Network Security Checklist · Atlanta

The network security checklist we actually use.

Eleven areas to cover, the specific things to check in each, and what to review every quarter. Written for Atlanta businesses without a security team of their own.

Marietta-based · Since 2004 · Cyber + physical, one team

The short answer

A basic network security checklist for a small business covers eleven things: know what is on the network, segment it, lock down the firewall, patch on a schedule, require multi-factor authentication, back up and test the restore, protect email and every device, secure the Wi-Fi, control vendor access, monitor and keep logs, and plan for the bad day.

None of it is exotic. The checklist is the easy part. What fails is the follow-through: the restore nobody tested, the vendor account nobody turned off, the camera recorder still on its factory password. So each section below lists specific things you can check, and there is a quarterly review at the end to keep it from drifting.

The network security checklist

  1. Know what is on the network

    You cannot protect a device you do not know about. It is common to find gear nobody listed: an old switch, a camera recorder, a printer still on its default password.

    • Keep a list of every device: computers, servers, firewalls, switches, Wi-Fi access points, printers, phones, cameras, recorders, and door controllers.
    • Note who owns each one, where it is, and whether it still gets security updates.
    • List every account with admin rights, on the network gear and in your cloud apps.
    • Know where your important data lives: which server, which cloud service, which laptops.
  2. Segment the network

    On a flat network, one infected laptop or hacked camera can reach everything else. Segments (VLANs with firewall rules between them) keep a problem in one room.

    • Put staff computers, servers, guest Wi-Fi, phones, and cameras and door controllers on separate segments.
    • Block guest Wi-Fi from every internal segment. Guests get the internet and nothing else.
    • Allow only the traffic each segment needs. A camera needs its recorder, not your file server.
    • Keep the management interfaces of firewalls, switches, and access points off the guest and IoT segments.
    The cabling and switching underneath →
  3. Lock down the firewall and the edge

    The firewall is the front door. Default settings and forgotten rules are how most of them end up open.

    • Change every default admin password, on the firewall and every other network device.
    • Turn off admin login from the internet. Manage remotely only through a VPN with multi-factor authentication.
    • Review the inbound rules and port forwards. Remove any whose purpose nobody can explain.
    • Turn off UPnP and any services you do not use.
    • Replace firewalls, switches, and access points the manufacturer no longer patches.
  4. Patch on a schedule

    Attackers go after known flaws that have already been fixed. Patching on a schedule closes them before they get used.

    • Update operating systems and applications on every computer and server on a set schedule, with a faster path for urgent fixes.
    • Update firmware on firewalls, switches, access points, cameras, recorders, and door controllers. They are computers too.
    • Retire any operating system past end of support. Windows 10 stopped getting free security updates in October 2025.
    • Confirm the updates actually installed. A patch that failed silently does not protect you.
  5. Require MFA and limit admin rights

    A stolen password is the most common way in. Multi-factor authentication stops most of those logins, and limited admin rights cap the damage from the rest.

    • Turn on MFA for email, remote access and VPN, cloud apps, banking and payroll, and every admin console.
    • Give everyone their own login. No shared admin accounts, and no daily work done from an admin account.
    • Grant admin rights only to the people who need them, and review the list.
    • Disable accounts the same day someone leaves, and change any shared passwords they knew.
  6. Back up, and test the restore

    Backups are what you fall back on after ransomware, a dead server, or a deleted folder. A backup nobody has restored from is a hope, not a plan.

    • Follow the 3-2-1 rule: three copies of your data, on two kinds of storage, with one copy offsite.
    • Keep at least one copy that ransomware cannot reach or change: offline, or immutable.
    • Back up your cloud data too, including email and file sharing. The provider keeping the service up is not the same as backing up your data.
    • Restore something on a schedule and time it. Know how long getting back to work actually takes.
    What downtime costs →
  7. Protect email and every device

    Most attacks start with an email and land on a laptop. Filtering, endpoint protection, and trained staff catch them at those two points.

    • Filter inbound email for phishing, malware, and spoofed senders.
    • Run managed endpoint protection on every computer and server, with alerts going to someone who responds.
    • Encrypt laptop drives so a lost laptop is a hardware problem, not a data breach.
    • Train staff to spot phishing, and give them an easy way to report a suspicious email.
  8. Secure the Wi-Fi

    Wi-Fi reaches past your walls, into the parking lot and the suite next door.

    • Use WPA3, or WPA2 with AES where older devices need it. Never WEP or an open network for staff.
    • Where you can, give staff individual Wi-Fi logins (WPA2/WPA3-Enterprise) instead of one shared password.
    • Run guest Wi-Fi on its own segment, with client isolation, and change its password regularly.
    • Turn off WPS, change the access points’ admin passwords, and look for access points nobody approved.
  9. Control vendor and remote access

    Your copier company, phone vendor, camera installer, and software providers may all have a way into your network. Each one is a door you do not watch.

    • List every vendor with remote access and how they connect.
    • Give each vendor its own account with MFA. Never share a staff login.
    • Turn vendor access on when they need it and off when they are done, and log it.
    • Keep vendor-managed devices such as HVAC controls, copiers, and cameras on their own segment.
    • Remove a vendor’s access when the contract ends.
  10. Monitor and keep logs

    Tools that alert nobody do not protect anybody. Someone has to watch, and the logs have to be there when you need to know what happened.

