current provider, or Braintek’s managed IT services, which typically run $150 to $250 per device per month with the security and backup layers above included and maintained.