Shield & Scale

The Basics: A Self-Audit Checklist Before You Start Scaling

By Kaleb Parker ·

A lot of the scaling work we get asked to do (cloud migrations, new tooling, AI adoption, workflow automation) is more expensive and riskier than it needs to be, because it’s layered on top of security fundamentals that were never quite finished. None of this replaces a proper audit, but it’s a genuinely useful five-minute gut check on where you stand.

Go through it honestly. “Mostly” and “I think so” both count as no.

Access and accounts

  • Multi-factor authentication is turned on for email, for any remote access, and for anything holding client data, not just for a few accounts you remembered to set up.
  • Staff who’ve left the business in the last twelve months have had every account and access permission actually revoked, not just their email disabled.
  • Nobody is doing everyday email and browsing from an account that also has administrator rights.
  • You could list, right now, who has access to your most sensitive system (client records, financial data, trust accounts) without having to go and check.

Backups

  • Backups run on a schedule you could actually state, not “I believe it’s automatic.”
  • A backup has been test-restored in the last twelve months, not just confirmed as “completed” in a log.
  • At least one backup copy is stored somewhere that a ransomware attack hitting your main systems couldn’t also reach.

Patching and updates

  • Operating systems and business-critical applications update on a defined schedule, not “whenever someone notices.”
  • You’d know within a reasonable timeframe if a device on your network stopped receiving updates.

Email and endpoint hygiene

  • Office document macros from the internet are blocked by default, not enabled for convenience.
  • Staff have had phishing awareness training in the last year, not just when they were onboarded.
  • There’s a clear, known process for what a staff member does when they suspect they’ve clicked something they shouldn’t have, and nobody’s afraid to use it.

Governance basics

  • Someone specific (not “IT,” an actual named person or firm) owns security decisions for the business.
  • You know, roughly, what your obligations are if client data were ever exposed, not just “we’d deal with it if it happened.”
  • The last time a new tool or system was adopted, someone checked where it stores and processes data before it went live.

Scoring yourself

If you ticked most of these honestly, you’re in reasonable shape to start scaling: migrating infrastructure, rolling out new tools, or growing headcount won’t be building on a foundation with obvious holes in it.

If you’re unsure on several, especially in the access and backups sections, that’s worth fixing before anything else. Those two categories are where the difference between “bad afternoon” and “business-ending event” usually gets decided, and they’re also the ones a scaling project will expose fastest, not fix on its own.

This checklist is intentionally quick and intentionally not exhaustive. If you want the properly scored version, mapped against the Essential Eight with a written, prioritised remediation plan, that’s exactly what our cybersecurity audit is for, and it’s the sensible starting point before any of our scaling services as well.

Have a question about your own systems?

Book a free 15-minute discovery call, no obligation, no sales pitch.

CallGet in touch