Digital risk audit for small business
I check what happens to your business if one account, one device or one person disappears. What you get is a list of weak points ranked by priority and a clear plan: what to fix today, what within a week, what within a month.
Is your account blocked right now? Read what to do in the first minutes first →
Why audit anything if everything works
Almost every emergency I deal with could have been prevented with a few hours of work. A single administrator, a domain registered to a former contractor, two-factor authentication on a lost phone, work correspondence in a personal inbox, advertising paid for with a personal card: all of it works for years and breaks in a day, usually at the worst possible moment.
The audit answers one practical question: if any element of your digital infrastructure disappears tomorrow, does the business stop? Not “do you have your passwords” but resilience, meaning whether access to your money, your customers and your communication survives when something falls away.
This is not a “security check” in the penetration-testing sense. Small businesses are rarely the target of a directed attack. The threat to them is losing control of their own accounts. So I look at ownership, recoverability and dependencies rather than theoretical vulnerabilities.
What exactly I check
- Access and roles. Who actually owns each account, how many administrators there are, whether former employees and contractors still have access, where two-factor authentication is enabled and whether the backup codes were kept.
- Domain and DNS. Who the domain is registered to, when the registration expires, whether auto-renewal is on, who manages the DNS records, whether there is a risk of losing email if you change contractor.
- Work email. Whether email runs on your domain or the business lives in personal inboxes, how many super administrators there are, whether SPF, DKIM and DMARC are configured, where account recovery emails go.
- Payments and billing. What pays for advertising, hosting and subscriptions, whether payment is tied to a personal card, what happens if it is blocked or expires.
- Advertising and analytics. Whether ad accounts and analytics sit inside the corporate structure, whether they are linked to personal profiles, whether there is a risk of losing historical data.
- Website and data. Where the site is hosted, who has access, whether backups exist, whether restoring from them has ever been tested, where customer data and contracts are stored.
- Dependence on people. Whether there is any action only one person can perform. This is the most common and most underestimated point of failure in a company of two to five people.
How the audit runs
- 1A short questionnaire. You answer a list of questions about which services you use and who manages them. 20 to 30 minutes of your time.
- 2An interview. 45 to 60 minutes: I go through the history, the contractors, past incidents and how the work actually happens rather than how it is described on paper.
- 3Verification. I look at the configurations wherever you can grant access, and record the gaps between what you believe to be true and what is actually the case.
- 4The report. Risks ranked by priority: critical, important, advisable. Each one states the consequence in money and time rather than an abstract “vulnerability”.
- 5The remediation plan. What to do today, what within a week, what within a month. You will close some items yourself by following the instructions; I can close others.
The audit does not require sharing passwords. Where access is needed, I work through an invitation with limited rights that you revoke once the work is done.
Who needs this most
- A good fit. A business that depends on advertising. If a week without Meta or Google Ads noticeably hurts revenue, the audit costs less than one outage.
- A good fit. Companies that grew organically. Accounts were created as needed, some on personal email addresses, some by contractors. Nobody knows the full picture.
- A good fit. A business after parting ways with a contractor. The most common place to discover someone else holds rights to the domain, the company listing and the ad accounts.
- A good fit. Companies with one key person. If all the access rests on one employee or the founder, every holiday is an operational risk.
- Not a fit. Organisations with their own IT department and internal policies: they need process integration, not an audit in this format.
- Not a fit. A request to “test us for vulnerabilities”: that is penetration testing, a different service and different specialists.
What you get at the end
The report is written for a business owner, not for a system administrator. Each item is framed as a consequence: “if the domain expires, email and the website stop at the same time, and recovery takes between a day and a week”, rather than “auto-renewal is not enabled”. That format lets you decide on priorities without technical experience.
Beyond the list of risks you get an ownership map: every significant account, who controls it, what proves ownership, and how to restore access if a device is lost. A separate section covers the order of actions during an incident: a short set of instructions you can print and hand to an employee.
For companies that have never had any documentation, this is the first management document about their digital infrastructure. You can show it to an accountant, a partner or a new employee without explaining it verbally.
A design studio: an audit after an incident
The audit took less than one working day; closing the critical points took about a week. Set against the loss of access that had previously halted communication with clients, those costs are not comparable.
Pricing and terms
The report stays with you and commits you to nothing. Contract and proper invoice from SolveOne EOOD, company number 208821652. For EU companies the invoice is issued under the VAT reverse charge mechanism. For companies with several legal entities and a distributed team, the scope is agreed separately after a short conversation.
FAQ
How is this different from an information security audit?
I do not look for vulnerabilities in code and I do not run penetration tests. I check ownership and recoverability: who controls the accounts, what happens if one element is lost, and how quickly the business gets back to work.
How much of my time will it take?
About two hours: the questionnaire and one interview. I do the rest. The report is usually ready within a few working days.
Do I have to share passwords with you?
No. Where access is needed I use an invitation with minimal rights that you revoke afterwards. Some of the checks are done from your screenshots and answers.
I run a micro business with only two accounts. Is there any point?
Usually yes, precisely because there are so few accounts: the smaller the infrastructure, the greater the dependence on each part of it. The express audit fits that case.
What if the audit finds no problems?
That almost never happens, but if there are no critical points you get written confirmation of resilience and a short list of advisable improvements. That is a result too: you stop guessing.
Can the audit be done after a block rather than before?
It can and it should. Recovery restores access but does not remove the cause. Most of my audits are commissioned after an incident.
Related services
Find out where your weak points are
Describe in two or three sentences which services you use and who manages them. I will tell you which audit format fits and what it will show in your case.
Order an audit