2026-08-07 · 12-15 min read · Security Hardening

Essential Cybersecurity Audit Checklist for SMBs: SkyCore's 2026 Guide

Cybersecurity Audit Checklist for SMBs

For Small and Medium-sized Businesses (SMBs), a robust cybersecurity posture isn't a luxury; it's a necessity. With cyber threats escalating in sophistication and frequency, a proactive approach is critical. This essential cybersecurity audit checklist for SMBs, crafted by SkyCore Solutions, provides a structured framework to evaluate your current security landscape, identify vulnerabilities, and build a resilient defense. We emphasize a CLI-first approach, leveraging Azure CLI and PowerShell to get precise, actionable insights.

Prerequisites

Step 1: Define Audit Scope & Inventory Assets

Before diving into technical checks, it's crucial to establish a clear audit scope. Identify all systems, applications, data stores, and cloud resources that are critical to your business operations. This step also involves compiling a comprehensive, up-to-date inventory of your assets, both on-premises and in the cloud. A detailed asset inventory is the bedrock for any effective security audit, ensuring no critical components are overlooked.

# List all Azure resources in a subscription for initial inventory discovery
az resource list --query '[].{Name:name, Type:type, ResourceGroup:resourceGroup, Location:location}' --output table

az resource list: Command to list resources.

--query '[].{Name:name, Type:type, ResourceGroup:resourceGroup, Location:location}': JMESPath query to filter output to specific properties.

--output table: Formats the output as a readable table.

Portal alternative: Navigate to 'All resources' in the Azure portal. Use the filter options to sort by resource type, location, or resource group. Export to CSV for an inventory snapshot.

Expected result: A tabulated list of all Azure resources, providing a foundational inventory of your cloud footprint. Supplement this with manual inventory of on-premises hardware, software licenses, and SaaS applications.

Step 2: Azure AD & Identity Governance

Identity is the new perimeter. This step focuses on auditing your Azure Active Directory (now Microsoft Entra ID) configuration, scrutinizing user accounts, Multi-Factor Authentication (MFA) enforcement, Conditional Access policies, and Privileged Identity Management (PIM). Weaknesses here can grant attackers direct access to your resources.

# Get all users and check their MFA status (requires Microsoft Graph PowerShell SDK)
Connect-MgGraph -Scopes 'User.Read.All'
Get-MgUser -All | Select-Object DisplayName, UserPrincipalName, @{Name='MfaStatus'; Expression={($_.UserPrincipalName | Get-MsolUser).StrongAuthenticationRequirements.State}}

Connect-MgGraph -Scopes 'User.Read.All': Connects to Microsoft Graph API with necessary permissions.

Get-MgUser -All: Retrieves all user objects from Microsoft Entra ID.

Select-Object ...: Selects and formats desired properties, including a custom property for MFA status.

Common pitfall: Relying on legacy `Get-MsolUser` cmdlets. While still functional for some MFA checks, the Microsoft Graph PowerShell SDK is the recommended, future-proof approach. Ensure you have the `Microsoft.Graph.Users` module installed (`Install-Module Microsoft.Graph.Users`).

Portal alternative: In the Microsoft Entra admin center, navigate to 'Users' > 'All users'. For MFA status, go to 'Identity' > 'Protection' > 'Identity Secure Score' or 'MFA status' under 'Per-user MFA'. Review Conditional Access policies under 'Protection' > 'Conditional Access'.

Expected result: A list of all user accounts, their roles, and clear indication of MFA enrollment and enforcement status. Verify that all administrative accounts and external users have MFA enabled and that Conditional Access policies are applied to critical applications and resources, blocking legacy authentication.

Step 3: Endpoint Protection & Device Management

Endpoints (laptops, desktops, mobile devices) are prime targets. This step involves verifying the deployment and efficacy of antivirus/Endpoint Detection and Response (EDR) solutions, ensuring devices are configured securely, and that a robust patch management process is in place. Unpatched systems and unprotected endpoints are easy entry points for malware and ransomware.

# Check Microsoft Defender Antivirus status on a Windows endpoint
Get-MpComputerStatus | Select-Object AntivirusEnabled, RealTimeProtectionEnabled, FullScanEndTime, SignatureLastUpdated, RebootRequired, ComputerStatus

Get-MpComputerStatus: Retrieves the current status of Microsoft Defender Antivirus.

Select-Object ...: Filters and displays key security health indicators for the endpoint.

Portal alternative: For Intune-managed devices, go to the Microsoft Endpoint Manager admin center > 'Devices' > 'All devices'. Review compliance policies, security baselines, and endpoint security status reports. For Defender for Endpoint, use the Microsoft 365 Defender portal.