    • Send firewall, endpoint, and cloud sign-in alerts to a person or service that acts on them.
    • Watch for new admin accounts, repeated failed logins, sign-ins from unexpected places, and devices that go offline.
    • Keep logs long enough to look back at an incident after it is discovered, which is often weeks later.
    • Know who gets the call after hours.
  11. Plan for the bad day

    Deciding who to call during a breach costs hours you do not have. Write it down in advance.

    • Write a one-page incident plan: who decides, who to call, and how to disconnect an infected machine.
    • Keep your IT partner’s, your cyber insurer’s, and your bank’s contacts somewhere other than the network that might be down.
    • Know what your cyber insurance requires. Applications commonly ask about MFA, backups, and endpoint protection.
    • Walk through the plan once a year with the people named in it.
    Are you cyber-insurable? →

What to check every quarter

Security drifts. People leave, vendors come and go, a rule gets added for a project and never removed. A short quarterly review catches that before an attacker does. Block an afternoon for it:

  1. Review every admin and user account. Remove anyone who left and any access nobody can explain.
  2. Confirm patches and firmware are current on computers, servers, and network gear, including cameras and door controllers.
  3. Restore a file and a full system from backup, and confirm an offline or immutable copy exists.
  4. Review firewall rules and port forwards. Remove what is no longer needed.
  5. Check MFA coverage. Look for any account, app, or remote-access path without it.
  6. Review vendor remote access. Turn off anything not in active use.
  7. Compare the device list to what is actually on the network, and track down anything unknown.
  8. Change the guest Wi-Fi password.
  9. Check the end-of-support list, and budget to replace what is coming up.
  10. Read the recent alerts. Confirm they went to someone, and that someone acted.

Once a year, go back through the full checklist above and walk through the incident plan with the people named in it. For a year-end version, see our end-of-year cybersecurity checklist.

A DIY network security audit, step by step

You do not need special tools for a first pass. You need admin access, an afternoon, and the willingness to write down what you find.

  1. Walk the network closet

    Write down every box that is plugged in, and match it to your device list. Unlabeled gear and equipment nobody can name is your first finding.

  2. Log in to the firewall

    Check the firmware version against the manufacturer’s latest, confirm the admin password is not the default, and export the inbound rules. Each one should have an owner and a reason.

  3. Pull the account lists

    Export the users and admins from your email and cloud apps, your firewall, and your servers. Compare them to the staff list and the vendors you actually use.

  4. Check MFA and patch reports

    Most cloud email and endpoint consoles report which users lack MFA and which devices are missing updates. Read those reports rather than assuming.

  5. Test a restore

    Pick a file and restore it. If you can, restore a whole machine and time it. This is the step most often skipped, and the one that matters most after ransomware.

  6. Write down what you found

    Rank the findings by what would hurt most, and give each one an owner and a date. An audit that does not end in a list of fixes is just a tour.

A DIY audit is good at finding things. It is weaker at judging them: whether a firewall rule is actually safe, whether a backup would survive ransomware, whether an alert means anything. If your findings list has more question marks than answers, that is the time for a second set of eyes.

Where the cameras and doors fit

Most network security checklists skip the physical security systems. They should not. Your camera recorders and access control panels are computers on your network. They are often installed by a different vendor, left on factory passwords, never updated, and plugged into the same network as your accounting server. That makes them only as secure as the network underneath them, and sometimes the weakest thing on it.

Treat them like any other device on the checklist: their own segment, changed passwords, firmware updates, and installer access you control. That is why we run the cameras, doors, and network as one system. See security solutions for the full picture, or what that means for a door project in our access control cost breakdown.

How we work through it with you

We start the way this page does: an assessment of what is actually on your network, how it is segmented, what is patched, who has access, and whether your backups restore. Then we tell you honestly what is worth keeping and what to fix first. From there, the same Marietta-based team can run it for you: endpoint protection, email security, MFA, patching, and ongoing monitoring, delivered with our managed IT practice. Coverage and response terms are set in your agreement.

Further reading

Network security checklist questions

What should a basic network security checklist include?
At minimum: a list of every device and admin account, separate network segments for staff, guests, and devices like cameras, a locked-down firewall with no default passwords, patching on a schedule, multi-factor authentication on email and remote access, backups with at least one offline copy and a tested restore, endpoint protection and email filtering, secured Wi-Fi, controlled vendor access, monitoring that alerts a person, and a written incident plan.
How often should a small business review its network security?
Patching and alert review are ongoing. Accounts, firewall rules, vendor access, backup restores, and MFA coverage are worth a quarterly review. Once a year, walk through the whole checklist and the incident plan. Review again after any big change, such as a move, a new system, or a staff turnover at the top.
Can I do a network security audit myself?
You can do a useful first pass yourself: list your devices and accounts, check the firewall for default passwords and old rules, read your MFA and patch reports, and test a restore. Where a DIY audit falls short is judging what you find, such as whether a firewall rule is safe or a backup would survive ransomware. That is where an outside review is worth it.
Is a home network security checklist enough for a small office?
It is a good start. Router updates, strong Wi-Fi passwords, and a guest network all apply. An office adds segmentation between staff, guests, and devices, central patching and endpoint protection, MFA across business apps, tested backups, vendor access, and monitoring. For remote staff, our home network security checklist is the right one to send them.
Do security cameras and access control belong on the checklist?
Yes. Camera recorders and door controllers are computers on your network, so they are only as secure as the network underneath them. They need their own segment, changed default passwords, firmware updates, and controlled installer access, the same as any other device.

Ready when you are.

Client or not, a one-time review is fine.