Tech Insights

The 2026 Houston Small Business Cybersecurity Audit: 25 Questions Every Owner Should Ask

Clipboard with glowing cyan checkboxes against Houston skyline at dusk — Aspendora cybersecurity audit

Most Houston small business owners are not technologists, and that’s fine. But in 2026, you need to be able to answer 25 plain-English questions about your cybersecurity posture — because insurers, customers, and regulators are all going to ask them.

This is the same audit we run with prospective clients. Score yourself honestly. Each question is worth one point. Below 18 means you have meaningful gaps.

Identity (5 questions)

  1. Is multi-factor authentication enforced on every email account, including the owner’s?
  2. Is MFA enforced on every remote access tool — VPN, RDP, RMM, anything that connects in from outside the office?
  3. Are admin accounts separate from daily-use accounts?
  4. When an employee leaves, is access removed within 24 hours? Documented?
  5. Is there a password manager in use for shared credentials?

Endpoints (5 questions)

  1. Does every laptop and server run modern endpoint detection (EDR), not just antivirus?
  2. Are operating systems and applications patched on a documented schedule?
  3. Is full-disk encryption enabled on every laptop?
  4. Are personal devices that access company email under any kind of mobile device management?
  5. Are USB drives controlled (whitelisted, encrypted, or blocked)?

Email (5 questions)

  1. Is email filtering blocking phishing and malicious attachments?
  2. Are SPF, DKIM, and DMARC properly configured on your sending domain?
  3. Does every employee take security awareness training at least annually?
  4. Do you run simulated phishing tests at least quarterly?
  5. Is there a one-click way for employees to report suspicious email?

Data and Backup (5 questions)

  1. Are critical files backed up daily — both on-site and off-site?
  2. Is Microsoft 365 (or Google Workspace) backed up by a third-party tool?
  3. Are backups immutable (an attacker can’t delete them with stolen credentials)?
  4. When was the last test-restore? Could you point at a calendar entry?
  5. How long would it take to restore your most critical system from backup?

Response and Recovery (5 questions)

  1. Do you have a written incident response plan with names and phone numbers?
  2. Has the plan been reviewed in the last 12 months?
  3. Do you have cyber insurance, and do you know what it covers?
  4. Do you know the first three people to call if you discover a breach?
  5. Has the business ever practiced an incident-response tabletop exercise?

Scoring

  • 22-25: Strong posture. You’re better than most Houston SMBs we audit.
  • 18-21: Decent baseline. A few gaps to close before they bite.
  • 14-17: Significant gaps. A motivated attacker would find a way in.
  • 10-13: At risk. Insurance is going to be expensive or unavailable.
  • Below 10: You’re due for a breach. Closing these gaps should be this quarter’s priority.

What good looks like

A typical Houston small business we move from "no plan" to fully managed lands in the 22-25 range within 90 days. The first 60 of those days focus on identity (MFA enforcement, EDR rollout, email security), the last 30 on documentation (incident response plan, vendor attestations, training rollout).

The cost? For a 25-person firm, comparable to one mid-level employee’s monthly cost — and dramatically less than the cost of getting it wrong.

What to do next

If you scored below 18 and want a no-pressure conversation about how to close the gaps, book a free 15-minute discovery call. We’ll walk through your scores, talk about what would move the needle fastest, and you decide what to do from there. No pitch.

Aspendora Technologies has audited and protected Houston-area small businesses since 2010. We provide managed IT services, cybersecurity, and data backup and recovery.

Need IT Help?

Talk to a real Houston-based IT pro. 15 minutes, no pressure.

Schedule a Free Consultation