Expected result: Confirmation that all corporate endpoints have up-to-date antivirus/EDR agents installed, real-time protection is active, and devices are receiving regular security updates. Verify that device hardening policies (e.g., firewall, screen lock, encryption) are enforced via MDM solutions like Intune.

Step 4: Network Perimeter & Segmentation

Your network's perimeter and internal segmentation are critical for containing breaches. This audit step reviews firewall rules, virtual network configurations, Network Security Groups (NSGs), and network segmentation strategies in Azure. Proper segmentation isolates critical assets, limiting lateral movement for attackers.

# List all Network Security Groups (NSGs) and their associated rules in a resource group
az network nsg list -g  --query '[].{Name:name, Location:location, Rules:securityRules[].{Name:name, Direction:direction, Access:access, Priority:priority, SourceAddressPrefix:sourceAddressPrefix, DestinationPortRange:destinationPortRange}}' --output json

az network nsg list -g : Lists NSGs within a specified resource group.

--query '[].{...}': Extracts NSG name, location, and details of each security rule.

--output json: Provides detailed output in JSON format, useful for parsing.

Portal alternative: In the Azure portal, navigate to 'Network Security Groups'. Select each NSG to review its inbound and outbound security rules. Also, check 'Virtual networks' to understand peering and subnet configurations, and 'Azure Firewall' for centralized network policy if deployed.

Expected result: A clear understanding of your network's perimeter rules and internal segmentation. Identify overly permissive rules (e.g., 'Any' source/destination), unneeded open ports, and ensure NSGs are correctly applied to subnets and NICs, segmenting environments (e.g., dev/test/prod).

Step 5: Cloud Resource Security (Azure)

The security of your cloud resources is paramount. This step audits the security configurations of Azure subscriptions, management groups, resource groups, storage accounts, virtual machines, web applications, and other critical cloud services. Misconfigurations in the cloud are a leading cause of breaches.

# Check for HTTPS Only enforcement on Azure Storage Accounts within a subscription
az storage account list --query '[].{Name:name, ResourceGroup:resourceGroup, SupportsHttpsTrafficOnly:supportsHttpsTrafficOnly}' --output table

az storage account list: Lists all storage accounts in the active subscription.

--query '[].{...}': Filters and displays the storage account name, resource group, and HTTPS-only status.

--output table: Formats the output as a table.

Common pitfall: Overlooking 'soft delete' or versioning settings on storage accounts. While the CLI command checks HTTPS, ensure you also audit for data resilience features. DIY for cloud security posture management without specialized tools (like Defender for Cloud) is extremely complex and prone to errors.

Portal alternative: Use Azure Security Center (now Microsoft Defender for Cloud) for a consolidated view of security posture. Navigate to 'Recommendations' to review security misconfigurations for various resource types. Manually inspect individual storage accounts (Encryption, Networking, Configuration), VMs (Networking, Disks, Extensions), and App Services (TLS/SSL settings, Authentication).

Expected result: Identification of misconfigured Azure resources, such as storage accounts without HTTPS enforcement or public access, VMs with open RDP/SSH ports, or App Services without proper authentication. Ensure Azure Policy initiatives are applied for baseline security.

Step 6: Data Protection & Backup Strategy

Data is your most valuable asset. This step critically examines data encryption at rest and in transit, evaluates backup policies (frequency, retention), and scrutinizes your organization's disaster recovery (DR) and business continuity (BC) plans. Inadequate data protection can lead to irreversible data loss and regulatory non-compliance.

# Check encryption status for Azure Disks in a subscription
az disk list --query '[].{Name:name, ResourceGroup:resourceGroup, OsType:osType, Encryption:diskEncryptionSetId}' --output table

az disk list: Retrieves a list of managed disks.

--query '[].{...}': Extracts disk name, resource group, OS type, and encryption set ID.

--output table: Presents results in a table format.

Portal alternative: For Azure Disks, navigate to 'Disks' in the Azure portal and check the 'Encryption' column. For storage accounts, go to the storage account > 'Encryption'. For Azure Backup, navigate to 'Backup center' > 'Backup instances' to review protection status and recovery points. Review DR/BC plans manually.

Expected result: Confirmation that sensitive data is encrypted at rest (e.g., Azure Disk Encryption, Storage Service Encryption) and in transit (e.g., TLS 1.2+). Verify backup integrity, frequency, and retention periods, ensuring alignment with recovery point objective (RPO) and recovery time objective (RTO) requirements. Validate DR/BC plans through tabletop exercises or actual drills.

Step 7: Vulnerability & Patch Management

A proactive vulnerability and patch management program is foundational. This step assesses your processes for regular vulnerability scanning, identifying critical vulnerabilities, and the timely application of security patches across all systems. Delays in patching known vulnerabilities are a significant attack vector.

# List critical security recommendations from Azure Defender for Cloud
az security recommendation list --query "[?properties.impact == 'High' && properties.status == 'Unhealthy'].{Name:name, Description:properties.description, ResourceId:properties.resourceId, Remediation:properties.remediation}" --output table

az security recommendation list: Retrieves security recommendations from Azure Defender for Cloud.

--query "[?properties.impact == 'High' && properties.status == 'Unhealthy']...": Filters for high-impact, unhealthy recommendations, extracting key details.

--output table: Displays the filtered recommendations in a table.

Portal alternative: Go to Microsoft Defender for Cloud > 'Recommendations'. Filter by 'Severity' (High/Medium) and 'Remediation status'. Also, review Azure Update Management for VM patch compliance, and vulnerability scanner reports (e.g., Qualys, Tenable) for on-premises assets.

Expected result: A clear picture of your organization's vulnerability landscape and patching cadence. Ensure regular, scheduled vulnerability scans are conducted (internal and external), critical vulnerabilities are prioritized, and patches are applied systematically. A robust change management process should govern patching.

Step 8: Security Monitoring & Logging

Effective security monitoring and logging are crucial for detecting and responding to incidents promptly. This step checks for centralized log management, Security Information and Event Management (SIEM) integration, alert configurations, and the established incident response procedures. Without visibility, breaches can go unnoticed for extended periods.

# List Azure Activity Log alerts configured for critical operations
az monitor activity-log alert list --query '[].{Name:name, ResourceGroup:resourceGroup, Enabled:enabled, Conditions:criteria.allOf[].{Field:field, Operator:operator, Value:value}}' --output table

az monitor activity-log alert list: Retrieves all activity log alerts.

--query '[].{...}': Extracts alert name, resource group, enabled status, and trigger conditions.

--output table: Displays alerts in a table format.

Portal alternative: In the Azure portal, navigate to 'Monitor' > 'Alerts' > 'Manage alert rules'. Review 'Activity log alerts' and 'Metric alerts'. Check 'Log Analytics workspaces' for data ingestion and query capabilities. If Azure Sentinel is used, review analytics rules, workbooks, and playbooks.

Expected result: Confirmation of comprehensive logging across critical systems (Azure Activity Logs, resource logs, endpoint logs). Verify that these logs are collected centrally (e.g., Log Analytics, Sentinel), and that alerts are configured for suspicious activities, security events, and compliance deviations. An incident response plan should be documented and tested.

Step 9: Application & Third-Party Security

Applications, especially web-facing ones, are frequent attack vectors. This step evaluates the security posture of key business applications, assessing secure coding practices (if applicable), and crucially, reviews the security agreements and practices of third-party vendors. Your supply chain is only as strong as its weakest link.

# Check if Azure App Service apps enforce HTTPS Only and have managed identity enabled
az webapp list --query '[].{Name:name, ResourceGroup:resourceGroup, HttpsOnly:httpsOnly, ManagedIdentity:identity.type}' --output table

az webapp list: Lists all App Services.

--query '[].{...}': Extracts App Service name, resource group, HTTPS-only status, and managed identity type.

--output table: Formats output as a table.

Common pitfall: Neglecting third-party vendor security. Many breaches originate from supply chain attacks. A CLI audit can check your own apps, but third-party security requires diligent contract review, vendor security questionnaires, and continuous monitoring. This is often where SMBs are most exposed.

Portal alternative: For Azure App Services, go to each App Service > 'TLS/SSL settings' for HTTPS enforcement, and 'Identity' for Managed Identity configuration. For third-party vendors, review procurement contracts, service level agreements (SLAs), and security questionnaires (e.g., SOC 2 reports, ISO 27001 certifications).

Expected result: Verification that internal and cloud applications adhere to secure development principles (e.g., OWASP Top 10) and are configured securely. Robust vendor assessment processes are in place, with clear security requirements integrated into contracts and regularly audited. Sensitive data processing by third parties must be explicitly controlled.

Step 10: Employee Security Awareness

The human element remains the weakest link in cybersecurity. This step reviews current security awareness training programs, phishing simulation results, and the overall employee understanding of common cyber threats and security best practices. A well-informed workforce is your first line of defense.

# (Conceptual CLI for M365 Security Center data, typically via Graph API or specific M365 modules)
# This example is illustrative; direct CLI for *training results* is limited without specific M365 security modules or Graph API access configured for tenant-wide reporting.
# Install-Module -Name Microsoft.Graph.Reports -RequiredVersion 2.0.0 # Or similar specific module
# Connect-MgGraph -Scopes 'SecurityEvents.Read.All' # Example scope for related data
# Get-MgSecurityAttackSimulationRepeatOffender # Illustrative for repeat offenders in phishing simulations if available via Graph Reports
Write-Host "Reviewing security awareness training records and phishing simulation results is primarily a documentation and platform review task."
Write-Host "Use platform-specific reports for Microsoft 365 Defender (Attack simulation training)."

Write-Host "...": Used here as a placeholder to emphasize that this step is less CLI-driven for SMBs than other technical aspects.

Portal alternative: In the Microsoft 365 Defender portal, navigate to 'Email & collaboration' > 'Attack simulation training' to review past campaigns, user susceptibility, and repeat offenders. Review records from your Learning Management System (LMS) for completion rates of security awareness training modules.

Expected result: Documented evidence of ongoing security awareness training for all employees, covering topics like phishing, password hygiene, social engineering, and data handling. Regular phishing simulations should demonstrate improving employee resilience to attacks, with targeted remediation for susceptible individuals.

Step 11: Policy, Compliance, & Governance

This step verifies adherence to relevant industry regulations (e.g., GDPR, HIPAA, PCI DSS), internal security policies, and overall IT governance frameworks. Compliance is not just a legal obligation; it often drives sound security practices. A well-defined governance structure ensures accountability and consistency.

# List all Azure Policy assignments in the current subscription, demonstrating compliance framework implementation
az policy assignment list --query '[].{Name:name, DisplayName:displayName, PolicyDefinitionId:policyDefinitionId, Scope:scope}' --output table

az policy assignment list: Retrieves all policy assignments in the current context.

--query '[].{...}': Extracts the assignment name, display name, definition ID, and scope.

--output table: Presents the policy assignments in a table.

Portal alternative: In the Azure portal, navigate to 'Azure Policy' > 'Assignments' to see which policies are enforced and their scope. Review 'Regulatory compliance' within Microsoft Defender for Cloud for an assessment against common industry standards. Manually review your organization's internal security policies, procedures, and governance documents.

Expected result: Documented internal security policies that are regularly reviewed and communicated. Evidence of adherence to applicable regulatory frameworks and industry best practices, potentially enforced via Azure Policy. A clear governance structure with defined roles, responsibilities, and accountability for security.

Step 12: Audit Findings & Remediation Plan

The culmination of the audit process is compiling all identified vulnerabilities and weaknesses into a comprehensive report. This step involves prioritizing risks based on their potential impact and likelihood, and developing a clear, actionable remediation roadmap with timelines and assigned responsibilities. An audit without a plan for improvement is merely an observation.

# (This step is entirely planning and reporting, not CLI-driven for audit output)
Write-Host "This step involves synthesizing all findings into a structured report."
Write-Host "Prioritize risks based on impact (High, Medium, Low) and likelihood."
Write-Host "Develop an actionable remediation plan, assigning owners and deadlines."
Write-Host "Consider using a project management tool (e.g., Azure DevOps, Trello) to track remediation efforts."

Write-Host "...": Placeholder to guide the user on the next steps, as this is a strategic planning phase.

Portal alternative: Use tools like Azure DevOps, Microsoft Planner, or even a simple spreadsheet to document findings from Azure Security Center recommendations, manual checks, and third-party reports. Track remediation tasks, owners, and due dates. Leverage the 'Workload protection' dashboard in Defender for Cloud to monitor the security posture improvements over time.

Expected result: A formal audit report detailing findings, risk levels, and recommended remediation actions. A clear, prioritized remediation plan with realistic timelines, assigned owners, and metrics for measuring success. Regular follow-ups should be scheduled to ensure remediation tasks are completed effectively.

When to bring in a consultant

While this checklist provides a solid foundation, for many SMBs, conducting a thorough cybersecurity audit requires specialized expertise that goes beyond day-to-day IT operations. If your internal team lacks deep knowledge in Azure security best practices, advanced threat detection, or compliance frameworks like GDPR/HIPAA, or if you simply don't have the time to dedicate to a comprehensive audit, DIY becomes risky. An external consultant, like SkyCore Solutions, can provide an objective, in-depth analysis, leveraging specialized tools and experience to uncover hidden vulnerabilities and guide you through complex remediation. Don't wait for a breach to realize the value of expert security guidance.

Book a free consultation